
OT Cybersecurity Intrusion Analysis FROSTYGOOP Modbus
Download this premium online course featuring high-quality video training, step-by-step lessons, practical demonstrations, and expert instruction. With OT Cybersecurity Intrusion Analysis FROSTYGOOP Modbus, you'll gain practical knowledge through structured learning, hands-on examples, and real-world applications. This comprehensive eLearning resource is ideal for students, professionals, freelancers, and lifelong learners looking to develop valuable skills and stay current with modern industry practices at their own pace.
Published 9/2026
Created by Ed Galarza
MP4 | Video: h264, 1920x1080 | Audio: AAC, 44.1 KHz, 2 Ch
Level: Intermediate | Genre: eLearning | Language: English | Duration: 13 Lectures ( 1h 15m ) | Size: 473.5 MB
FROSTYGOOP Modbus Intrusion Analysis
What you'll learn
⚡ Explain how OT intrusion analysis differs from IT investigation, including the data sources that are unique to industrial environments.
⚡ Read a Modbus TCP capture in Wireshark and identify unauthorized reconnaissance and write activity by function code, source IP, and register range
⚡ Describe what FrostyGoop is, how it operates, and why it caused physical impact.
⚡ Correlate SCADA historian data against an independent field sensor to detect falsified process values.
⚡ Trace an attacker's path across the IT and OT boundary using firewall, VPN, and host-artifact logs.
⚡ Build a consolidated incident timeline mapped to MITRE ATT&CK for ICS
⚡ Produce a prioritized list of detection and segmentation improvements grounded in the evidence.
Requirements
❗ This module assumes you are comfortable with basic TCP/IP and Wireshark navigation. If you have not done the Tier 1 Modbus TCP Exploitation module, I recommend completing that first — this module builds directly on that foundation.
Description
By the end of this module, you will be able to do seven things. First: explain how OT intrusion analysis differs from IT investigation, including the data sources that are unique to industrial environments. Second: read a Modbus TCP capture in Wireshark and identify unauthorized reconnaissance and write activity by function code, source IP, and register range. Third: describe what FrostyGoop is, how it operates, and why it caused physical impact. Fourth: correlate SCADA historian data against an independent field sensor to detect falsified process values. Fifth: trace an attacker's path across the IT and OT boundary using firewall, VPN, and host-artifact logs. Sixth: build a consolidated incident timeline mapped to MITRE ATT&CK for ICS. And seventh: produce a prioritized list of detection and segmentation improvements grounded in the evidence.
The evidence pack for this module is the FrostyGoop Evidence Set — a simulated but structurally faithful collection of a PCAP, a SCADA historian CSV, an independent field sensor CSV, a perimeter router syslog, an OT firewall log, and two host artifacts from the compromised workstation. it from the resources section of this lecture.
One prerequisite note: this module assumes you are comfortable with basic TCP/IP and Wireshark navigation. If you have not done the Tier 1 Modbus TCP Exploitation module, I recommend completing that first — this module builds directly on that foundation
Overall you will learn to conduct Intrusion Analysis, Intrusion Detection Engineering, Network Traffic Analysis, etc.
Who this course is for
⭐ OT Cybersecurity professionals who want to enhance their Intrusion Analysis and Incident Response skills.
⭐ Also any other Cybersecurity professionals who want to learn these skills.
Homepage
https://www.udemy.com/course/ot-cybersecurity-intrusion-analysis-frostygoop-modbus
Buy Premium From My Links To Get Resumable Support,Max Speed & Support Me
No Password - Links are Interchangeable
