EC-Council Certified Ethical Hacker (CEH) v12Mobile Platform, IoT, and OT HackingHard

A team of ethical hackers is performing a red team exercise against a critical national infrastructure (CNI) target. Their objective is to cause a physical disruption to a specific industrial process controlled by a PLC. They have gained remote access to an engineering workstation on the IT network, which has direct network access to the target PLC. Which OT attack tool category would be most appropriate for them to use next to manipulate the PLC's control logic and achieve their objective?

  1. ANetwork vulnerability scanners (e.g., Nessus)
  2. BWeb application penetration testing proxies (e.g., Burp Suite)
  3. CDistributed Denial of Service (DDoS) amplification tools
  4. DSCADA/ICS-specific protocol exploitation frameworks (e.g., Metasploit modules for Modbus/S7comm)
Show answer & explanation

Correct answer: D. SCADA/ICS-specific protocol exploitation frameworks (e.g., Metasploit modules for Modbus/S7comm)

To manipulate a PLC's control logic, an attacker needs tools that understand and can interact with the specific industrial protocols (like Modbus, S7comm, EtherNet/IP) used by PLCs. SCADA/ICS-specific protocol exploitation frameworks, often integrated into tools like Metasploit, provide the necessary modules and capabilities to send malicious commands or re-program PLCs.

Why the other options are wrong

  • A. Network vulnerability scanners identify vulnerabilities but do not directly manipulate PLC control logic.
  • B. Web application proxies are for web applications, not direct interaction with industrial PLCs.
  • C. DDoS tools aim to disrupt availability, not to manipulate control logic.

OT Protocol Exploitation Tools

Software tools specifically designed to interact with, analyze, and exploit vulnerabilities in industrial control system (ICS) communication protocols (e.g., Modbus, S7comm, DNP3).

  • Allow sending malicious commands to PLCs, RTUs, HMI.
  • Can be used for reconnaissance, manipulation, or denial of service.
  • Often require deep understanding of proprietary or specialized protocols.

Memory trick: To 'control' the factory, use protocol tools to speak its language.

More Mobile Platform, IoT, and OT Hacking questions