Group Purchasing
Group Purchasing

ICS515: ICS Visibility, Detection, and Response

ICS515Industrial Control Systems Security
  • 6 Days (Instructor-Led)
  • 36 Hours
Course authored by:
Robert M. Lee
Robert M. Lee
Course authored by:
Robert M. Lee
Robert M. Lee
  • GIAC Response and Industrial Defense (GRID)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person or Virtual

    Attend a live, instructor-led class from a location near you or virtually from anywhere

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 22 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Acquire critical visibility, detection, and response capabilities to protect ICS/OT environments against sophisticated threats while ensuring the safety and reliability of operations.

Course Overview

This ICS incident response course equips security professionals with practical skills to secure industrial environments. Through hands-on exercises using real industrial equipment, you'll learn to gain network visibility, identify assets, detect threats, and respond to incidents in critical infrastructure and other environments that rely on ICS/OT systems. The curriculum covers advanced defensive techniques against sophisticated threats like STUXNET, HAVEX, BLACKENERGY2, CRASHOVERRIDE, TRISIS/TRITON, FROSTYGOOP, EKANS, and PIPEDREAM. You'll work with a real programmable logic controller (PLC) kit, sector simulation board, and virtual machines that you keep post-course to continue skill development. Leveraging industry frameworks , you'll develop repeatable methodologies to secure industrial environments.

ICS Visibility, Detection & Response

ICS515: ICS Visibility, Detection, and Response will help you gain visibility and asset identification in your Industrial Control System (ICS)/Operational Technology (OT) networks, monitor for and detect cyber threats, deconstruct ICS cyber-attacks to extract lessons learned, perform incident response, and take an intelligence-driven approach to executing a world-leading ICS cybersecurity program to ensure safe and reliable operations. This course is also a primary preparation path for the GRID certification (GIAC Response and Industrial Defense), the industry’s leading credential for professionals focused on ICS threat detection, response, and active defense.

The course will empower students to understand their networked ICS environment, monitor it for threats, perform incident response against identified threats, and learn from interactions with the adversary to enhance network security. This approach is important to being able to counter sophisticated threats such as those seen with malware including STUXNET, HAVEX, BLACKENERGY2, CRASHOVERRIDE, TRISIS/TRITON, FROSTYGOOP, EKANS, and PIPEDREAM. In addition, the efforts are also critical to understanding and running a modern-day complex automation environment and achieving root cause analysis for non-cyber-related events that manifest over the network. Students can expect to come out of this course with core skills necessary for any ICS cybersecurity program.

The course uses a hands-on approach with numerous technical data sets from ICS ranges and equipment with emulated attacks and real-world malware deployed in the ranges for a highly simulated experience detecting and responding to threats. Students will also interact with and keep a programmable logic controller (PLC), physical kit emulating electric system operations at the generation, transmission, and distribution level, and virtual machine set up as a human machine interface (HMI) and engineering workstation (EWS).

Students will spend roughly half the course performing hands-on skills across more than 25 technical exercises and an all-day technical capstone. Students will gain a practical and technical understanding of defining an ICS cybersecurity strategy, leveraging threat intelligence, performing network security monitoring, and performing incident response. Frameworks such as the ICS Cyber Kill Chain, Collection Management Framework, and Active Cyber Defense Cycle will be taught to give students repeatable frameworks and models to leverage post class. These practical frameworks enhance your ability to deliver effective ICS threat detection and response programs aligned with the competencies required for the GRID certification.

The strategic and technical skills presented in this course serve as a basis for ICS organizations looking to show that ICS defense is do-able.

  • How to perform ICS incident response focusing on security operations and prioritizing the safety and reliability of operations.
  • How ICS threat intelligence is generated and how to use what is available in the community to support ICS environments. The analysis skills you learn will enable you to critically analyze and apply information from ICS threat intelligence reports on a regular basis.
  • How to identify ICS assets and their network topologies and how to monitor ICS hotspots for abnormalities and threats. The course will introduce and reinforce methodologies such as ICS network security monitoring and approaches to reducing the control system threat landscape.
  • How to analyze ICS threats and extract the most important information needed to quickly scope the environment and understand the nature of the threat.
  • How to operate through an attack and gain the information necessary to instruct teams and decision-makers on whether operations must shut down or it is safe to respond to the threat and continue operations.
  • How to use multiple security disciplines in tandem to leverage an active defense and safeguard an ICS, all reinforced with hands-on labs and technical concepts.

This Course Will Prepare You To

  • Examine ICS networks and identify the assets and their data flows in order to understand the network information needed to identify advanced threats
  • Use active defense concepts such as threat intelligence consumption, network security monitoring, malware analysis, and incident response to safeguard the ICS
  • Build your own Programmable Logic Controller using the SANS ICS515 Student Kit, which you retain after the class ends
  • Gain in-depth knowledge on ICS targeted threats and malware including STUXNET, HAVEX, BLACKENERGY2, CRASHOVERRIDE, TRISIS/TRITON, FROSTYGOOP, EKANS, and PIPEDREAM
  • Leverage technical tools such as Shodan, Wireshark, Zeek, Suricata, Volatility, FTK Imager, PDF analyzers, PLC programming software, and more
  • Create indicators of compromise (IOCs) in YARA
  • Take advantage of models such as the Sliding Scale of Cybersecurity, the Active Cyber Defense Cycle, the Collection Management Framework, and the ICS Cyber Kill Chain to extract information from threats and use it to encourage the long-term success of ICS network security

Hands-On Training

  • Build a Programmable Logic Controller (PLC) using the SANS ICS515 Student Kit
  • Identify information available about assets online through Shodan
  • Complete an analysis of competing hypotheses
  • Ingest threat intelligence reports
  • Identify and leverage new active defense skills to guide incident responders to the Human Machine Interface (HMI) affected by an advanced persistent threat (APT) on the lab network
  • Identify which system is affected by APT malware identified in the network and assemble a sample of the threat that can be analyzed
  • From the infected HMI and samples of the APT malware identified, analyze the malware, extract information, and develop YARA rules to complete the active defense
  • Address three different hands-on, real-world scenarios, one involving live data collected from an intrusion into the SANS ICS515 Student Kit, and the other involving data collected from a Distributed Control System (DCS) infected with malware

Author Statement

"This class was developed from my experiences in the U.S. intelligence community, at Dragos and within the control system community dealing with advanced adversaries targeting industrial control systems. It is the class I wish I would have had available to me while protecting infrastructure against these adversaries. It is exactly what you'll need to maintain secure and reliable operations in the face of determined threats. ICS515 will empower you to prove that defense is do-able."

- Robert M. Lee

What You'll Learn

  • Implement ICS-specific threat detection strategies
  • Apply network security monitoring for OT environments
  • Perform incident response in operational technology
  • Extract intelligence from ICS threat analysis
  • Build effective cybersecurity for industrial systems

Business Takeaways

  • Improve visibility into ICS/OT asset inventories
  • Reduce risk of operational disruption from cyber threats
  • Enhance detection capabilities for ICS-specific attacks
  • Develop effective OT incident response procedures
  • Increase resilience against targeted industrial threats
  • Bridge security gaps between IT and OT environments
  • Apply intelligence-driven approaches to ICS security

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in ICS515: ICS Visibility, Detection, and Response.

Section 1ICS Cyber Threat Intelligence

Learn to leverage threat intelligence to analyze threats, extract indicators of compromise, document tactics, techniques, and procedures, and guide security teams to protect industrial environments.

Topics covered

  • Case Study: STUXNET
  • Introduction to ICS Active Defense
  • Cyber Threat Intelligence Primer
  • ICS Cyber Kill Chain
  • Threat Intelligence Consumption

Labs

  • Building a Programmable Logic Controller
  • Structured Analytical Techniques
  • Analysis of Intelligence Reports
  • ICS Information Attack Space
  • Maltego and Shodan Heatmap

Industrial control system (ICS) security professionals must be able to leverage internal and external threat intelligence to critically analyze threats, extract indicators of compromise (IOCs), document tactics, techniques, and procedures (TTPs), and guide security teams to find threats in the environment. On this first course day students will learn how threat intelligence is generated, how to critically analyze reports, and the basic tenets of active defense functions. Students will become better analysts and critical thinkers by learning skills useful in day-to-day operations, regardless of their jobs and roles. This day features five hands-on labs that include building a Programmable Logic Controller (PLC), identifying information available about assets online through Shodan, completing an analysis of competing hypotheses, visualizing the attack space combining Maltego and Shodan, and ingesting threat intelligence reports to guide their practices over the rest of the labs in the course.

Section 2Visibility and Asset Identification

Understand the networked environment to build comprehensive asset inventories and develop effective collection strategies for both industrial operations and security operations.

Topics covered

  • Case Study: Bhopal Disaster
  • Asset Inventories
  • Collection Management Frameworks
  • ICS Network Visibility
  • IT Discovery Protocols

Labs

  • Operating the Process
  • ICS Traffic Analysis
  • ICS Protocol Analysis
  • ICS Network Mapping

Understanding the networked environment is the only way to fully defend it: you cannot defend what you do not know. This day starts off with leveraging the PLC to perform electric grid system operations in an attempt to understand ICS operations better and what aspect of asset identification can help operations. Students will analyze packet captures, ICS protocols, and topologies across four hands on labs to learn what they can extract from network information to build asset inventories inclusive of equipment make and models, firmware, serial numbers, ports, protocols, and logical addressing information.

The day is guided around the concept of a Collection Management Framework teaching students how to build a collection and visibility strategy tailored to their needs for both industrial operations and security operations

Section 3ICS Threat Detection

Develop detection strategies to remain resilient against targeted and untargeted threats, with focus on safely conducting threat hunting and analyzing attack patterns in industrial environments.

Topics covered

  • Case Study: German Steelworks Attack
  • ICS Threat Hunting
  • Threat Detection Strategies
  • Case Study: SANDWORM
  • ICS Network Security Monitoring

Labs

  • Detecting Stage 1 Intrusions
  • Investigating Stage 2 Compromises
  • Traffic Analysis of Control Manipulation
  • Validating System Logic Changes
  • Logic Manipulation of Control Elements

Threat detection is core to remaining resilient in the face of targeted and un-targeted ICS threats. In this section students will learn about the different types of detection and build a detection strategy for their ICS/OT networks. This will begin with instruction on what threat hunting is and how to accomplish it in the ICS safely. Students will spend the day in network captures from the course’s ICS range to identify the beginning of an attack on the industrial environment and follow it through to completion. Across five hands-on-labs, students will learn to identify the difference between intrusions and Stage 1 of the ICS Cyber Kill Chain intrusions and then investigate a Stage 2 intrusion where the adversary is attempting to manipulate the logic of a controller.

Section 4Incident Response

Learn to safely perform ICS incident response with focus on acquiring digital evidence while scoping threats and their operational impact, using forensic techniques tailored for industrial environments.

Topics covered

  • Case Study: SANDWORM - Ukraine 2015
  • ICS Digital Forensics
  • Preparing an ICS Incident Response Team
  • Case Study: ELECTRUM and CRASHOVERRIDE
  • Initial Compromise Vectors

Labs

  • Acquisition in an Operational Environment
  • PLC Logic and Protocol Root Cause Analysis
  • Analyzing Phishing Emails
  • HMI Memory Forensics
  • Process Triage

The ability to prepare for and perform ICS incident response is vital to the safety and reliability of control systems. ICS incident response is a core concept of ICS active defense and requires that analysts safely acquire digital evidence while scoping the environment for threats and their impact on operations. ICS incident response is a young field with many challenges, but during this section students will learn effective tactics and tools to collect and preserve forensic-quality data. Students will then use these data to perform timely forensic analysis leveraging techniques such as memory forensics. In this section's five hands on labs students will learn to safely acquire data, analyze initial infection vectors such as phishing emails, perform memory forensics, and analyze manipulated PLC logic.

Section 5Threat and Environment Manipulation

Extract information from threats through malware analysis to reduce the effectiveness of threats and create shareable threat intelligence for improved defensive posture.

Topics covered

  • Case Study: XENOTIME - TRISIS
  • ICS Threat Manipulation Goals
  • Environment Manipulation Considerations
  • Threat Analysis and Malware Triaging
  • YARA

Labs

  • Logic Analysis for Root Cause Analysis

Understanding the threat is key to discovering its capabilities and its potential to affect the ICS. The information extracted from threats through processes such as malware analysis is also critical to being able to make the necessary changes to the environment to reduce the effectiveness of the threat. The information obtained is vital to an ICS active defense, which requires internal data collection to create and share threat intelligence. In this section, students will finish out the course scenario to identify the root cause of the failure in the ICS networks and craft a YARA rule on the malware for an IOC. For half the day, students will experience a mini capstone with another complete scenario for students to put their skills to the test in a guided scenario that is educational.

Section 6Capstone Day, Under Attack!

A full-day technical challenge where students apply all learned skills to analyze packet captures, logic, memory images, and more from compromised ICS ranges and equipment, simulating real-world scenarios.

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system that meets all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 16GB of RAM or more is required.
  • 200GB of free storage space or more is required.
  • At least one available USB Type-A or USB Type-C port. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.
  • SANS has begun providing printed materials in PDF and Web format (electronic workbook). In this new environment, a second monitor and a tablet device can be helpful by keeping the class materials visible while the instructor is presenting or while you are working on lab exercises.

Mandatory Host Configuration and Software Requirements

  • Ability to update BIOS configuration settings to enable virtualization (VT-x) support
  • Your host operating system must be the latest version of Windows 10, Windows 11, or newer.
  • Fully update your host operating system and hardware drivers prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. This course requires full administrative access to the operating system and these products will prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.
  • Download and install VMware Workstation Pro 16.2.X+ or VMware Player 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ or VMware Player 17.0.0+ (for Windows 11 hosts) prior to class beginning. If you do not own a licensed copy of VMware Workstation Pro, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial at their website. Also note that VMware Workstation Player offers fewer features than VMware Workstation Pro. For those with Windows host systems, Workstation Pro is recommended for a more seamless student experience.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts). This tool is also included in your downloaded course materials.

Your course media is delivered via download. The media files for class are large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete before arrival to class. Internet connections and speed vary greatly and are dependent on many different factors. Consequently, it is impossible to estimate the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. Waiting until the night before the class starts to begin your download has a high probability of failure.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

If you have questions about the laptop specifications, please contact customer service.

ICS515 training is recommended for a diverse range of individuals, including:

  • ICS Incident Response Team Leads and Members who want to learn how to respond to advanced threats safely in an industrial control systems with a focus on combined and continued security
  • ICS and Operations Technology Security Personnel who want to learn how to leverage an industrial control system active defense, including network security monitoring and threat intelligence
  • IT Security Professionals who want to expand their knowledge into the industrial control system field with an understanding of ICS protocols, threats, and priorities
  • Security Operations Center (SOC) Team Leads and Analysts who want to learn how to monitor OT networks and industrial control system assets in an ICS SOC or dual IT/OT SOC
  • ICS Red Team and Penetration Testers who want to learn the latest in defense tactics to identify how they can better perform, and how they can better highlight areas for improvement in industrial control system networks
  • Active Defenders who want to challenge themselves to identify and respond to advanced targeted threats

The GRID certification is for professionals who want to demonstrate that they can perform Active Defense strategies specific to and appropriate for an Industrial Control System (ICS) network and systems. Candidates are required to demonstrate an understanding of the Active Defense approach, ICS-specific attacks and how these attacks inform mitigation strategies. Candidates must also show an understanding of the strategies and fundamental techniques specific to core subjects with an ICS-focus such as network security monitoring (NSM), digital forensics and incident response (DFIR).

  • Active Defense Concepts and Application, Detection and Analysis in an ICS environment
  • Discovery and Monitoring in an ICS environment, ICS-focused Digital Forensics, and ICS-focused Incident Response
  • Malware Analysis Techniques, Threat Analysis in an ICS environment, and Threat Intelligence Fundamentals

More Certification Details

  • Electronic Download package continuing ICS lab data such as packet captures and memory images
    • Protocol samples of OPC, ModbusTCP, DNP3, BACnet, EthernetIP/CIP, S7, and more
    • System files from infected DCS and HMI systems
  • A fully functioning SANS ICS515 Student Kit that students will keep following the class
    • A CLICK PLC Plus Controller, with additional modules and cards for communications with a sector simulation board
    • Physical components and attachments for I/O connections to the SANS sector simulator board
    • Commercial Click PLC Programming software from KOYO ElectronicsÂ
    • Commercial HMI control system runtime applications from Rockwell Automation
    • Commercial OPC server application software from Matrikon
  • A SANS ICS515 Windows Virtual Machine
  • A SANS ICS515 RELICS Virtual Machine

Students from either an IT or ICS background will do well in this course. Prior to attending the course, it is recommended that you attend SANS ICS410: ICS/SCADA Security Essentials, ICS456: Essentials for NERC Critical Infrastructure Protection, or equivalent essential cybersecurity classes such as SEC401, or that you have fundamental cybersecurity experience. Students do not need previous ICS experience, but they should be comfortable with ICS terminology and systems such as SCADA, DCS, PLCs, and RTUs, and have an understanding of distinct risks and mitigation approaches in OT environments.

With your purchase of this ICS Security course, you’ll receive complimentary OnDemand access to ICS310: ICS Cybersecurity Foundations — an added benefit, not a prerequisite or requirement. This course is a great way to reinforce key concepts or fill gaps in your ICS/OT security knowledge, whether you complete it in full or focus on what’s most relevant to you. Within 14 business days, you’ll receive a non-transferable access code via your SANS account email.

The recommended learning path starts with foundational courses like ICS410: ICS/SCADA Security Essentials, ICS456: Essentials for NERC Critical Infrastructure Protection, or SEC401: Security Essentials - Network, Endpoint, and Cloud. While prior ICS experience isn't required, familiarity with basic ICS terminology (SCADA, DCS, PLCs, RTUs) and OT risk concepts is beneficial. The course includes complimentary access to ICS310: ICS Cybersecurity Foundations.

ICS (Industrial Control System) Incident Response is the structured process of detecting, investigating, and mitigating cybersecurity incidents that affect operational technology (OT) environments—such as power grids, water treatment facilities, manufacturing systems, pipelines, and other critical infrastructure.

These environments rely on real-time control systems like SCADA (Supervisory Control and Data Acquisition), PLCs (Programmable Logic Controllers), and HMIs (Human Machine Interfaces), which differ significantly from traditional IT systems in both design and risk profile.

This course enhances careers by providing hands-on experience with real ICS equipment and advanced defense techniques. Learners gain specialized skills in industrial threat detection, incident response, and network monitoring that are highly sought after in critical infrastructure sectors, positioning you as a specialized security professional capable of bridging IT and OT security domains.

Relevant Job Roles

Threat Hunter Training, Salary, and Career Path

Digital Forensics and Incident Response

This expert applies new threat intelligence against existing evidence to identify attackers that have slipped through real-time detection mechanisms. The practice of threat hunting requires several skill sets, including threat intelligence, system and network forensics, and investigative development processes. This role transitions incident response from a purely reactive investigative process to a proactive one, uncovering adversaries or their footprints based on developing intelligence.

Explore learning path

All-Source Analyst (DCWF 111)

DoD 8140: Intelligence (Cyberspace)

Analyzes data from multiple sources to prepare environments, respond to information requests, and support intelligence planning and collection requirements.

Explore learning path

Cyber Defense Infrastructure Support Specialist (DCWF 521)

DoD 8140: Cybersecurity

Deploys, configures, maintains infrastructure software and hardware to support secure and effective IT operations across organizational systems.

Explore learning path

Control Systems Security Specialist (DCWF 462)

DoD 8140: Cybersecurity

Oversees cybersecurity configuration and daily security operations of control systems, ensuring mission support and stakeholder coordination.

Explore learning path

Operational Technology (OT) Cybersecurity Engineering (OPM 652)

NICE: Design and Development

Responsible for working within the engineering department to design and create systems, processes, and procedures that maintain the safety, reliability, controllability, and security of industrial systems in the face of intentional and incidental cyber-related events. Interfaces with Chief Information Security Officer, plant managers, and industrial cybersecurity technicians.

Explore learning path

Industrial Control Systems and Operational Technologies

SCyWF: Industrial Control Systems And Operational Technologies

This role conducts cybersecurity tasks for Industrial Control Systems and Operational Technologies (ICS/OT). Find the SANS courses that map to the Industrial Control Systems and Operational Technologies SCyWF Work Role.

Explore learning path

Incident Responder Training, Salary, and Career Path (DCWF 531)

DoD 8140: Cybersecurity

Responds to and investigates network cyber incidents, performing analysis to mitigate threats and maintain cybersecurity in enclave environments.

Explore learning path

Incident Response (OPM 531)

NICE: Protection and Defense

Responsible for investigating, analyzing, and responding to network cybersecurity incidents.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 15

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources