DEF CON 33 - There and Back Again: Detecting OT Devices Across Protocol Gateways - Rob King

DEF CON 33 - There and Back Again: Detecting OT Devices Across Protocol Gateways - Rob King

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 21:56

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video explains how to discover OT devices across protocol gateways, focusing on industrial protocols like Modbus, DNP3, and Ethernet/IP, with an emphasis on their discovery mechanisms and limitations. 0:00

Key Takeaways:
• Modbus supports device discovery via the Encapsulated Interface Transport (EIT) function, which returns vendor, product, and version details when using function code 0x0F 9:50.
• DNP3 devices are hard to discover due to their primary address requirement and lack of standardized discovery, but unsolicited responses can reveal device addresses and attributes; enumeration of the 65,000+ address space is often needed 13:00.
• Ethernet/IP provides built-in device discovery via the "List Identity" command over UDP broadcast, and through SIP's connection manager, enables recursive discovery of all devices on a backplane or rack, including those using other protocols 18:10.

This approach allows comprehensive OT device discovery in complex industrial environments, despite protocol-specific challenges. 21:44

Sources:

  • 0:00 Introduction to OT device discovery and overview of industrial control evolution.
  • 9:50 Modbus EIT function for device identification details.
  • 13:00 DNP3 discovery challenges and unsolicited response use cases.
  • 18:10 Ethernet/IP discovery via List Identity and SIP connection manager for recursive device enumeration.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello everybody. Thank you for coming. Um, this is there and back again, which is all about discovering OT devices across protocol gateways. Uh, my name is Rob King. There's my face. If you want to see it twice, it's right there. Um, so let's talk about how did we get here? It's going by. So when we talk about OT, we talk about ICS, we talk about SCADA, we often think about these super cool looks like from a 1990s or maybe 80s with a good budget sci-fi thing with a control room and uniforms and bleepy things and all that. And that is part of it and it's super great. Um, this is a control room from I think it's a refinery in Germany, but it's from Wikipedia. So very nice of them. But what we're really talking about as well and what we tend to kind of abstract away from as security practitio…