Unsolicited Response Podcast

Sep 30, 2020

Detecting Triton Type Attacks

In this episode I talk with Otis Alexander of MITRE about ATT&CK for ICS Evaluations. We begin with a discussion on ATT&CK and the ICS version of ATT&CK. If you are familiar with this, skip to 17:09 where we begin our discussion on the upcoming evaluations.

MITRE has created a Triton type...

Sep 16, 2020

Most of the OT Detection and Asset Management solutions have developed 'integrations' with SIEMs, with Splunk and QRadar being the most common. I put integrations in quotes because they did little more than push alerts and events to the SIEMs with little context. This all changed with Splunk announcing their OT...

Sep 2, 2020

We hear it all the time. OT is different than IT, and IT doesn't understand OT. People argue about IT/OT convergence. In all these discussions I believe two things are true.

  1. OT doesn't really understand IT, and the similar, but not identical, requirements that mission critical IT has with OT.
  2. OT can actually learn a...