Labshock — Signal Feed
News & Updates
Releases. Partnerships. Product updates. Real OT security intelligence from the World of Labshock ecosystem — not isolated updates — delivering continuous insights you can track, analyze, and act on.
Two Federal Advisories, No Zero Day
Water utilities in July, Siemens controllers in August, five agencies between them — and not one zero day. The stated causes were exposure, default credentials and missing segmentation.
Two federal advisories in three weeks. Not one zero day between them. ## 30 July, Water The FBI and EPA reported activit…
→Electroshock: Switching a 6 kV Substation
Two incomers, two busbars, six feeders, two RTUs, and interlocks that refuse you. Send the command, watch what the process does about it, and find out why when nothing happens.
You can read a hundred pages about substations. Or open one breaker and see what really happens. Electroshock is our GRI…
→Free Masterclass: Firewall and Zoning in OT
OT protocols carry no user identity, which makes the firewall rule the authentication. On 23 August we stop drawing zones and start writing rules on a live substation.
OT protocols carry no user identity. Modbus, S7, IEC 104, DNP3 — nobody has to prove who they are. So whoever can reach…
→Asset Inventory From Traffic You Just Made
Installing an inventory tool takes five minutes. Finding plant traffic to point it at does not. Labshock now captures what you generate and feeds it straight into the tool.
The hardest part of OT asset inventory is not the tool. It is finding traffic to point it at. The tool installs in five…
→One SUBSCRIBE Can Print Your Whole Plant
MQTT is not an industrial protocol, but it runs more plants every year. Wildcards, retained messages and optional authentication combine into something worth understanding before it reaches your estate.
MQTT is not an industrial protocol. It runs more plants every year anyway. It arrives through telemetry gateways, edge d…
→Nine ICS Technique IDs Stopped Existing
ATT&CK for ICS finally got sub-techniques, and the T0-means-ICS rule everybody learned is no longer true. If your mapping dates from 2020, part of it now points at nothing.
If your ATT&CK for ICS mapping was written in 2020, part of it now points at nothing. Not because your detection got wor…
→Zeek and Suricata Are Now Free Labs
Two network detection labs, open to everyone, reading live industrial traffic from a running process. Write a rule, send the command it should catch, and check whether it actually fired.
Two weeks ago Wazuh became a free lab. Now Zeek and Suricata are free too. You told us detection is where you get stuck,…
→Zeek vs Suricata: What Each One Actually Sees On An OT Network
Both sensors read the same mirror port and answer different questions. Plus the industrial parsers Suricata ships disabled, and the Zeek defaults that quietly limit what lands in your logs.
Put Zeek and Suricata on the same mirror port and they see identical packets. They answer completely different questions…
→S7comm Anatomy: What Travels To A Siemens PLC On Port 102
The stack, the TSAP, the function codes and the S7ANY addressing scheme — plus why classic S7comm is still very much alive on S7-1500.
Siemens S7 is probably the most deployed PLC family on the planet, and S7comm is how you talk to it. Most engineers who…
→Phase 3 Is Complete: Guides, Labs and Quests Now Live in One Place
Every Labshock service now runs under one design. Each zone is one page where quest leads to guide, guide leads to lab, and lab brings you back to the quest.
Phase 3 of Labshock is complete. Every service now runs under one design, and guides, labs and quests live in the same p…
→Wazuh Is Now a Free OT SIEM Lab Inside Labshock
Wazuh manager and dashboard, deployed and connected to a living industrial environment. Trigger an action on the OT side, find it in the dashboard, and test whether your rule fires.
Wazuh is one of the most asked-about tools in our community. An open source SIEM many of you already run. Now it runs in…
→Firegate Is Live: A 6 kV Substation You Can Operate
A new zone built around a 6 kV substation running DNP3 and IEC 60870-5-104 — send an approved command, watch the breaker change state, and check what the IDS saw.
Firegate is live. A new zone inside World of Labshock, built around a 6 kV substation, running two of the protocols used…
→DNP3 Is Not Just Port 20000
Master and outstation roles, class polls, event classes, Select-Before-Operate, and the protocol fields that tell you who read what and who operated what.
Most monitoring for DNP3 stops at the port. A rule watches TCP 20000, an allow-list names the hosts that may use it, and…
→Three Ways to Place a Firewall Between IT and OT
One firewall, two firewalls, or a firewall with a DMZ — how each topology separates the Enterprise network from OT, and why the boundary is not real until you test it.
One wrong firewall rule and the Enterprise network talks straight to your PLC. A firewall between IT and OT is not one b…
→5 Manufacturing Attacks Every OT Security Team Should Study
Five manufacturing cyber incidents — German Steel Mill, EKANS, Mirai, JBS, Verkada — the shared IT-to-OT pattern, and how to test detection against each one.
Manufacturing has been the most attacked industry for 5 years in a row, and attacks grew more than 50% last year alone.…
→Structured Text: The PLC Language That Reads Like Code, Runs Like Control Logic
Structured Text is an IEC 61131-3 PLC language built for calculation, condition, and sequence, but it still executes inside the PLC scan cycle like every other control program.
The second Labshock masterclass on PLC programming just finished, focused entirely on Structured Text. PLC programming i…
→Labshock Is Not One Thing. It Is Four Directions.
OT security learning, ICS pentesting, IDS/SIEM validation, and custom OT lab building all run on the same executable environment.
People often ask what Labshock actually is. It is not one thing. It is four directions, built on the same underlying env…
→PLC Programming Masterclass Part 2: Structured Text Inside Thunderwatch
The PLC programming masterclass series moves from Automation Anatomy into Structured Text, live inside World of Labshock's Thunderwatch zone.
The first Labshock masterclass started from Automation Anatomy. This session goes one layer deeper. ## Part 2 Of The PLC…
→Labshock Headlines BSides Paris 2026
From two friends showing Labshock on stage in Sao Paulo and Aarhus to headlining as first partner of BSides Paris this October.
Last year, two friends carried Labshock onto the stage. This year, Labshock headlines Paris. ## How It Started BSides Sa…
→OT/ICS Security Has Two Dimensions: Automation and Security
Automation engineers and security engineers look at the same PLC and see two different worlds. Real OT protection appears only when both dimensions connect.
OT/ICS security has two dimensions. One comes from Automation. One comes from Security. Both look at the same PLC. Both…
→Labshock and Boots to Cyber Partnership
Labshock partners with Boots to Cyber to help more people from military backgrounds move into cyber and understand industrial systems, PLCs, SCADA, and critical infrastructure security.
Labshock has entered a new partnership with Boots to Cyber. This partnership matters to us. A lot of people from militar…
→Patch 2.3: Thunderwatch PLC Programming Zone Opens Inside World of Labshock
Patch 2.3 expands World of Labshock with Thunderwatch, a PLC programming zone focused on automation anatomy, PLC scan cycle, Ladder Logic, Structured Text, HMI tags, live memory, and OT security validation.
Patch 2.3 is coming to World of Labshock. A new zone is opening. Thunderwatch. This zone moves Labshock deeper into PLC…
→Automation Anatomy: Why OT Security Starts with the Machine
Industrial cybersecurity starts by understanding the control chain behind the screen: sensors, PLC memory, HMI requests, engineering workstations, outputs, and physical process behavior.
A utility plant can look simple from the operator screen. The HMI shows pumps, valves, tanks, temperatures, alarms, and…
→PLC Programming Masterclass: Automation Anatomy Inside Labshock
The next Labshock Masterclass starts the PLC Programming path with Automation Anatomy, first Ladder logic, and practical control behavior inside World of Labshock.
This Sunday we start a new Labshock Masterclass. Topic: PLC Programming. First session: Automation Anatomy. The goal is…
→Overview Of PLC Programming Languages
PLC programming languages define how controllers read inputs, process logic, control outputs, and expose system behavior for engineering and OT security validation.
PLC programming languages define how industrial controllers behave. A PLC reads inputs. It processes logic. It controls…
→Labshock Is Now On Trustpilot
Labshock is now open for public reviews because real user feedback is one of the strongest signals for building testable OT security environments.
Labshock is now on Trustpilot. This may look like a small update. But for us it matters. Because product is not what we…
→Automation Anatomy: How Industrial Control Systems Work Before PLC Programming
Industrial automation is not one device. It is a chain of sensors, PLC logic, HMI requests, engineering workstations, networks, outputs, and physical process behavior.
A utility plant may look simple from the operator screen. A pump starts. A valve opens. A tank level rises. A temperatur…
→Labshock Adds IEC 60870-5-104 Support
IEC 104 support expands Labshock toward realistic power grid, substation, RTU, and control center environments.
Labshock now supports IEC 60870-5-104. Also known as IEC 104. This is an important step for the next direction of Labsho…
→What Actually Travels Through IEC 104 Port 2404?
Every second, critical infrastructure exchanges thousands of IEC 60870-5-104 messages carrying process data, measurements, status signals, and control commands that directly influence physical operations.
Most people know one fact about IEC 60870-5-104. It uses TCP port 2404. The more interesting question is: What actually…
→Network Swiftness Receives a Major Update
A new interface, Siemens S7 support, machine learning capabilities, and expanded industrial visibility mark the next evolution of Network Swiftness inside the Labshock ecosystem.
The feature was supposed to be demonstrated during the latest Labshock Masterclass. For two very unexpected reasons, it…
→80% of OT Alerts Are Useless Without Context
Logs, events, and alerts are not enough. Without asset, process, and operational context, OT investigations become guesswork.
Most OT security programs have no shortage of data. They collect: - Logs - Events - Alerts - Network traffic - Protocol…
→Free Labshock Masterclass: Building Your First OT Detection
Real OT detection does not start with an alert. It starts by connecting PLC activity, industrial protocols, detection systems, SIEM platforms, analysts, and process impact into a single operational chain.
Most OT security programs stop at the IDS layer. An alert is generated. An event is logged. The workflow ends. Real OT d…
→One Small Change Can Affect an Entire City
The Eastwater Facility inside Labshock demonstrates why industrial cybersecurity begins with understanding physical processes, not network traffic.
Labshock now includes a simulated water treatment environment called Eastwater Facility. The purpose is simple. To show…
→Labshock Environments Are Executable Systems
Industrial environments should execute, evolve, and validate continuously. Static labs and documentation cannot keep pace with changing OT systems.
Most OT laboratories are built as static representations of industrial systems. They describe process behavior. They dem…
→Integrations Are Not a List. They Are the System Shape.
The value of an OT platform is not defined by the number of integrations it has. It is defined by how those integrations create a single operational system.
Most platforms present integrations as a feature list. A collection of connected products. A marketplace. A partner page…
→Segmentation Without Validation Does Not Exist
Industrial network segmentation is often treated as a design exercise. In reality, segmentation is defined by actual communication paths, not diagrams.
Network segmentation is one of the most common security initiatives in OT environments. Zones are created. VLANs are con…
→Three Directions Are Changing OT Security
Detection validation, telemetry validation, and response validation are reshaping industrial cybersecurity. All three point to the same missing capability: verification against real process behavior.
OT security is changing. Three major directions are emerging across industrial cybersecurity. All of them lead to the sa…
→How Six PLC Events Cover Most Incident Signals
Effective OT detection starts with controller state. A small set of high-value PLC events often provides more visibility than collecting millions of network records.
OT security without signal focus becomes noise collection. Many security programs collect more data every year. More pac…
→Future OT Environments Will Be Continuously Testable
Industrial systems evolve every day, but validation often remains periodic. The next generation of OT security will require continuous testing and verification.
Future OT environments will be continuously testable. Today, most are not. Industrial systems are commonly tested during…
→Most Systems Start with Software. OT Starts with a Dry Contact.
Before SCADA, PLCs, protocols, and dashboards, industrial systems begin with something much simpler: a contact changing state.
Most modern systems start with software. OT starts with a contact. A dry contact is one of the simplest electrical inter…
→Industrial Gas Station OT Security Masterclass Using Gasflow Terminal
Understanding industrial processes, turbine control systems, SCADA, and OT security through real operational environments.
Most people see a gas station as infrastructure for fuel distribution. In industrial cybersecurity, it is a complex oper…
→Labshock and Y Cyber Partnership: Advancing OT Security Validation
A collaboration focused on operational OT security, testing, and industrial cyber defense.
Labshock has entered a strategic partnership with Y Cyber, part of the HWG Sababa Group, an Italy-based OT cybersecurity…
→Gasflow Terminal: Industrial OT Simulation with 26 Services on One System
A compact industrial cybersecurity environment running full OT infrastructure in a single runtime.
## Gasflow Terminal demonstrates how modern OT environments can be simulated at full industrial scale using a compact sy…
→Why OT Security Must Move From Documentation to Continuous Validation
Industrial cybersecurity requires real-world testing, not assumptions.
## OT security today is often based on documentation, compliance requirements, and dashboard visibility rather than vali…
→Trust in OT Security Requires a Feedback Loop (Labshock on Trustpilot)
Why OT security trust must be based on real-world validation, not marketing claims.
Trust in security is not marketing. Trust is a system with a feedback loop. Labshock is now listed on Trustpilot. The re…
→OT Security Must Be Testable: Building and Running Real OT Networks
How Labshock Builder turns OT network design into an executable system.
OT security today is mostly based on documentation. But industrial systems are not documents. This is why Labshock intro…
→How Gas Turbines Like the GE MS5002E Are Controlled in OT Systems
Understanding PLC control, turbine physics, and OT security monitoring gaps in industrial gas turbines.
Industrial gas turbines such as the GE MS5002E are not IT systems. They are controlled physical processes governed by in…
→6 Critical HMI Detection Signals for OT SIEM and Industrial Defense
How HMI monitoring provides operational visibility in industrial cybersecurity environments.
A common misconception in industrial cybersecurity is that OT defense is primarily about scanning systems or generating…
→Portable Lab Format (PLF): Portable OT Labs Inside Labshock
A new system for exporting, importing, and running industrial OT labs across different environments.
One of the biggest challenges in industrial cybersecurity labs is portability. Teams can spend days or weeks building OT…
→OT SIEM with Labshock and Splunk: Understanding SCADA Events
A practical masterclass on building OT SIEM detection from real SCADA data.
The second Labshock Masterclass focuses on integrating Labshock with Splunk to analyze SCADA-level events in industrial…
→Building a Real OT Gas Transportation Station in Labshock Using GE MS5002E
How Labshock Builder creates a full industrial OT environment with turbines, PLCs, SIS, and SCADA systems.
This post describes the construction of a real OT lab environment inside Labshock, not a demo or simplified simulation,…
→Real Cyber Attacks on Water Systems: Oldsmar, Maroochy Shire, and SCADA Security Lessons
How real-world water infrastructure attacks reveal weaknesses in OT systems and SCADA security.
Water infrastructure systems are among the most critical and frequently targeted operational technology (OT) environment…
→Labshock Reaches 20,000 Followers: Building an OT Security Platform with Its Community
How Labshock is evolving from an idea into a practical OT security and simulation platform used by real practitioners.
Labshock has reached a new milestone of 20,000 followers, with more than 2,000 users actively engaging with the platform…
→Labshock Builder is Live: Automated OT Lab Creation with Full Network Control
Build, configure, and run OT security labs with automated routing, services, and industrial network modeling.
Labshock Builder is now live, enabling full creation of OT security labs without relying on static or manually configure…
→Understanding Siemens S7 Protocol in OT Security
How S7 communication works, what it exposes, and why it matters for industrial cybersecurity.
The Siemens S7 protocol is one of the most widely deployed industrial communication protocols in OT environments. It is…
→OT Security Training with Labshock: Modbus, SCADA, and Real Protocol Testing
Hands-on OT cybersecurity training demonstrated in the OT Leaders Club webinar.
Last week, Labshock was presented in an OT Leaders Club webinar focused on practical OT security training using real ind…
→Command Center for OT Training: Managing Labs, Progress, and Students in Real Time
How Labshock Command Center improves visibility in OT cybersecurity training environments.
Training OT cybersecurity teams is difficult when learners are distributed across complex lab environments. A common sit…
→OT Network Basics: Field, Layer 2, Layer 3 Before Building DMZ
Understanding industrial network architecture before moving into DMZ and segmented OT environments.
Before working with OT security concepts such as DMZ architecture, it is essential to understand how industrial networks…
→58 ENTRIES — OT SECURITY MUST BE TESTABLE, NOT DOCUMENTED
