Forty Minutes From Modbus Theory to Writing Coils on a Live PLC
An OT Leaders Club webinar walks the whole path in one session — the protocol, the running plant, the network scan that finds it, the write that changes it, and the traffic that shows it happened.

April 15, 2026 — Labshock chief executive Zakhar Bernhardt presented a webinar for the OT Leaders Club on using the platform in OT security training, running a full lab walkthrough inside a forty-minute session.
The session opened on Modbus itself — the memory model of coils and registers, and the fact that the protocol carries no authentication. It then moved to normal operation inside Labshock: starting the SCADA system, watching the process run, and reading the PLC tags and logic behind it.
From there it went directly at the protocol. The network was scanned with Nmap, the PLC located on port 502, and coils read and then written directly, with the resulting change visible in the behaviour of the system.
The last technical segment closed the loop on detection: what the Modbus traffic looked like, what the Labshock collector recorded, and why monitoring is not optional in an environment where a valid command and an unauthorised one are the same packet.
The argument the sequence makes is that an OT system is visible and changeable from the network as soon as controls are absent, and that this is not a claim a slide can carry. Labshock thanks the OT Leaders Club, and Alexandro Fernandez and Karla Isabel Soriano Salgado for organising the session.
Media enquiries: info@labshocksecurity.com
