Skip to main content
Labshock
LoginStart Free

World of Labshock — Use Cases

Who Uses It.
And What For.

Eight things people do with Labshock that they could not do otherwise — because each one needs a real industrial process with no production consequences. Vendors demoing to prospects, startups building detection, security teams and governments testing the stack they already own, universities teaching, and engineers building the topology their own estate has.

Looking for your sector specifically — water, power, oil & gas, manufacturing, rail? See the industry breakdown.

Who runs it

6
continents
every inhabited one
35
countries buying
paid orders, not signups
24
named organisations
universities, partners, academies and conferences, all public record
4
ways to use it
Learn (training), Test (pentest and cyber range), Validate (your IDS, SIEM and controls), Build (infrastructure)
01

Universities

Teach ICS security with systems students can actually operate

Who does this

George Mason University, The Citadel, Texas A&M Corpus Christi, University of Texas San Antonio, Friedrich-Alexander University
US and German research universities

Teach ICS and OT security using Labshock environments, on campus and in coursework.

See the academic ecosystem

What they do

  • Run a full industrial environment per student, isolated, reset between sessions
  • Assign structured progression — quests, guides and badges — instead of building coursework from scratch
  • Take students from automation fundamentals through protocol analysis to detection engineering
  • Manage users and track XP, levels and completed quests through Command Center

What makes it possible

Structured progressionlevels 1-60 across 10 zones, mapped to competencies
Guides and quizzestheory tied to the lab it belongs to, with badges on completion
Command Centeruser management plus XP, levels, quests and badges per student
02

Training providers

Deliver paid OT courses without building the lab yourself

Who does this

Boots to Cyber, OT Leaders Club, Netsentinel Academy
Training academies and professional communities

Use Labshock to take people into industrial security — veterans transitioning into cyber, practising OT leaders, and academy students.

Institute of Cybersecurity Excellence
Cybersecurity training and research organisation

Delivers training on Labshock at scale.

ICS Arabia
Regional industrial cybersecurity initiative, Middle East

Uses Labshock to deliver industrial security training to their own customers.

A UK engineering and defence training groupunnamed by request
Large technical training provider, United Kingdom

Delivers industrial cybersecurity training on Labshock environments.

License terms

What they do

  • Deliver instructor-led workshops and bootcamps on environments that already exist
  • Grant access to enrolled participants for the duration of a programme
  • Record sessions and produce derived course material
  • Run the same environment for every cohort, reset each time

What makes it possible

Enterprise Licenseexternal training programme delivery is explicitly permitted
On-premise deploymentno cloud dependency, no shared infrastructure
Portable Lab Formatship the environment to a classroom or a client site
03

Security vendors

Demo your product on a real plant with no production behind it

Who does this

GuidePoint Security
Cybersecurity services and solutions provider, US

Run a dedicated Labshock OT environment for their industrial security work.

HWG Sababa and Y Cyber
OT security vendors, Italy and international

Built a GE Mark VIe gas turbine environment on Labshock and use it to present their own product to customers.

NVISO Labs
Security research and services team, Europe

Tests their own products and services against Labshock environments.

A major US cybersecurity integratorunnamed by request
Enterprise security solutions provider, United States

Commissioned a custom railway control lab and uses it to demonstrate their product to their own customers.

Enterprise License terms

What they do

  • Stand up an isolated environment matching the prospect's architecture — their protocols, their segmentation, their device mix
  • Point your product at live Modbus, S7comm, DNP3 or IEC 104 traffic from a running process
  • Trigger a real process event on the OT side and show your product catching it in front of the buyer
  • Reset the environment and run the same demo again for the next prospect

What makes it possible

Surge Routermirrors raw industrial traffic to any external IDS or hardware appliance
Tidal Collectorstreams OT events into any external SIEM or analytics platform
Portable Lab Formatexport the environment and hand it to a colleague or reuse it on the next call
04

Product integration

Put a working industrial plant inside your own product

Who does this

Kasm and SteelDome
Workspace streaming and industrial storage/security platforms, US

Integrate Labshock into their own products, both to demonstrate capability to customers and to build a service on top.

License scope

What they do

  • Embed Labshock environments inside your own platform as the industrial layer
  • Show customers your product operating against real PLC, SCADA and protocol traffic
  • Build a billable service on top of the environment rather than reselling a demo
  • Deploy on-premise where the customer requires it, with no cloud dependency

What makes it possible

Portable Lab Formatcomplete environments exported and deployed inside another product
On-premise deploymentno shared infrastructure, no cloud requirement
Partner Programembedding Labshock in your own product runs under a separate agreement
05

Security startups

Get OT traffic to build your detection product against

Who does this

A French security startupunnamed by request
Early-stage OT detection vendor, France

Tests and tunes its IDS against live industrial traffic it has no other way to obtain.

A Houston security startupunnamed by request
Early-stage detection vendor, United States

Validates its IDS against multi-protocol OT traffic from running processes.

See the lab environments

What they do

  • Generate continuous, labelled industrial traffic across several protocols and topologies
  • Tune detection logic against genuine protocol behaviour rather than replayed captures
  • Test whether your parser handles Modbus pipelining, DNP3 event classes, or S7comm symbolic addressing correctly
  • Feed labelled OT traffic into behavioural or AI-based models for training and evaluation

What makes it possible

Live process behaviourtraffic comes from PLC logic actually executing, not from a replay
Multi-protocol coverageModbus TCP, Siemens S7comm, DNP3, IEC 60870-5-104
Repeatabilityrun the same scenario twice and get the same conditions
06

Security teams

Find out whether the detection you already pay for actually fires

Who does this

A US state governmentunnamed by request
State-level public sector, United States

Uses Labshock to work on critical infrastructure security capability.

A European national governmentunnamed by request
National public sector, Europe

Uses Labshock for industrial security capability development.

An industrial operator under elevated threatunnamed by request
Critical infrastructure operator

Uses Labshock to build and test OT security capability under realistic threat conditions.

How the Wazuh lab works

What they do

  • Mirror industrial traffic from the lab into the same IDS you run in production
  • Forward OT telemetry into your live SIEM and check whether ingestion, parsing and normalisation are correct
  • Operate an approved command — a breaker, a setpoint, a coil write — and confirm the alert fires and says something useful
  • Test the IT-to-OT boundary by sending traffic at it and watching which rules actually engage

What makes it possible

Wazuh labfree, deployed, connected to a running industrial environment
Splunk and ELK labsfull pipelines from OT telemetry into a production-grade SIEM
Zeek and Suricatanetwork detection over industrial traffic, next in the same chain
07

Engineering teams

Build the exact topology your estate has, not a generic one

Who does this

A US engineering and infrastructure firmunnamed by request
Engineering services, own OT estate

Builds environments matching the architectures they work on rather than using the stock labs.

Detection startupsunnamed by request
Early-stage OT security vendors, Europe and the US

Construct the topologies their own IDS has to survive — odd segmentation, mixed protocols, traffic they cannot otherwise generate.

Industrial operatorsunnamed by request
Asset owners with their own OT estate

Recreate their own plant architecture — their segments, their controllers, their protocols — to test a change before it reaches production.

See the release

What they do

  • Define your IT, DMZ and OT zones and the routing between them
  • Add PLCs, HMIs, SCADA servers, historians and firewalls to match your real device mix
  • Model your segmentation and test whether the boundary holds when you send traffic at it
  • Export the finished environment and share it with the team, or archive it for repeatable exercises

What makes it possible

Labshock Builderdynamic environment generation across IT, DMZ and OT layers
Multi-PLC scenariosmaster-slave topologies and distributed process control
Command Centeruser management and XP progression tracking across your team
08

Conferences & community

Run a live OT test-and-defend session instead of a talk

Who does this

BSides São Paulo, BSides Aarhus, BSides Paris, DEF CON, HOU.SEC.CON, OT.SEC.CON, CYBR.SEC.CON
Security conferences, three continents

Ran Labshock on stage as live industrial systems rather than as a slide deck.

ICS Village
Industrial cybersecurity community

Shows Labshock at conferences as hands-on industrial systems for attendees to operate.

Read the announcement

What they do

  • Give attendees real industrial systems to operate and defend, scored like a CTF but built for OT
  • Run a live masterclass where participants write PLC logic and watch the process respond
  • Use the free tier so anyone in the room can continue afterwards without a purchase

What makes it possible

Free starter zoneLoginward, no card, so attendees keep going after the session
Isolated installationruns entirely on your own hardware, air-gapped if required
Reset between runsthe same scenario for every group

Why there are no customer logos on this page

Naming an industrial operator as a security customer tells the internet which organisations are working on their OT gaps. Most of ours are contractually entitled to stay unnamed, and we think the rest should be too.

Universities, conferences and partners are named here because their participation is already public and costs them nothing. Commercial customers are described by profile only. If you want a reference conversation before buying, we will arrange one directly — info@labshocksecurity.com.

OT security must be testable, not documented.

Start in the free zone, or tell us what you need to prove and we will show you the environment that proves it.