World of Labshock — Industrial Directions
World of Labshock
Four Industrial Directions
World of Labshock is the environment all four directions run on — working industrial systems, not a simulator. Real SCADA. Real PLCs. Real industrial protocols. Learn how OT works. Test its security. Validate your own controls against it. Build the environments you need.
Want this cut by sector instead — water, power, oil & gas, manufacturing, rail? See the industry breakdown.
Runs inside your perimeter
All four directions run on an isolated on-premise installation. Labshock sits on your own hardware, inside your own network, with no cloud dependency and no outbound connection required. Industrial data, captures and user activity never leave your perimeter.
Direction 01
Learn How OT Works
Real environments. Real protocols. Real skills.
Zones · Levels · Quests · Guides · SkillsMost OT security training is theoretical. Slides and diagrams of systems you never touch. Labshock is different — you operate actual SCADA interfaces, program real PLC logic, and interact with industrial processes the way engineers and security testers do in the field.
The World of Labshock structures this into a full progression system. You start from zero and advance through 10 zones, each representing a new layer of OT security complexity — from basic SCADA interaction to industrial protocol testing and DMZ architecture analysis.

Quest System
Structured objectives guide you through industrial environments step by step. Quests are tied to specific zones and labs, defining what to do, what to observe, and what concepts to unlock next.
Progression & XP
Advance from Level 1 to 60 by completing hands-on actions inside real OT environments. XP reflects what you actually did, not what you read.
Guides & Playbooks
Theory and practical playbooks tightly connected to zones and quests. Context-delivered, not dumped in a wiki. You learn the concept the moment you need it.
Badges & Skills
Earn verifiable badges tied to completed labs and quizzes. Skills represent specific OT competencies — Modbus analysis, PLC logic, SCADA visibility, IDS detection — built through action.
World Map & Zones
10 interconnected zones, each representing a unique industrial environment: oil stations, utilities, railroad control, gas terminals. Progress unlocks new zones and increases complexity.
Direction 02
Test Industrial Systems
Authorised OT penetration testing and team cyber range exercises. Safely isolated.
Pentest Fury · Protocols · Segmentation · Exposure · Cyber RangeProduction OT environments cannot be safely tested directly. They operate critical infrastructure and cannot tolerate disruption. Labshock provides a controlled alternative: a fully isolated industrial environment that behaves like production, built for authorised security testing.
Pentest Fury is the testing framework behind this capability. It runs structured, authorised OT security tests across industrial environments, from initial discovery through lateral movement to process impact — on a plant that exists to be tested.
The same environment runs as a cyber range for a team: one scenario, one isolated environment per person, on your own hardware.

Pentest Fury Framework
A structured OT penetration testing framework built for authorised engagements. Focuses on industrial context rather than generic IT penetration testing.
Industrial Protocol Testing
Evaluate security exposure and behaviour across multiple industrial protocols (e.g. Modbus, Siemens S7, DNP3, EtherNet/IP). Understand how systems respond under test conditions.
OT System Exposure Analysis
Identify exposure across PLCs, SCADA systems, HMIs, and industrial gateways. Assess segmentation gaps and misconfigurations across OT/DMZ/IT boundaries.
Segmentation & Trust Boundary Testing
Trace the paths that cross Engineering Workstations and DMZ layers, and confirm whether segmentation actually holds where the network diagram says it does.
End-to-End Test Scenarios
Run a complete industrial test scenario — discovery, access, lateral movement, process impact — in a controlled environment, and see which steps your controls catch.
Cyber Range Exercises
Run one scenario across a whole team, each person on their own isolated environment, on your own hardware. Command Center shows who got how far, so an exercise produces a result rather than an impression.
Security Control Validation
Confirm that defensive mechanisms do what they claim by testing them directly and observing how industrial security controls respond under pressure.
Direction 03
Validate Your Own Controls
The IDS, SIEM and detection you already pay for — pointed at a live plant.
Traffic · Telemetry · IDS · SIEM · Scenarios · Asset DiscoveryYou cannot validate detection logic using synthetic logs or isolated simulations. You need real industrial behaviour: live Modbus traffic, PLC state transitions, SCADA events, and network-level visibility across OT segments.
Labshock acts as a controlled OT traffic and telemetry generator that connects directly into external security ecosystems. It enables continuous validation of how well your tools see, interpret, and respond to industrial environments under realistic conditions.

Tidal Collector (Telemetry Export)
Streams real OT events — SCADA actions, PLC state changes, process signals — into any external SIEM or analytics platform. Used to validate ingestion pipelines, parsing accuracy, and normalization quality.
Surge Router (Network Mirroring)
Forwards raw industrial traffic (Modbus, S7, EtherNet/IP, DNP3) as SPAN/mirrored flows to external IDS systems or hardware appliances. Enables full packet-level validation outside Labshock.
IDS & NDR Validation
Test detection coverage from packet visibility to signature and anomaly detection. Verify whether IDS solutions correctly interpret OT protocol behaviour and industrial process anomalies.
SIEM & SOC Correlation Testing
Generate structured process and event sequences to test correlation rules, alert chaining, and SOC workflows. Validate whether incidents are detected, enriched, and escalated correctly.
Repeatable Scenarios
Run the same industrial scenario again after a rule change and compare what your stack caught. Detection work is only measurable when the input is identical each time.
Asset Discovery & Network Mapping
Evaluate whether external tools correctly identify PLCs, HMIs, historians, and OT endpoints. Validate passive and active discovery accuracy in real industrial traffic conditions.
AI / Detection Model Training
Feed labeled OT traffic into AI-based detection systems for training and evaluation. Enables behavioral modeling for anomaly detection and industrial context awareness.
Direction 04
Build The Environments You Need
Custom industrial environments. On demand.
IT · DMZ · OT · Multi-PLC · Custom RoutingEvery organization has a different OT architecture. A water utility looks nothing like a railroad control system. A gas terminal has different protocols, segmentation, and failure modes than a power substation. Generic labs teach generic skills. Labshock Builder lets you construct the specific infrastructure you need.
Define your IT, DMZ, and OT zones. Add PLCs, HMIs, SCADA servers, historians, and firewalls. Configure routing. Start the lab. The environment comes up fully operational, with real industrial process simulation running across every component.

Labshock Builder
Dynamic OT environment generator. Define network architecture across IT, DMZ, and OT layers. Automated routing, service orchestration, and security visibility configuration on deployment.
Industrial DMZ Architecture
Model enterprise-grade network segmentation with enforced zone isolation. Simulate firewall rules, restricted data paths, and cross-segment traffic exactly as deployed in critical infrastructure.
Portable Lab Format
Export complete cyber-physical environments as portable lab definitions. Share with teammates, deploy on another machine, or archive for repeatable training sessions and security exercises.
Command Center
User management and progression tracking. See XP, levels, completed guides, quests and badges across every user, and manage who has access to what.
Complex Multi-PLC Scenarios
Build environments with synchronized master-slave PLC operations, distributed process control, and multi-HMI configurations — the kind of complexity found in real industrial facilities.
