Zakhar Bernhardt (@zakharbernhardt) 's Twitter Profile
Zakhar Bernhardt

@zakharbernhardt

ICS/OT Cybersecurity Responder | Creator of Patented NVIDIA AI IDS & 1st OT SIEM | Industrial Pentester | Writer

ID: 1814139738506645504

linkhttp://linkedin.com/in/zakharb calendar_today19-07-2024 03:27:05

267 Tweet

136 Followers

106 Following

FBI (@fbi) 's Twitter Profile Photo

Cyber threat actors have targeted specific operational technology (OT) products to exploit common design weaknesses. OT owners and operators should read new guidance from the FBI and our partners on how to integrate security into the procurement process: ic3.gov/CSA/2025/25011…

Cyber threat actors have targeted specific operational technology (OT) products to exploit common design weaknesses. OT owners and operators should read new guidance from the FBI and our partners on how to integrate security into the procurement process: ic3.gov/CSA/2025/25011…
Zakhar Bernhardt (@zakharbernhardt) 's Twitter Profile Photo

📒 Week of Innovation 📒 Day 2 – Guides Guides in Labshock 2.0 are no longer static slides. 💾 They track what you do. You see progress in real time. You see outcomes, failures, and choices.

📒 Week of Innovation
📒 Day 2 – Guides
Guides in Labshock 2.0 are no longer static slides.

💾 They track what you do. 
You see progress in real time. 
You see outcomes, failures, and choices.
Zakhar Bernhardt (@zakharbernhardt) 's Twitter Profile Photo

2020 | Mirai wasn’t “just IoT” anymore. Industrial variants targeted IIoT devices using: > Default / weak creds > Telnet & SSH exposure Routers, cameras, network gear inside OT DDoS, unauthorized access, pivoting deeper Lesson: If it has an IP and a default password, it’s done

2020 | Mirai wasn’t “just IoT” anymore.

Industrial variants targeted IIoT devices using:
> Default / weak creds
> Telnet & SSH exposure

Routers, cameras, network gear inside OT
DDoS, unauthorized access, pivoting deeper

Lesson:
If it has an IP and a default password, it’s done
Zakhar Bernhardt (@zakharbernhardt) 's Twitter Profile Photo

2021 | Verkada camera breach = IIoT reality check Attackers accessed a publicly exposed Super Admin account 🎯 Industrial sites using cloud-managed cameras 👁️ 150,000+ live feeds from factories & warehouses Lesson: Cameras don’t look critical > until they expose your operations.

2021 | Verkada camera breach = IIoT reality check
Attackers accessed a publicly exposed Super Admin account
🎯 Industrial sites using cloud-managed cameras
👁️ 150,000+ live feeds from factories & warehouses

Lesson:
Cameras don’t look critical > until they expose your operations.
Zakhar Bernhardt (@zakharbernhardt) 's Twitter Profile Photo

OT SIEM ≠ IT SIEM. NIST 800-82 splits OT SIEM into Detect and Respond with safety and availability first. This is how we teach it in World of Labshock. world.labshocksecurity.com

OT SIEM ≠ IT SIEM.
NIST 800-82 splits OT SIEM into 
Detect and Respond
with safety and availability first.

This is how we teach it in World of Labshock.
world.labshocksecurity.com
Zakhar Bernhardt (@zakharbernhardt) 's Twitter Profile Photo

New Railway layout coming to Labshock 🚆 Multi-PLC master–slave logic, emergency stops, realistic system behavior. Built for learning, testing, and understanding complex OT Security! Soon.

New Railway layout coming to Labshock 🚆

Multi-PLC master–slave logic, emergency stops, realistic system behavior.

Built for learning, testing, and understanding complex OT Security!

Soon.
Zakhar Bernhardt (@zakharbernhardt) 's Twitter Profile Photo

2021 🥩 JBS Foods Ransomware Phishing led to compromised IT systems > and OT went down with it. Production stopped across the US, Canada & Australia. Lesson: IT breaches can shut down real-world operations. IT/OT separation matters.

2021 🥩  JBS Foods Ransomware 

Phishing led to compromised IT systems > and OT went down with it.

Production stopped across the US, Canada & Australia.

Lesson: IT breaches can shut down real-world operations.

IT/OT separation matters.
Zakhar Bernhardt (@zakharbernhardt) 's Twitter Profile Photo

2020 | EKANS Ransomware ICS processes taken hostage. Production lines stopped. Plants went silent. Targeted ICS: GE, Honeywell & more. Honda plants shut worldwide. IT defenses failed. OT needs its own shield. #Labshock + OT SIEM protects what matters.

2020 | EKANS Ransomware

ICS processes taken hostage. 
Production lines stopped. 
Plants went silent.

Targeted ICS: GE, Honeywell & more. 
Honda plants shut worldwide.

IT defenses failed. OT needs its own shield.

#Labshock + OT SIEM protects what matters.
Zakhar Bernhardt (@zakharbernhardt) 's Twitter Profile Photo

Siemens S7 protocol runs many OT environments & it’s still largely insecure. • TCP port 102 • No auth, no encryption • Read/write PLC memory (I, Q, M, DB) • Real impact on physical processes Visibility on S7 traffic = huge win for OT defense. #Labshock

Siemens S7 protocol runs many OT environments 
&
it’s still largely insecure.
• TCP port 102
• No auth, no encryption
• Read/write PLC memory (I, Q, M, DB)
• Real impact on physical processes

Visibility on S7 traffic = huge win for OT defense.
#Labshock
Zakhar Bernhardt (@zakharbernhardt) 's Twitter Profile Photo

#Labshock How To view & detect new IP/protocols in ICS network in real time! Here’s why that matters: it can catch suspicious devices or rogue scanners before they cause damage to your OT Process.

Zakhar Bernhardt (@zakharbernhardt) 's Twitter Profile Photo

☢️ #Labshock Masterclass ☢️ First Dive into Siemens S7 Inputs, outputs & PLC cycle. Feb 08, live & free discord.gg/bpmaQFfW76

☢️ #Labshock Masterclass ☢️
First Dive into Siemens S7 

Inputs, outputs & PLC cycle. 

Feb 08, live & free

discord.gg/bpmaQFfW76
Zakhar Bernhardt (@zakharbernhardt) 's Twitter Profile Photo

Pentest Fury update live in Labshock: full S7 support (read I/O, write DB & Merker). Safe virtual PLC. New clean 2.0 look. Live test + CNC tomorrow in Masterclass. Join us. discord.gg/bpmaQFfW76

Pentest Fury update live in Labshock: 
full S7 support (read I/O, write DB & Merker). 

Safe virtual PLC. New clean 2.0 look. 
Live test + CNC tomorrow in Masterclass. 
Join us.
discord.gg/bpmaQFfW76