24/7 Emergency Response: 1-800-868-8189
Forensic Services

OT/ICS/SCADA Forensics

Forensic response, triage, and analysis of cyber incidents affecting industrial control systems, SCADA networks, and critical infrastructure. Water treatment, power generation, energy distribution, transportation, and manufacturing.

GDF OT/ICS/SCADA Forensics Process: 5-step methodology from incident triage through findings and reporting
Industrial control room with SCADA monitoring screens showing power grid and water treatment supervisory control displays during forensic incident analysis

What Is OT/ICS/SCADA Forensics?

OT/ICS/SCADA forensics is the specialized discipline of collecting, preserving, and analyzing digital evidence from operational technology environments after a cyber incident, equipment malfunction, or suspected sabotage. These environments run the physical processes behind water treatment plants, power generation stations, electrical distribution grids, oil and gas pipelines, railroad signaling systems, traffic control networks, and manufacturing facilities.

Unlike traditional IT forensics, OT forensic analysis must account for real-time process control requirements, safety-critical systems that cannot be taken offline, proprietary protocols (Modbus, DNP3, EtherNet/IP, OPC UA, IEC 61850), and the convergence of IT and OT networks that creates new attack surfaces. GDF brings decades of experience in both digital forensics and industrial control environments to deliver forensic findings that support litigation, regulatory compliance, and operational recovery.

Incident Triage and Safety Assessment

Every OT forensic engagement begins with a safety-first assessment. Before any evidence collection, GDF's responders coordinate with plant engineers and operations staff to verify that forensic procedures will not interfere with active safety systems, emergency shutdown logic, or real-time process control.

The triage phase establishes the scope of the incident across IT/OT boundaries, identifies which control systems and network segments are affected, and documents the initial state of the environment. This includes recording alarm states, operator actions, and any process anomalies that correlate with the suspected event timeline. Volatile evidence (PLC memory contents, active network sessions, running ladder logic) is catalogued for priority collection before it is overwritten by normal system operations.

Evidence Collection in OT Environments

Collecting forensic evidence from industrial control systems requires specialized techniques that differ from standard IT forensics. Many OT devices have limited logging, proprietary file systems, and firmware that cannot be imaged using conventional tools. GDF deploys purpose-built collection procedures for each device class:

  • PLC memory dumps and ladder logic extraction using vendor-specific diagnostic interfaces
  • HMI session recording and configuration backup recovery
  • Historian database extraction with timestamp integrity verification
  • SCADA server forensic imaging (Windows, Linux, and RTOS platforms)
  • Network traffic capture from industrial protocols (Modbus TCP, DNP3, EtherNet/IP, PROFINET, BACnet)
  • Firewall, jump server, and VPN logs from the IT/OT demilitarized zone (DMZ)
  • Engineering workstation examination for unauthorized project file modifications
  • Safety instrumented system (SIS) configuration and trip log recovery

GDF follows the Dragos-recommended Collection Management Framework (CMF) approach, which maps all available data sources in the OT environment, documents how each can be accessed, and records what incident response questions each source can answer. This methodology ensures that evidence collection is thorough, non-disruptive, and defensible.

Control Logic and Firmware Analysis

The most critical phase of OT forensics is analyzing the control logic and firmware running on PLCs, RTUs, and safety controllers. An attacker who gains access to a PLC can modify ladder logic, function block diagrams, or structured text programs to alter physical process behavior while the HMI displays normal readings to operators.

GDF's analysts compare extracted control logic against known-good baseline configurations provided by the asset owner or recovered from engineering workstation backups. Register values, timer configurations, setpoint thresholds, and communication parameters are examined for unauthorized modifications. Firmware images are analyzed at the binary level to detect malicious code injection, backdoor implants, or modifications to interrupt service routines.

For environments where baseline configurations are unavailable, GDF's analysts examine logic patterns against industry-standard templates and engineering documentation to identify anomalous structures that do not align with the documented control strategy.

OT Network Forensic Analysis

Network forensics in OT environments focuses on reconstructing the attacker's path from the corporate IT network into the operational technology zone. GDF analyzes:

  • Lateral movement through the IT/OT DMZ, including compromised jump servers and VPN concentrators
  • Industrial protocol traffic for command injection, parameter manipulation, and unauthorized function codes
  • Communication between PLCs, RTUs, and the SCADA master that deviates from baseline patterns
  • Data exfiltration channels, including covert communication over industrial protocols
  • Historian data manipulation that may have been used to conceal process changes

Because OT networks are typically deterministic (devices communicate in predictable patterns), deviations from established baselines are often strong indicators of compromise. GDF correlates network evidence with PLC logic changes, operator logs, and process data to build a comprehensive attack timeline.

Critical Infrastructure Sectors We Support

GDF has performed OT/ICS/SCADA forensic analysis across the sectors that form the backbone of critical infrastructure:

  • Water and wastewater treatment: SCADA-controlled chemical dosing, pump stations, filtration systems, and distribution networks
  • Power generation: Turbine control systems, boiler management, distributed control systems (DCS), and generator protection relays
  • Electrical transmission and distribution: Substation automation, intelligent electronic devices (IEDs), synchrophasor networks, and DERMS
  • Oil and gas: Pipeline SCADA, compressor station controls, tank farm monitoring, and safety instrumented systems
  • Transportation: Railroad signaling and positive train control (PTC), air traffic control, traffic management systems, and port operations
  • Manufacturing: Robotic cell controllers, CNC machine networks, quality control instrumentation, and batch process automation

Regulatory and Compliance Support

Incidents affecting critical infrastructure trigger reporting obligations and regulatory scrutiny. GDF's forensic documentation is structured to support compliance requirements across multiple frameworks:

  • CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act): 72-hour reporting to CISA for covered entities
  • NERC CIP (Critical Infrastructure Protection): Evidence preservation and reporting for bulk electric system incidents
  • EPA and state drinking water regulations: Documentation for incidents affecting public water systems
  • TSA Security Directives: Pipeline cybersecurity incident reporting and response documentation
  • NIST Cybersecurity Framework (CSF) and SP 800-82: Alignment with federal ICS security guidance
  • IEC 62443: Industrial automation and control systems security lifecycle documentation

Methodology and Standards

GDF's OT forensic methodology integrates established frameworks adapted for industrial control environments. Our process follows SANS ICS incident response guidance, the Dragos Collection Management Framework, MITRE ATT&CK for ICS tactics and techniques mapping, and NIST SP 800-82 guidelines for ICS security. All evidence handling follows chain-of-custody procedures that meet federal court admissibility standards, and our analysts hold GICSP (Global Industrial Cyber Security Professional), GRID (GIAC Response and Industrial Defense), and traditional digital forensics certifications.

Last updated: April 16, 2026

Incident Response Triage

Safety-first assessment, IT/OT boundary scoping, volatile evidence prioritization, and coordination with plant operations to preserve critical forensic artifacts without disrupting active process control.

PLC and Controller Forensics

Memory dump extraction, ladder logic comparison against baselines, firmware binary analysis, register value examination, and detection of unauthorized control program modifications across all major PLC vendors.

SCADA Network Analysis

Full-packet capture of industrial protocols, lateral movement reconstruction from IT to OT zones, historian data integrity verification, and mapping of adversary tactics to MITRE ATT&CK for ICS.

Regulatory Documentation

Forensic reports structured for CIRCIA, NERC CIP, EPA, and TSA compliance. Expert declarations and testimony support for regulatory proceedings and civil litigation arising from critical infrastructure incidents.

Request an OT/ICS Forensics Consultation

All consultations are strictly confidential. GDF's OT forensics team is available around the clock for critical infrastructure incidents.

Critical Infrastructure Under Attack?

When industrial control systems are compromised, safety and operational continuity are at stake. Contact GDF for immediate OT forensic response.