OT/ICS/SCADA Forensics
Forensic response, triage, and analysis of cyber incidents affecting industrial control systems, SCADA networks, and critical infrastructure. Water treatment, power generation, energy distribution, transportation, and manufacturing.
What Is OT/ICS/SCADA Forensics?
OT/ICS/SCADA forensics is the specialized discipline of collecting, preserving, and analyzing digital evidence from operational technology environments after a cyber incident, equipment malfunction, or suspected sabotage. These environments run the physical processes behind water treatment plants, power generation stations, electrical distribution grids, oil and gas pipelines, railroad signaling systems, traffic control networks, and manufacturing facilities.
Unlike traditional IT forensics, OT forensic analysis must account for real-time process control requirements, safety-critical systems that cannot be taken offline, proprietary protocols (Modbus, DNP3, EtherNet/IP, OPC UA, IEC 61850), and the convergence of IT and OT networks that creates new attack surfaces. GDF brings decades of experience in both digital forensics and industrial control environments to deliver forensic findings that support litigation, regulatory compliance, and operational recovery.
Incident Triage and Safety Assessment
Every OT forensic engagement begins with a safety-first assessment. Before any evidence collection, GDF's responders coordinate with plant engineers and operations staff to verify that forensic procedures will not interfere with active safety systems, emergency shutdown logic, or real-time process control.
The triage phase establishes the scope of the incident across IT/OT boundaries, identifies which control systems and network segments are affected, and documents the initial state of the environment. This includes recording alarm states, operator actions, and any process anomalies that correlate with the suspected event timeline. Volatile evidence (PLC memory contents, active network sessions, running ladder logic) is catalogued for priority collection before it is overwritten by normal system operations.
Evidence Collection in OT Environments
Collecting forensic evidence from industrial control systems requires specialized techniques that differ from standard IT forensics. Many OT devices have limited logging, proprietary file systems, and firmware that cannot be imaged using conventional tools. GDF deploys purpose-built collection procedures for each device class:
- PLC memory dumps and ladder logic extraction using vendor-specific diagnostic interfaces
- HMI session recording and configuration backup recovery
- Historian database extraction with timestamp integrity verification
- SCADA server forensic imaging (Windows, Linux, and RTOS platforms)
- Network traffic capture from industrial protocols (Modbus TCP, DNP3, EtherNet/IP, PROFINET, BACnet)
- Firewall, jump server, and VPN logs from the IT/OT demilitarized zone (DMZ)
- Engineering workstation examination for unauthorized project file modifications
- Safety instrumented system (SIS) configuration and trip log recovery
GDF follows the Dragos-recommended Collection Management Framework (CMF) approach, which maps all available data sources in the OT environment, documents how each can be accessed, and records what incident response questions each source can answer. This methodology ensures that evidence collection is thorough, non-disruptive, and defensible.
Control Logic and Firmware Analysis
The most critical phase of OT forensics is analyzing the control logic and firmware running on PLCs, RTUs, and safety controllers. An attacker who gains access to a PLC can modify ladder logic, function block diagrams, or structured text programs to alter physical process behavior while the HMI displays normal readings to operators.
GDF's analysts compare extracted control logic against known-good baseline configurations provided by the asset owner or recovered from engineering workstation backups. Register values, timer configurations, setpoint thresholds, and communication parameters are examined for unauthorized modifications. Firmware images are analyzed at the binary level to detect malicious code injection, backdoor implants, or modifications to interrupt service routines.
For environments where baseline configurations are unavailable, GDF's analysts examine logic patterns against industry-standard templates and engineering documentation to identify anomalous structures that do not align with the documented control strategy.
OT Network Forensic Analysis
Network forensics in OT environments focuses on reconstructing the attacker's path from the corporate IT network into the operational technology zone. GDF analyzes:
- Lateral movement through the IT/OT DMZ, including compromised jump servers and VPN concentrators
- Industrial protocol traffic for command injection, parameter manipulation, and unauthorized function codes
- Communication between PLCs, RTUs, and the SCADA master that deviates from baseline patterns
- Data exfiltration channels, including covert communication over industrial protocols
- Historian data manipulation that may have been used to conceal process changes
Because OT networks are typically deterministic (devices communicate in predictable patterns), deviations from established baselines are often strong indicators of compromise. GDF correlates network evidence with PLC logic changes, operator logs, and process data to build a comprehensive attack timeline.
Critical Infrastructure Sectors We Support
GDF has performed OT/ICS/SCADA forensic analysis across the sectors that form the backbone of critical infrastructure:
- Water and wastewater treatment: SCADA-controlled chemical dosing, pump stations, filtration systems, and distribution networks
- Power generation: Turbine control systems, boiler management, distributed control systems (DCS), and generator protection relays
- Electrical transmission and distribution: Substation automation, intelligent electronic devices (IEDs), synchrophasor networks, and DERMS
- Oil and gas: Pipeline SCADA, compressor station controls, tank farm monitoring, and safety instrumented systems
- Transportation: Railroad signaling and positive train control (PTC), air traffic control, traffic management systems, and port operations
- Manufacturing: Robotic cell controllers, CNC machine networks, quality control instrumentation, and batch process automation
Regulatory and Compliance Support
Incidents affecting critical infrastructure trigger reporting obligations and regulatory scrutiny. GDF's forensic documentation is structured to support compliance requirements across multiple frameworks:
- CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act): 72-hour reporting to CISA for covered entities
- NERC CIP (Critical Infrastructure Protection): Evidence preservation and reporting for bulk electric system incidents
- EPA and state drinking water regulations: Documentation for incidents affecting public water systems
- TSA Security Directives: Pipeline cybersecurity incident reporting and response documentation
- NIST Cybersecurity Framework (CSF) and SP 800-82: Alignment with federal ICS security guidance
- IEC 62443: Industrial automation and control systems security lifecycle documentation
Methodology and Standards
GDF's OT forensic methodology integrates established frameworks adapted for industrial control environments. Our process follows SANS ICS incident response guidance, the Dragos Collection Management Framework, MITRE ATT&CK for ICS tactics and techniques mapping, and NIST SP 800-82 guidelines for ICS security. All evidence handling follows chain-of-custody procedures that meet federal court admissibility standards, and our analysts hold GICSP (Global Industrial Cyber Security Professional), GRID (GIAC Response and Industrial Defense), and traditional digital forensics certifications.
Last updated: April 16, 2026
Incident Response Triage
Safety-first assessment, IT/OT boundary scoping, volatile evidence prioritization, and coordination with plant operations to preserve critical forensic artifacts without disrupting active process control.
PLC and Controller Forensics
Memory dump extraction, ladder logic comparison against baselines, firmware binary analysis, register value examination, and detection of unauthorized control program modifications across all major PLC vendors.
SCADA Network Analysis
Full-packet capture of industrial protocols, lateral movement reconstruction from IT to OT zones, historian data integrity verification, and mapping of adversary tactics to MITRE ATT&CK for ICS.
Regulatory Documentation
Forensic reports structured for CIRCIA, NERC CIP, EPA, and TSA compliance. Expert declarations and testimony support for regulatory proceedings and civil litigation arising from critical infrastructure incidents.
Request an OT/ICS Forensics Consultation
All consultations are strictly confidential. GDF's OT forensics team is available around the clock for critical infrastructure incidents.
Related Services
SCADA Security Testing
Proactive security assessment of SCADA systems, HMIs, and industrial communication protocols to identify vulnerabilities before they are exploited.
ICS Penetration Testing
Controlled adversary simulation against industrial control networks to test defenses, segmentation, and detection capabilities.
Network Forensics
Analysis of network traffic, logs, and packet captures to reconstruct cyber incidents and support litigation.
Critical Infrastructure Under Attack?
When industrial control systems are compromised, safety and operational continuity are at stake. Contact GDF for immediate OT forensic response.