Technical field guide

The sections below preserve the service-specific depth behind OT, ICS & SCADA Forensics, edited for the current national practice and its documented engagement model. Methods are selected for the source, authorization, system state and assigned specialty. No single tool or artifact establishes a conclusion, and legal, regulatory or certification decisions remain with the responsible authority.

Preserve evidence without losing the process

OT, ICS and SCADA forensics examines digital records around a cyber event, equipment malfunction, unexplained process change or suspected unauthorized access. The first priority is safe operations. Evidence collection is coordinated with plant engineering and process owners so the method does not interfere with safety systems, controller timing, availability or recovery work.

The initial record captures alarms, operator actions, network state, affected zones, current logic and any emergency change already made. Volatile sources are ranked by retention and operational risk. A controller memory capture may be valuable, but not if the method creates a process hazard or destroys the state it was meant to preserve.

Industrial evidence sources

Potential sources include engineering workstations, HMI and SCADA servers, historians, jump hosts, firewalls, VPN systems, identity services, controller logic, configuration backups, field gateways, safety systems and passive network captures. Many devices have limited logs or vendor-specific export methods. The source map identifies the owner, time source, retention, acquisition method and known gaps for each.

Logic, configuration and firmware comparison

Controller and engineering records can be compared with approved project files, backups and change-management records. Relevant differences may include logic, setpoints, timers, communications, users, firmware or safety configuration. A difference is not automatically malicious. Maintenance, replacement, failed commissioning and undocumented operator changes are considered alongside cyber explanations.

Binary or firmware review may be appropriate when a supported comparison or known-good image exists. The report identifies what the extraction covers and whether signing, encryption, proprietary formats or missing reference material limits interpretation.

Build a cross-system timeline

Industrial clocks may drift, use local time, reset on power loss or lack a reliable time source. Network records, historian values, operator logs, controller events and enterprise identity records are normalized with those offsets stated. The timeline separates the initiating event, control actions, process consequences and later response changes where the evidence supports that sequence.

Technical findings for operations and counsel

Deliverables can include a source and collection matrix, normalized event timeline, logic or configuration comparison, network path analysis, affected-asset inventory and technical report. The report distinguishes observed records from causal opinions and records missing logs, source changes and safety-driven limits.