The Worst ICS/OT Love Story Every Told - 2025 Mike Holcomb
Mike Holcomb (Fluor)
DEF CON 33 · Day 1 · Main Stage
Overview
In "The Worst ICS/OT Love Story Ever Told," Mike Holcomb, a seasoned professional from Fluor, delves into the critical and often overlooked cybersecurity challenges within Industrial Control Systems (ICS) and Operational Technology (OT) environments. Filling in for another speaker at DEF CON, Holcomb leverages his extensive experience to expose the pervasive misconceptions and vulnerabilities that plague these vital infrastructures. The talk centers on the transformative potential of Generative AI (GenAI), specifically ChatGPT, as a powerful tool for both offensive and defensive security operations in OT, even for individuals without a background in software development.

Key moments
- 0:00 Introduction, speaker's background, and Stuxnet's impact
- 1:55 Stuxnet's deceptive nature: operators unaware of damage
- 3:35 Challenging the myth: 'PLCs aren't vulnerable'
- 4:50 Master's project: Monitoring PLC run mode remotely
- 5:25 PLC run mode: understanding security benefits and limitations
- 6:55 The non-developer's challenge: building a web interface
- 7:35 Leveraging GenAI (ChatGPT) for security tool development
The Worst ICS/OT Love Story Ever Told - 2025 Mike Holcomb
Speakers: Mike Holcomb, Fluor
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=iVmS5dPjggU
Overview
In "The Worst ICS/OT Love Story Ever Told," Mike Holcomb, a seasoned professional from Fluor, delves into the critical and often overlooked cybersecurity challenges within Industrial Control Systems (ICS) and Operational Technology (OT) environments. Filling in for another speaker at DEF CON, Holcomb leverages his extensive experience to expose the pervasive misconceptions and vulnerabilities that plague these vital infrastructures. The talk centers on the transformative potential of Generative AI (GenAI), specifically ChatGPT, as a powerful tool for both offensive and defensive security operations in OT, even for individuals without a background in software development.
Holcomb’s presentation is a stark reminder of the unique complexities and inherent risks associated with securing the physical world's digital backbone. He meticulously illustrates how fundamental security gaps, such as a lack of accurate asset inventory and the exposure of critical control systems to the public internet, create fertile ground for devastating attacks. By demonstrating how easily GenAI can be harnessed to identify vulnerabilities, develop custom reconnaissance tools, and even deploy sophisticated honeypots, Holcomb underscores a critical paradigm shift: the barrier to entry for effective OT security, whether for good or ill, has been dramatically lowered.
This talk is particularly pertinent for anyone involved in critical infrastructure, manufacturing, or industrial automation, highlighting that the "PLC is not vulnerable" mindset is not only outdated but dangerously naive. It challenges conventional wisdom, urging defenders to embrace innovative approaches and leverage emerging technologies like GenAI to understand and counteract the evolving threat landscape in OT. The underlying message is clear: the integration of AI into security workflows is no longer a futuristic concept but an immediate necessity for navigating the precarious "love story" between complex OT systems and persistent cyber threats.
Background
▶ Watch: Introduction, speaker's background, and Stuxnet's impact (0:00)
Mike Holcomb's journey into the intricate world of Operational Technology (OT) cybersecurity began notably in 2010 with the emergence of Stuxnet. He recounts being fascinated not merely by its use of four Windows zero-days or its ability to manipulate nuclear centrifuges, but by its deceptive elegance: operators in the control room saw normal operations while the centrifuges were physically breaking down behind the scenes. This demonstration of physical impact through cyber means solidified his commitment to understanding and securing OT environments.
A pivotal moment that shaped this talk was a conversation Holcomb had early in his OT career with a leader of one of the world's largest OT cybersecurity programs. When Holcomb suggested potential attack vectors against a Programmable Logic Controller (PLC), the response was dismissive: "Yeah, but it's a PLC. It's not vulnerable." This alarming lack of awareness, even at a high level, propelled Holcomb to delve deeper. He quickly found a CVE for that specific PLC model within 30 seconds, reaffirming his initial instincts and highlighting a significant knowledge gap pervasive in the industry.
This experience directly informed his Masters thesis project at SANS. Recognizing that asset inventory is a universal struggle in both IT and OT—where it's "a million times worse"—Holcomb aimed to create a system for monitoring the run mode status of PLCs. The goal was to build a web interface with backend scripts that could remotely query various vendor PLCs to determine if they were in run mode. Run mode, often perceived as a "read-only" state, is more secure than other modes, preventing remote firmware uploads or unauthorized programming changes. Detecting a PLC exiting run mode would flag a potential security incident, such as an unscheduled technician intervention or malicious activity.
The primary hurdle for Holcomb, a self-admitted non-developer, was the actual coding required for such a system. His frustration with traditional development led him to a crucial realization: if ransomware groups were leveraging ChatGPT to build functional phishing platforms, he could certainly use it to develop his OT security tools. This insight became the genesis of the "Worst ICS/OT Love Story," demonstrating how generative AI could bridge the skill gap and democratize tool creation for OT security professionals.
Key Findings
▶ Watch: Challenging the myth: 'PLCs aren't vulnerable' (3:35)
The talk unveils several critical findings that challenge conventional wisdom and highlight both the vulnerabilities and the innovative solutions in OT cybersecurity:
- Generative AI as an OT Security Enabler: The most significant finding is the powerful capability of GenAI, exemplified by ChatGPT, to rapidly generate functional security tools and scripts for OT/ICS environments. This dramatically lowers the barrier to entry for non-developers, allowing them to create custom solutions for tasks ranging from network scanning and asset inventory to honeypot deployment in minutes.
- Pervasive OT Vulnerability Misconceptions: A dangerous "PLC is not vulnerable" mindset persists even among experienced OT security professionals. This lack of awareness leads to critical security oversights and underestimation of attack surfaces, particularly concerning common industrial control systems.
- Critical Asset Inventory Deficiencies: OT environments suffer from significantly worse asset inventory practices compared to IT. Many organizations, including critical infrastructure like power plants and nuclear facilities, lack accurate and comprehensive records of their control systems, their connectivity, and their IP addresses.
- Widespread Internet Exposure of Critical OT: Despite best practices, a substantial number of operational PLCs and control systems are directly exposed to the public internet. This exposure is often easily discoverable through simple search engine queries (Google dorking) using information derived from publicly available sources like NSA-released Snort signatures, bypassing specialized tools like Shodan in some instances.
- "Living Off The Land" is Essential in OT: Due to stringent operational constraints and resistance to installing new software, leveraging native operating system tools and scripting languages like PowerShell is crucial for security operations in Windows-heavy OT environments. GenAI facilitates the conversion of scripts between languages, enabling this approach.
- Affordable and Effective OT Honeypots are Attainable: High-fidelity OT honeypots, previously requiring significant investment in commercial solutions, can be created quickly and cheaply using GenAI. These custom honeypots effectively simulate PLC behavior, detecting early reconnaissance and interaction with industrial protocols like Modbus, offering invaluable early warning capabilities.
Technical Deep Dive
▶ Watch: Master's project: Monitoring PLC run mode remotely (4:50)
Holcomb's technical deep dive illustrates the practical application of GenAI in developing OT security tools, progressing from basic scripting to complex network monitoring and defensive mechanisms.
The journey begins with a foundational demonstration of GenAI's code generation capabilities. Holcomb tasked ChatGPT with creating a simple Python script, moving beyond the typical "Hello World" to "Hello Friend," a nod to the TV show Mr. Robot. This initial step showcased GenAI's ability to provide not just the code, but also explanations and execution instructions, making it accessible even to those unfamiliar with programming syntax.
Next, Holcomb escalated the complexity by requesting a basic port scanner, a "mini Nmap," in Python. This scanner was designed to check for common web ports (80, 443) alongside critical OT protocol ports: 102 (Siemens S7), 502 (Modbus), and 44818 (Ethernet/IP). Modbus, specifically, is highlighted as the most commonly used OT protocol due to its open-source nature. The GenAI-generated script successfully identified open ports on a home Wi-Fi access point (443 for an admin page) and an OT network (502 for Modbus on a PLC), demonstrating its immediate utility for reconnaissance.
A crucial aspect of OT security is the concept of "living off the land," avoiding the installation of new software which can violate operational policies or introduce instability. Recognizing the prevalence of Windows machines in OT environments, Holcomb challenged ChatGPT to convert the Python port scanner into PowerShell. Initially, the generated PowerShell script had errors, a common occurrence. However, by feeding the error message back to ChatGPT, the AI successfully debugged and corrected its own code, emphasizing its value not just for generation but also for troubleshooting—a significant time-saver, particularly with verbose Linux error messages.
The talk then addresses the critical issue of asset inventory in OT. Active scanning with tools like Nmap is often avoided in OT due to the risk of crashing sensitive control systems. Holcomb demonstrated how GenAI could create a script to passively extract asset information from PCAP (packet capture) files. The script initially extracted IP and MAC addresses from network traffic. A key enhancement, iteratively requested from ChatGPT, was the addition of a graphical user interface (GUI) for easy file selection, transforming a command-line tool into a more user-friendly utility. The script then performed a reverse lookup on the first half of the MAC address to identify the manufacturer and outputted the findings into an Excel spreadsheet, a common format for asset registers in OT.
A particularly alarming section detailed the discovery of internet-exposed PLCs. Holcomb reminisced about Shodan, which originated as a tool to find exposed control systems. He then referenced the NSA's release of the Elite Wolf project, initially perceived as merely Snort signatures. However, upon closer inspection, he realized these signatures contained URLs for specific Allen-Bradley Rockwell PLCs, a major OT vendor. By simply pasting these URLs into Google, Holcomb demonstrated how easily one could find dozens of active, internet-connected PLCs (around 60 instances at the time of the talk), bypassing traditional Shodan searches for these specific models. He explained that these PLCs, essentially "little computers physically wired into physical systems," control critical processes like turbine RPM and temperature in power plants. Further analysis of these exposed systems using netstat revealed internal IP addresses and numerous public IP addresses connecting via ports like 80 (web interface) and 44818 (Ethernet/IP), indicating active reconnaissance and potential manipulation attempts. To visualize the global reach of these connections, Holcomb used ChatGPT to create a script that mapped the source IP addresses onto a geographical map.
Throughout these technical examples, Holcomb stressed an important principle for effective GenAI use: iterative development. Instead of asking the AI to perform ten tasks at once and risking failure, he advised breaking down requests into single, testable steps. "Do one thing, test it, make sure it works, then add something else, test it, make sure it works." This iterative process, he argued, significantly increases success rates and saves time.
Demo / Proof of Concept
▶ Watch: The non-developer's challenge: building a web interface (6:55)
The culminating demonstration of the talk focused on the creation of a highly effective and low-cost OT honeypot using ChatGPT, challenging the notion that such tools require expensive commercial solutions. Holcomb highlighted the exorbitant costs associated with commercial honeypot vendors, contrasting them with the simplicity and affordability of an AI-generated alternative.
The initial step involved instructing ChatGPT to create a basic listener on TCP port 502, the standard port for Modbus, the most prevalent OT protocol. This honeypot was designed for fundamental detection:
- Ping Detection: It would alert if the machine hosting the honeypot received an ICMP ping, indicating basic network reconnaissance.
- Port Scan Detection: It would detect port scans by monitoring TCP handshake anomalies. Specifically, if the honeypot received a SYN packet and responded with a SYN-ACK, but did not receive the final ACK from the client, it would flag this as a port scan, typically performed by tools like Nmap. Such activity is highly unusual and suspicious in a legitimate OT environment.
Holcomb then advanced the honeypot's capabilities to simulate a realistic PLC. Real PLCs store operational data in two primary forms:
- Coils: These are single-bit registers that store binary values (0 or 1), often representing the on/off status of a component (e.g., turbine on/off).
- Registers: These store larger numerical values, typically ranging from 0 to 65,535, representing measurements like temperature, pressure, or RPM.
The enhanced GenAI-created honeypot not only listened for pings and port scans but also allowed an attacker to connect to it as if it were a genuine PLC. It simulated the presence of coils and registers, populating them with dummy values. Crucially, the honeypot was configured to detect attempts to read and, more importantly, write to these coils and registers. An attacker attempting to write to a coil—for instance, changing a "turbine on" coil from 1 to 0—would instantly trigger a high-fidelity alert, indicating a confirmed malicious actor in the environment. Holcomb emphasized the simplicity of such an attack in many real-world OT systems, where changing a single bit can directly impact physical operations. This proof of concept elegantly demonstrated how GenAI could empower defenders to deploy sophisticated, protocol-aware detection mechanisms without requiring specialized development skills or significant financial outlay.
Defensive Implications
▶ Watch: Leveraging GenAI (ChatGPT) for security tool development (7:35)
The insights from Mike Holcomb’s talk provide several critical defensive implications for organizations operating ICS/OT environments:
- Prioritize and Automate Asset Inventory: Given the "million times worse" state of OT asset registers, organizations must invest heavily in comprehensive inventory solutions. Defenders should leverage passive methods, such as analyzing PCAP files with AI-generated scripts, to identify connected devices, their IP/MAC addresses, and manufacturers without risking system disruption. The ability of GenAI to quickly create custom scripts for data extraction and visualization (e.g., outputting to Excel) can significantly accelerate this process.
- Actively Hunt for Internet-Exposed OT Devices: The discovery of numerous internet-exposed PLCs via simple Google dorking using NSA Elite Wolf URLs underscores a severe vulnerability. Security teams must proactively search for their own exposed assets using similar techniques and platforms like Shodan. Remediation efforts should prioritize removing direct internet connectivity, implementing robust network segmentation, and ensuring secure remote access solutions.
- Implement Robust Network Security Monitoring (NSM): The talk emphasizes the importance of NSM, particularly through the use of low-cost, AI-generated honeypots. Defenders should deploy these custom honeypots on key OT network segments to detect early reconnaissance activities like pings and port scans, as well as attempts to interact with industrial protocols such as Modbus (port 502) and Ethernet/IP (port 44818). High-fidelity alerts generated by write attempts to simulated coils and registers provide undeniable evidence of malicious intent.
- Leverage Generative AI for Custom Tool Development: Security teams, even those without dedicated developers, should embrace GenAI platforms like ChatGPT to rapidly create custom scripts for specific OT security tasks. This includes tailored scanners, PCAP analysis tools, log parsers, and specialized detection rules. The "living off the land" principle dictates a preference for PowerShell scripts on Windows-based OT systems, and GenAI can facilitate quick conversions and debugging.
- Educate and Challenge the "PLC Isn't Vulnerable" Mindset: A fundamental shift in organizational culture is required. OT engineers and operators must be educated about the real-world vulnerabilities of PLCs and other control systems. Training should cover common attack vectors, the importance of secure configurations (e.g., ensuring PLCs remain in run mode), and the severe physical consequences of cyber incidents.
- Enforce Secure Configurations and Change Management: Monitoring for deviations from secure configurations, such as PLCs unexpectedly exiting run mode, is crucial. Automated alerts for such changes can help detect unauthorized modifications or malicious activities in real-time.
- Embrace Iterative Development for AI-Assisted Security: When using GenAI for security tasks, adopt an iterative approach: start with simple requests, test thoroughly, and incrementally add complexity. This methodology, as highlighted by Holcomb, is more efficient and leads to more robust solutions.
Key Takeaways
- GenAI Empowers Non-Developers: Generative AI platforms like ChatGPT significantly lower the barrier for creating custom OT security tools, enabling individuals without extensive programming experience to develop powerful scripts for defense and analysis.
- Critical OT Assets are Exposed and Undocumented: Many OT environments suffer from severe deficiencies in asset inventory and have critical control systems (like PLCs) directly exposed to the internet, making them easily discoverable via simple search engines.
- Passive Monitoring is Key for OT Asset Discovery: Due to the sensitivity of OT systems, active scanning is often risky. Passive analysis of network traffic (PCAP files) combined with AI-generated scripts is a safer and effective method for asset identification and inventory.
- Affordable, High-Fidelity OT Honeypots are Achievable: Defenders can create effective, protocol-aware honeypots for Modbus and other OT protocols using GenAI in minutes, offering high-fidelity detection of attacker reconnaissance and interaction attempts without significant financial investment.
- The "PLC is Not Vulnerable" Mindset is Dangerous: A pervasive misconception that PLCs are inherently secure or invulnerable to cyberattacks creates significant blind spots and must be actively challenged and corrected through education and practical demonstrations.
- "Living Off The Land" is Crucial in OT: Leveraging native operating system tools and scripting languages (like PowerShell in Windows environments) with the aid of GenAI is an essential strategy for security operations in OT, where installing third-party software is often restricted.
About the Speaker(s)
Mike Holcomb is a seasoned professional with over 14 years of experience at Fluor, one of the world's largest engineering and construction companies. His immersion into the field of Operational Technology (OT) cybersecurity began around 2010, coinciding with the infamous Stuxnet incident, which profoundly shaped his understanding of the unique challenges and impacts of cyber threats on physical systems.
Holcomb is a vocal advocate for OT/ICS cybersecurity, frequently sharing his insights and expertise on platforms like LinkedIn. He is also dedicated to educating others, having developed a comprehensive 25-hour introductory course on OT/ICS cybersecurity available on YouTube. His academic background includes a Master's degree obtained through SANS, where his thesis project focused on practical security challenges in OT environments. At DEF CON, he stepped in as a replacement speaker, delivering a talk originally presented at BSides ICS, an OT-specific security conference that he helped establish and continues to support globally.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Holcomb knows OT/ICS cold and the core message — PLCs are vulnerable, asset inventory is a disaster, internet exposure is real — is correct and worth repeating at DEF CON. But the actual technical contribution is thin: using ChatGPT to write a Modbus listener and a PCAP parser isn't novel research, it's a tutorial. The talk lands squarely in 'competent practitioner shares field wisdom' territory, not original research.
Heather Calloway (CISO) — SOLID
Holcomb knows OT cold, and his core insight — that GenAI meaningfully lowers the barrier for defenders operating in resource-constrained industrial environments — is real and practically grounded. But the talk stays at the tool-builder level and never climbs to the institutional questions that make OT exposure a governance crisis rather than a tradecraft gap.