Preparing Your ICS Forensic Toolkit
About This Session
Industrial Control System (ICS) and Operational Technology (OT) environments present unique challenges for digital forensics and incident response. Unlike traditional IT systems, these environments prioritize safety, reliability and operations continuity, making intrusive forensic techniques impractical or even dangerous. This presentation provides a practical, vendor-neutral approach to preparing an effective ICS forensic toolkit, focusing on low-risk, non-disruptive methods that enable investigation without compromising critical processes.
This session will guide attendees through the essential tools and concepts required to perform forensic analysis in OT environments. It emphasizes the use of mostly open-source, portable utilities and native operating system capabilities that eliminate the need for installation, reduce system impact and support rapid deployment during incident response. Attendees will gain a clear understanding of how to collect and preserve evidence safely while working within the constraints of live industrial systems.
Key data sources critical to ICS investigations will be explored in depth, including operating system persistence mechanisms, file system artifacts, system and security logs and network packet captures. Each source will be examined in the context of known adversary behaviors within ICS environments, enabling participants to better identify indicators of compromise and suspicious activity. Guidance will also be provided on prioritizing logs and telemetry to build a coherent picture of adversary actions while minimizing alert fatigue.
The presentation will also show strategies for deeper forensic analysis using backups and disk images, allowing investigators to analyze systems that cannot be taken offline. Attendees will understand how to assemble a practical ICS forensic toolkit, both hardware and software, and how to use it to incrementally reconstruct adversary activity. This foundation enables more informed decision-making and supports the development of effective, context-aware response strategies.
This session will guide attendees through the essential tools and concepts required to perform forensic analysis in OT environments. It emphasizes the use of mostly open-source, portable utilities and native operating system capabilities that eliminate the need for installation, reduce system impact and support rapid deployment during incident response. Attendees will gain a clear understanding of how to collect and preserve evidence safely while working within the constraints of live industrial systems.
Key data sources critical to ICS investigations will be explored in depth, including operating system persistence mechanisms, file system artifacts, system and security logs and network packet captures. Each source will be examined in the context of known adversary behaviors within ICS environments, enabling participants to better identify indicators of compromise and suspicious activity. Guidance will also be provided on prioritizing logs and telemetry to build a coherent picture of adversary actions while minimizing alert fatigue.
The presentation will also show strategies for deeper forensic analysis using backups and disk images, allowing investigators to analyze systems that cannot be taken offline. Attendees will understand how to assemble a practical ICS forensic toolkit, both hardware and software, and how to use it to incrementally reconstruct adversary activity. This foundation enables more informed decision-making and supports the development of effective, context-aware response strategies.
Speaker
Andrew Dettmer
Consultant (Industrial Cybersecurity) - Black & Veatch
Andrew is an Industrial Cybersecurity Consultant with Black & Veatch’s Industrial Cybersecurity Practice, specializing in advanced cybersecurity offerings for operational technology (OT) environments. Prior to joining Black & Veatch, he served as the industrial cybersecurity engineer for a nine-plant generation and transmission cooperative, where he spent nine years developing and leading a comprehensive cybersecurity program for plant control systems. Andy brings deep expertise in OT/ICS systems, regulatory compliance (including NERC CIP), and industry-recognized cybersecurity frameworks. He holds a B.S. in Computer Science and maintains several advanced certifications, including CISSP, GICSP, GRID, GCFA, and GCIP. He is the recipient of the 2025 Mike Assante Scholar Award.
