{
  "id": 11780373,
  "title": "Nine OT Protocol Investigations Later, My Lab Got Smaller and My Research Got Better",
  "url": "https://urgent.news/2026/10/03/nine-ot-protocol-investigations-later-my-lab-got-smaller-and-my",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-03T17:41:24.000Z",
  "source": {
    "name": "HackerNoon",
    "slug": "hackernoon",
    "url": "https://hackernoon.com/nine-ot-protocol-investigations-later-my-lab-got-smaller-and-my-research-got-better?source=rss"
  },
  "original_language": "en",
  "account": "Nine industrial protocols later, the protocol research series came to an end. Initially, the goal was to learn industrial protocols, but it evolved into a deeper understanding of how to research them. The author's initial attempts were vastly different from their final approach. They began by building larger labs than necessary, chasing details without understanding their purpose, and treating protocols as the scope of research. Over time, they started asking better questions, constructing smaller experiments, writing their own harnesses, capturing traffic, and using packets as evidence. This led to a significant change in their research focus. Initially, the author did not enter cybersecurity with a clear plan to work in industrial security. They were first drawn to hacking due to its appeal in movies, pop culture, and CTFs, but soon realized that real systems were far more complex than portrayed in popular media. They found industrial systems particularly intricate, with numerous components such as networks, applications, authentication, configurations, operating systems, and people involved. Frustrated with the constant pursuit of new bugs, the author discovered that creating controlled environments, understanding component interactions, making changes, observing results, and challenging assumptions aligned better with their learning style. This led them to industrial control systems (ICS) and operational technology (OT). Before developing a protocol research methodology, the author had created a Modbus Exposure Analyzer. The initial idea was to build a tool to identify exposed Modbus services and analyze their exposure. However, they soon realized that industrial systems are not ordinary internet services suitable for experimentation. To test their tool safely, they built a local Modbus environment and tested the tool there, which influenced the direction of their subsequent work. This experience formed the foundation for their entire project. Initially, when studying industrial protocols, the author followed a detailed roadmap, including PLC architecture, runtimes, control logic, firmware analysis, extraction, reverse engineering, and more. However, they soon discovered that building complex laboratories with tools like OpenPLC, FUXA, Docker, virtual machines, GNS3, and protocol implementations became more complicated than the questions they aimed to answer. They eventually found that sometimes the laboratory outgrew the scope of the research question. The rabbit holes of curiosity often led to endless checklists of function codes and exceptions, making it difficult to determine when research was complete. However, a shift came when the author started defining research goals before exploring protocols. Instead of asking \"How much of DNP3 can I learn?\" they began asking \"What do I want to establish about DNP3?\" This change provided boundaries to their research and transitioned from attempting to learn everything about a protocol to answering specific questions about it. Consequently, the research lab became smaller and more focused on answering targeted questions rather than attempting to cover every aspect of a protocol.",
  "summary": "After nine industrial protocol investigations, an OT researcher explains how smaller labs, packet captures, and sharper questions improved the work.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}