Threat basis

What you hunt. What hunts back.

Every condition on the range is drawn from real water and building-automation incident patterns — reproduced inside an isolated simulation.

Register free

01 / Priority conditions

The ten conditions that matter most

Ranked by how directly each one collapses the boundary around a physical process.

#ConditionWhy it mattersPrimary defense
01Internet-exposed PLC or HMI; unnecessary remote/vendor pathDirect access collapses the boundary around the physical process.Remove exposure; controlled gateway; MFA; allowlists; monitor remote sessions.
02Default, shared, stale or weak credentials; no MFARecent water incidents repeatedly leverage poor identity controls.Unique accounts; vaulting; MFA; revoke departures; just-in-time vendor access.
03Unknown or incomplete OT inventoryAn owner cannot patch, isolate, monitor or recover an asset it cannot name.Field-verified inventory; owners; firmware; network paths; criticality; evidence.
04Flat IT/OT network or permissive firewall pathOne compromised endpoint can reach process control.Zones and conduits; OT DMZ; deny by default; separate identities; bastion.
05Outdated firmware and known exploited vulnerabilitiesPublicly known weaknesses shorten attacker effort.CISA KEV/advisory matching; vendor-approved remediation; compensating control.
06Unauthorized controller or configuration change without a trusted baselineOperators can be locked out or process logic altered.Gold project/config; hashes; change windows; write monitoring; restore tests.
07Weak logging and no ICS-aware monitoringWrites, failed logins and path violations may be invisible.Central logs; passive OT telemetry; config drift; maintenance-window correlation.
08Untested or online-only backups; no manual procedureRecovery fails exactly when operations depend on it.Offline known-good copies; restore drill; local and manual operating plan.
09Alarm or telemetry manipulation and loss of viewA trusted-looking screen can drive the wrong physical action.Independent sensing; plausibility checks; field verification; alarm integrity.
10Vendor governance and human-factor gapsFormer staff, informal remote help and undocumented SOPs create persistent paths.Owner, authorization, expiry, competency, SOP and attestation obligations.

02 / Controlled adversary

Eight injects, all preauthored

Nothing improvised, nothing routable to the venue. Each inject has a designed detection path and an approved defense.

RT-01

Exposed controller

A staged pump PLC/HMI is intentionally reachable from the isolated adversary zone. Teams find it through range telemetry — never Internet scanning.

Detect
Unexpected source login; exposed-service finding; remote-path edge.
Defend
Remove exposure; approved switch-port isolation; gateway and MFA; verify local process view.
RT-02

Weak / stale identity

A synthetic vendor account is valid outside its maintenance window. No real default passwords are used.

Detect
Stale identity, abnormal time or source, shared-account evidence.
Defend
Revoke; just-in-time access; MFA; named owner; vendor access obligation.
RT-03

Unauthorized config drift

A scenario controller changes a dummy IP/config value, causing simulated loss of view.

Detect
HMI disconnect; configuration hash mismatch; engineering event.
Defend
Local verification; restore gold config; restrict writes; change-window monitoring.
RT-04

Masquerading monitor

A benign range client presents as a monitoring utility but performs a preauthored write to a dummy register.

Detect
Process/tool anomaly; write outside maintenance; state divergence.
Defend
Application allowlist; protected controller mode; engineering-workstation allowlist.
RT-05

IT-to-OT route

A deliberately permissive synthetic firewall rule permits a canned cross-zone connection.

Detect
Forbidden zone flow; identity reuse; route-policy violation.
Defend
OT DMZ; deny by default; separate identity; validated conduit inventory.
RT-06

False telemetry

The simulator changes displayed pressure while the process model and independent sensor stay safe and stable.

Detect
Cross-sensor inconsistency; implausible rate of change; field mismatch.
Defend
Plausibility analytics; independent instrument; Meta-glasses field confirmation.
RT-07

Recovery trap

The first online backup is deliberately unusable; an offline signed gold copy exists.

Detect
Restore failure; checksum mismatch; extended recovery clock.
Defend
Offline copy; restore-test evidence; documented manual state.
RT-08

Compound LA event

A simulated leak above an electrical room plus pump loss-of-view and a fire-water dependency question.

Detect
Multiple alarms; ambiguous valve/power dependency; conflicting priorities.
Defend
Do not blindly isolate; consult graph, SOP and expert; preserve life safety; staged containment.

03 / Rules of engagement

Three action classes

Know your class before you touch anything. A red action ends your team's day.

Green — participant action

Observation and interaction with synthetic or dead training assets

Read labels; trace a mock cable; inspect a staged HMI; query the graph; submit evidence; execute simulator controls

Amber — authorized operator only

Preapproved physical or network isolation after checklist and safety-authority approval

Disconnect the training PLC network lead; disable the simulated switch port; restore a gold configuration

Red — prohibited

Any contact with venue or building production systems

Scanning venue networks; logging into live BAS/PLC/HMI; changing setpoints; closing live valves; unplugging a working pump

Think you can find it first?

Twelve teams get the same imperfect estate and the same clock. Registration is free.

Your privacy choices. We use only essential cookies by default. With your consent we may also use analytics or marketing tools. You can change your choice anytime. See our Privacy Notice.