
An exposed energy-themed honeypot gets discovered in under an hour, then faces continuous brute force, web scanning, and protocol-aware Modbus reconnaissance, with zero write or control attempts. Part 3 turns those findings into defence. The same structural controls that stop commodity scanning also shrink the targeted tail: keep OT protocols and management planes off the public internet, block egress by default, remove default credentials, segment IT from OT, and log behaviour instead of bare port contact. Most of it is network architecture, not detection wizardry.
View original source — Hacker Noon ↗



