Skip to main content

Hunt playbook

Unauthorized Wireless Connectivity

Find wireless access points, cellular modems or ad-hoc links in or attached to OT networks.

IntermediateT0860T0842

Hypothesis

Unapproved wireless connectivity may exist within the OT environment.

Why this hunt matters

Wireless and cellular links can silently bypass every wired control you designed.

Scope

Assets: iiot-gateway, industrial-switch, engineering-workstation

Protocols:

Data sources required

  • Wireless intrusion detection where deployed
  • Switch MAC/OUI data
  • Asset inventory
  • Physical inspection records
  • Firewall logs

Baseline needed first

  • An approved list of wireless infrastructure and cellular-connected devices

Hunt steps

  1. 01Compare observed OUIs against known wireless and cellular vendors
  2. 02Review inventory for devices with wireless capability enabled
  3. 03Walk high-risk areas and inspect panels for modems or APs during scheduled visits
  4. 04Look for traffic patterns indicating an alternative egress path

Indicators of interest

  • Wireless-capable OUIs in control VLANs
  • Devices with two network paths
  • Vendor equipment with built-in cellular
  • Traffic bypassing the boundary firewall

Triage

  • Who installed it?
  • Does it provide inbound reachability?
  • Is it vendor-managed?

Likely false positives

  • Approved industrial wireless (WirelessHART, licensed radios)
  • Temporary construction connectivity with approval

Escalation

  • Inbound reachability from outside
  • Any bridge between OT and an uncontrolled network

Containment options

  • Coordinate removal with the equipment owner; vendor links may support active maintenance

Validation

  • Wireless inventory documented
  • Contract terms updated for vendor connectivity

Why should I care?

Containment in OT is a joint decision. Isolating a device can be the safest action or the one that stops production — operations decides, security advises.