c0c0n 2026

c0c0n is a 19 years old platform that is aimed at providing opportunities to showcase, educate, understand and spread awareness on Information Security, data protection, and privacy...

Venue & Date

OT/ICS Security Village

About C3iHub, IIT Kanpur

C3iHub (Cybersecurity and Cybersecurity of Cyber-physical Systems, A Technology Innovation Hub at IIT Kanpur) is a Technology Innovation Hub established at the Indian Institute of Technology Kanpur under the National Mission on Interdisciplinary Cyber-Physical Systems (NM-ICPS), Department of Science and Technology, Government of India. It focuses on research, product development, and capacity building in cybersecurity, with a particular emphasis on securing critical infrastructure, industrial control systems (ICS), and operational technology (OT) environments.

Through its OT/ICS Security Village, C3iHub aims to bridge the gap between traditional IT security practices and the specialized requirements of industrial and cyber-physical systems, offering hands-on exposure to real-world attack and defense scenarios using dedicated testbeds and simulation platforms.

About the OT/ICS Village

The OT/ICS Village at c0c0n 2026 is a dedicated, hands-on learning track designed for security professionals, students, and enthusiasts interested in the security of industrial control systems, SCADA networks, and critical infrastructure. Unlike conventional IT-security tracks, this village focuses exclusively on the unique protocols, architectures, and threat landscape of operational technology environments.

Participants will work directly with C3iHub's industrial testbeds and simulation platforms – including a chemical plant process simulator, live PLC hardware, and a functioning OT Security Operations Centre (SOC) – to understand how attacks unfold against industrial systems and how they are detected, triaged, and investigated in practice.

The village is structured as a two-day, hands-on programme covering OT/ICS fundamentals, threat intelligence and dark-web reconnaissance, wireless and RF attack surfaces, and OT security operations, culminating in a live, end-to-end attack detection demonstration.

October 9-10, 2026

Prerequisites

Each participant must bring the following:

  • Laptop (minimum 8 GB RAM; 16 GB recommended for Docker/GRFICS workloads)
  • Administrator/root access on the laptop, to install tools locally
  • Power adapter / charger
  • Ethernet port or USB-to-Ethernet adapter
  • A modern web browser (Google Chrome or Mozilla Firefox, latest version) with Wi-Fi enabled for supplementary resources
  • Basic familiarity with networking and command-line usage (helpful, not mandatory)
  • Basic understanding of cybersecurity/networking concepts is helpful

Learning Outcomes

On completion of the OT/ICS Village, participants will be able to:

  • Distinguish the security priorities, architectures, and constraints of OT/ICS environments from those of traditional IT systems.
  • Apply the Purdue Enterprise Reference Architecture to reason about network segmentation and attack surfaces in industrial environments.
  • Execute and interpret common OT attack techniques, including ARP poisoning, Modbus register manipulation, and unauthorized PLC logic injection, on a live process simulator.
  • Perform structured threat intelligence gathering, including dark-web reconnaissance and IOC/IOA extraction, mapped against the MITRE ATT&CK framework.
  • Identify and assess RF and Bluetooth attack surfaces using practical wireless reconnaissance and exploitation techniques.
  • Explain the architecture and workflow of an OT Security Operations Centre, from sensor data to analyst-driven incident investigation.
  • Correlate SOC alerts with process-level impact using OT network and process visualisation tools such as CyberMap.
  • Detect and trace a live attack on real PLC hardware end-to-end, from execution through to SOC-based detection and process-level impact.

Deliverables for Participants

Participants attending the OT/ICS Village can expect to receive:

  • Hands-on exposure to C3iHub's industrial testbeds, including a chemical plant process simulator, live PLC hardware, and an operational OT SOC.
  • Reference material and session notes covering OT/ICS fundamentals, threat intelligence workflows, and wireless attack surfaces.
  • Guided walkthroughs of attack simulation, detection, and investigation across the OT SOC and CyberMap platforms.
  • A certificate of participation from C3iHub, IIT Kanpur.
  • Access to C3iHub's point of contact for follow-up queries, collaboration, and future engagement opportunities.

Two-Day Agenda

Both days of the OT/ICS Village follow an identical structure, allowing participants to attend either day independently or repeat the track for reinforcement.

DAY 1

9th October 2026

Friday
11:00
11:30
11:30
13:00
OT/ICS Fundamentals, Industrial Protocol Deep-Dive, OT Attack Simulation & Threat Hunting

Comparison of IT security versus OT security and an introduction to the Purdue Enterprise Reference Architecture.

Hands-on OT attack on a chemical plant process simulator (GRFICSv3): ARP poisoning between HMI and PLC, manipulation of Modbus register reads/writes, and injection of unauthorized PLC logic commands.

Ajinkya PandayAjinkya Panday, C3iHub, IIT Kanpur
Lunch Break | 13:00 – 14:30
14:30
16:00
Threat Intelligence + Dark Web; Wireless Security (RF & Bluetooth Attack Surfaces)

Introduction to threat intelligence, IOC/IOA analysis, TTPs, and the MITRE ATT&CK framework, followed by practical dark-web intelligence gathering, IOC extraction, enrichment, and verification.

Live demonstration of RF and Bluetooth attack surfaces using Raspberry Pi, PiFmRds, and Bluetooth devices, covering FM/RDS transmission, wireless signal analysis, Bluetooth discovery, and associated attack, detection, and defensive techniques.

Aman RajAman Raj, C3iHub, IIT Kanpur
Break | 16:00 – 16:30
16:30
18:00
OT SOC & CyberMap; Live Attack Detection Demo on PLC Test Kit

Architecture of an OT Security Operations Centre – from OT data sources and sensors through the detection pipeline to analyst workflow, including alert triage, correlation, and incident investigation using real data from C3iHub's industrial testbeds (power, water treatment, manufacturing, conveyor).

Introduction to CyberMap for OT network and process-level visualisation, mapping SOC alerts onto P&ID-style process views and tracing attack paths from the affected device to the affected process.

Live demonstration on the PLC Test Kit: execution of an attack on real PLC hardware, real-time observation of detection on the SOC dashboard, and tracing of its process impact on CyberMap.

Tanmay AgrawalTanmay Agrawal, C3iHub, IIT Kanpur
DAY 2

10th October 2026

Saturday
11:00
11:30
11:30
13:00
OT/ICS Fundamentals, Industrial Protocol Deep-Dive, OT Attack Simulation & Threat Hunting

Comparison of IT security versus OT security and an introduction to the Purdue Enterprise Reference Architecture.

Hands-on OT attack on a chemical plant process simulator (GRFICSv3): ARP poisoning between HMI and PLC, manipulation of Modbus register reads/writes, and injection of unauthorized PLC logic commands.

Ajinkya PandayAjinkya Panday, C3iHub, IIT Kanpur
Lunch Break | 13:00 – 14:30
14:30
16:00
Threat Intelligence + Dark Web; Wireless Security (RF & Bluetooth Attack Surfaces)

Introduction to threat intelligence, IOC/IOA analysis, TTPs, and the MITRE ATT&CK framework, followed by practical dark-web intelligence gathering, IOC extraction, enrichment, and verification.

Live demonstration of RF and Bluetooth attack surfaces using Raspberry Pi, PiFmRds, and Bluetooth devices, covering FM/RDS transmission, wireless signal analysis, Bluetooth discovery, and associated attack, detection, and defensive techniques.

Aman RajAman Raj, C3iHub, IIT Kanpur
Break | 16:00 – 16:30
16:30
18:00
OT SOC & CyberMap; Live Attack Detection Demo on PLC Test Kit

Architecture of an OT Security Operations Centre – from OT data sources and sensors through the detection pipeline to analyst workflow, including alert triage, correlation, and incident investigation using real data from C3iHub's industrial testbeds (power, water treatment, manufacturing, conveyor).

Introduction to CyberMap for OT network and process-level visualisation, mapping SOC alerts onto P&ID-style process views and tracing attack paths from the affected device to the affected process.

Live demonstration on the PLC Test Kit: execution of an attack on real PLC hardware, real-time observation of detection on the SOC dashboard, and tracing of its process impact on CyberMap.

Tanmay AgrawalTanmay Agrawal, C3iHub, IIT Kanpur

Contact

For queries regarding the OT/ICS Village at c0c0n 2026, please reach out to the C3iHub team on-site at the village, or through the official C3iHub, IIT Kanpur channels.

Village Crew

Meet the experts leading the OT/ICS Security Village.

Dr. Anand Handa

CSO

C3iHub, IIT Kanpur

Dr. Ras Diwedi

CTO

C3iHub, IIT Kanpur

Ajinkya Panday

C3iHub, IIT Kanpur

Aman Raj

C3iHub, IIT Kanpur

Tanmay Agrawal

C3iHub, IIT Kanpur

PARTNERS