← LibraryTechnique entry
OT-ENG-WORKSTATIONLateral Movement
Engineering Workstation Pivot
Compromise the engineering laptop (TIA Portal / Studio 5000) — push arbitrary logic to PLCs through legitimate channels.
§ Where this technique fits
OT-ENG-WORKSTATION is catalogued under the Lateral Movement tactic of the offensive-security kill-chain. It appears in 2 approved dossiers in the registry, typically at step 2.5 on average.
§ Dossiers chaining this technique
- step 2 / 5
TRITON-class SIS reprogram → disable safety shutdown
After OT-network foothold, reach a Triconex Safety Instrumented System. Download attacker logic that suppresses safety trips on a process that's about to be pushed past its safe envelope.
- step 3 / 6
Engineering workstation → push payload to PLC
Compromise the OT engineer's laptop (corporate-network adjacent, jumphost-reachable). Use legit engineering tools (TIA Portal / Studio 5000) to download attacker ladder logic to the PLC.
§ What commonly comes next
- 01Siemens S7 Protocol Abuseseen 1×OT-S7-SIEMENS · Impact
- 02Triconex / TRITON SIS Reprogramseen 1×ICS-TRITON-SIS · Impact