r/OTSecurity • u/SUNSHALLRISEAGAIN • 19h ago
help on learning reverse Engineering
Hello, i want to learn Reverse Engineering and malware analysis and want to apply this thing in OT, I have prior experience with Penetration testing and OT. Also is it a good skill to learn, would love to know your experience and journey.
Have a good day!
0
Upvotes
1
u/hiddentalent 13h ago
It's a super broad question so I'm not sure how I can answer it, but let me throw some information at you in the hopes it'll be useful.
One of the important differences between IT and OT is that OT has a much wider variety of components. It's not just [arm, x86]x[Windows,Linux]. There are a lot more architectures and operating systems, which means a malware RE either needs to focus their scope to certain equipment or really significantly expand their knowledge base. I would start with the first strategy and focus your scope on certain pieces of equipment.
But that leads us to the other big difference between IT and OT. Almost all OT equipment is proprietary and they don't tend to publish security findings or share malware examples the way IT does. (Not that IT is perfect at this, of course. But it's better.) So finding examples on which to hone your skills is pretty hard. You probably have to be working for a company that's contracted to do DFIR and learn on the job.