TroutTrout

Whitepapers & Guides

Technical deep-dives on Zero Trust architecture, compliance frameworks, and industrial network security.

Zuletzt aktualisiert:

Practical guides and architecture references for security and compliance teams protecting industrial control systems, OT networks, and critical infrastructure. Each whitepaper covers real-world deployment patterns, covering Zero Trust access control, CMMC Level 2, NIS2, IEC-62443, and legacy OT equipment protection, without requiring network redesign or production downtime.

SCADA-Sicherheit: der vollständige Leitfaden

Die sechs Wege, die SCADA erreichen, sechs Kontrollen, die keine Steuerung anfassen, die Normenkarte, ein Kapitel pro Sektor und ein Plan für das erste Jahr. 38-seitiges PDF, auf Englisch.

Read
SCADA security: the complete guide, cover

Beyond Purdue: Micro-DMZs for Modern OT

Why the Purdue Model and Industrial DMZ were never designed for today's OT, and how Micro-DMZs deliver Zero Trust without network redesign.

Read
LEVEL 4EnterpriseLEVEL 3Site OperationsLEVEL 2Area SupervisoryLEVEL 1Basic ControlLEVEL 0ProcessERPEMAILWEBADHISTMESPATCHAVPLC-1PLC-2RTUSISVALVEPUMPMOTORSENSLEVEL 3.5: INDUSTRIAL DMZSINGLE CHOKEPOINTVENDOR VPNCLOUDPURDUE MODEL STATUS3 BYPASS PATHS DETECTEDDMZ: SINGLE POINT OF FAILURE

Overlay Networks Explained

How the Access Gate builds a secure virtual layer on top of your existing industrial network, no rewiring, no downtime.

Read
Overlay networking diagram

Industrial DMZ Design Patterns

From flat networks to proxy-based segmentation, architectures that protect legacy OT without replacing equipment.

Read
TRADITIONAL APPROACHPLC-1HMI-2RTU-3SIS-4CENTRALIZEDDMZALL TRAFFIC FUNNELEDERPMESCLOUDSAME PHYSICAL NETWORKWITH INLINE MEDIATIONPLC-1PROXYHMI-2PROXYRTU-3PROXYSIS-4PROXYERPMESCLOUDXXXTRADITIONAL DMZSINGLE POINT OF FAILURELATERAL MOVEMENT POSSIBLE

DoD Zero-Trust for OT | Alignment Guide

Point-by-point mapping of DTM 25-003 requirements to Trout Access Gate capabilities across all 7 DoD OT-ZT pillars.

Read
DOD OT ZERO-TRUST ALIGNMENTDTM 25-0031USERSFULL✓2DEVICESFULL✓3APPLICATIONSFULL✓4DATAFULL✓5NETWORKSFULL✓6AUTOMATIONFULL✓7VISIBILITYFULL✓7 PILLARS | TARGET LEVEL | UNCLASSIFIED: PUBLIC RELEASE

Securing Modbus in Modern Industrial Environments

Architecture, risks, and practical security controls for a protocol that was never designed to be connected, but now is.

Read
Typical path of a Modbus attack

OPC-UA-Sicherheit: Praxisleitfaden für OT-Ingenieure

OPC UA wurde von Anfang an mit Sicherheit entworfen, und die meisten Server kommen mit allem abgeschaltet. Was das Modell leistet und wie Sie die Lücke schließen.

Read
OPC UA SECURITY MODELTHREE LAYERS, ALL OPTIONAL, ALL OFF BY DEFAULTSESSIONSHIPPED: ANONYMOUSNAMED USERSECURECHANNELSHIPPED: MODE: NONESIGN + ENCRYPTTRANSPORTSHIPPED: TCP 4840TCP 4840SECURE BY DESIGN. OPEN BY DEFAULT.

DNP3 absichern: Authentifizierung, Verschlüsselung und die Lücke in SAv5

DNP3 Secure Authentication belegt, wer einen Befehl gesendet hat. Verbergen tut sie ihn nie. Was SAv5 abdeckt und woher die zweite Kontrolle kommen muss.

Read
DNP3 WITH SAv5 ENABLEDAUTHENTICATION IS NOT ENCRYPTIONWAS IT ALTERED IN FLIGHT?YESDID THE REAL MASTER SEND IT?YESIS IT A REPLAYED COMMAND?YESCAN ANYONE ON THE PATH READ IT?NOARE THE SETPOINTS CONCEALED?NOSAv5 PROVES THE SENDER. TLS IS A SEPARATE DECISION.

Securing MAVLink in Connected Robotic & UAV Environments

Zero-trust architecture for MAVLink protocol security, threat analysis, cryptographic remediation, and practical deployment for UAV fleets.

Read
MAVLink communication security threat model

Impeller Technology Validation

Independent performance benchmark: Impeller vs. Logstash for edge log processing.

Read
IMPELLER VS. LOGSTASHINDEPENDENT BENCHMARK: HUN-REN SZTAKIMETRICIMPELLERLOGSTASHIMAGE SIZE80 MB890 MBSTARTUP2s8-39sCPU / EVENT0.06ms1.73ms91% SMALLER, 3-13x LESS CPU

FrostyGoop: eine vergleichende Analyse

Dragos gegen SCADASEC zum Heizungsvorfall in Lwiw, und warum die Bedrohungsstufe dieser ICS-Malware einen genaueren, belegbasierten Blick verdient.

Read
FrostyGoop ICS malware analysis and the Lviv heating incident

PLC-Sicherheit: speicherprogrammierbare Steuerungen schützen

Warum die meisten SPS jeden gültigen Befehl ausführen, die sechs Kontrollen, die sie wirklich schützen, und wie man eine Steuerung absichert, ohne sie anzufassen.

Read
Securing programmable logic controllers on the plant floor

OT-Mikrosegmentierung mit SIEM-Anbindung

Mikrosegmentierung als Overlay ausrollen und jede Sitzung per Syslog an Splunk, Elastic, QRadar oder Sentinel senden. Keine Agenten, kein Umbau.

Read
OT microsegmentation deployment architecture with SIEM integration

Unabhängige IMR-Validierung: Overlay-Sicherheit für OT

Irish Manufacturing Research hat Access Gate als Referenzimplementierung für Overlay-Sicherheit validiert. Fünf Protokolle, Least Privilege durch Verweigerung belegt, Nachweise auf NIS2, IEC 62443 und ISO 27001 abgebildet.

Read
Independent validation of overlay security for OT by Irish Manufacturing Research

OT-Verteidigung gegen Volt Typhoon: laterale Bewegung stoppen

Wie Living-off-the-Land-Akteure von IT auf OT übergehen, was die CISA-Leitlinien 2026 empfehlen, und wie man den Pfad an der Prozessgrenze unterbricht.

Read
Defending OT against Volt Typhoon lateral movement from IT to OT

Threat Intelligence und Schutzmaßnahmen für CCTV-Systeme

Forschung zu Bedrohungen von CCTV-Systemen mit Strategien zur Risikominimierung. Beschreibt typische Schwachstellen, aktuelle Cyberangriffe und praxisnahe Mitigation-Playbooks.

Read
CCTV THREAT SURFACEIP CAMERA · ONVIFFIELD OF VIEWDEFAULT PASSWORDSadmin / 12345OUTDATED FIRMWAREunpatched CVEsEXPOSED MGMT UIpublic internetFOOTAGE TAMPERINGloop / replayDVR / NVRstorage · playbackRESEARCH · 2024VULN CATALOG · ATTACK PATHS · MITIGATIONS