Design and Evaluation of a Wazuh-Based Security Monitoring Framework for a Simulated OT Environment
Security monitoring is becoming more critical for systems that were primarily set up for reliable process control; industrial systems are increasingly connected. This project focuses on the feasibility of a small simulated operational technology (OT) setup with a monitoring solution based on Wazuh. A Windows PC was employed to serve as a software PLC, Kali Linux for a security-testing machine and Wazuh for the central monitoring platform. The simulated PLC transmitted data of the simulated temperature, pressure, tank level, motor status, and valve position as Modbus TCP and provided changing values. A variety of practical tests were run: Failed Windows authentication, PowerShell activity, Linux file-integrity events, Modbus communication checks, and Nmap service discovery. Wazuh obviously recognized the Windows authentication and PowerShell testing and also got file-integrity events from Kali. Modbus communication was successfully set up without any problems. But the execution of Nmap was not finally detected as a Wazuh alert and, in the same way, the EICAR antivirus test did not trigger a Wazuh event. The study also highlights the value of Wazuh for endpoint-focused visibility in an OT environment, which can be complemented by more network and OT-aware monitoring if comprehensive visibility in an industrial environment is desired.
Authors
- Apoorva Khare
- Priyank Kumar Kartikey
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-06
- DOI
- https://doi.org/10.5281/zenodo.23187505
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00