• Real protocols.
  • Real field devices.
  • Real-world scenarios.
  • Build detection logic, investigate threats, and gain ground-truth visibility—without touching live production systems.

About CyRenLAB

CyRenLAB is Cynalytica’s advanced training environment for industrial control system (ICS) and operational technology (OT) cyber defense. Trainees interact with genuine process behavior, launch controlled exploit scenarios, and develop detection logic—all in a safe, simulated environment

Curriculum Overview

CyRenLAB offers ten labs, organized into three progressive modules:

Module 1: Foundations – Ground-Truth Visibility

  • Lab 1: Introduction to Analog Signals in ICS Operations
    Learn to capture and baseline raw 4–20 mA signals for true process visibility.
  • Lab 2: Introduction to Serial Communications
    Decode Modbus RTU & IEC 101 protocols over RS-485 for baseline understanding.
  • Lab 3: Introduction to TCP/IP Protocols
    Analyze Modbus TCP & IEC 104 traffic for IP-layer security.

Module 2: Visibility & Investigation Workflows

  • Lab 1: CyRenQL Widgets and Alerts
    Build widgets and alerts from live telemetry using CyRenQL Editor.
  • Lab 2: Network Map and Sankey Workflows
    Visualize device relationships and activity flows for faster investigations.

Module 3: Threat Detection & Exploit Labs

  • Lab 1: Tower-Light Tampering
    Detect illegal-state writes and rapid oscillations in Modbus registers.
  • Lab 2: Motor Override
    Identify override attacks and erratic in-band jitter.
  • Lab 3: Sensor Fault Injection
    Catch single-view manipulation and cross-validate sensor readings.
  • Lab 4: IEC 101 Spoofing
    Detect rogue devices and spoofed measurements in SCADA networks.
  • Lab 5: IEC 104 Takeover
    Flag ARP poisoning, telemetry gaps, and denial-of-service resets.

Key Benefits

  • Ground-Truth Reference: Learn to correlate physical process behavior with network data.
  • Protocol Mastery: Build baseline understanding across analog, serial, and IP layers.
  • Detection Logic: Develop MITRE ATT&CK-aligned detection rules for real-world attack scenarios.
  • Safe Environment: Train without risk to live production systems.

Who Should Attend?

  • Security analysts
  • ICS/OT engineers
  • Incident responders
  • Anyone seeking hands-on, practical cyber defense skills

Ready to Level Up Your ICS/OT Security?

Contact us to schedule a demo or enroll in CyRenLAB training!