Hunting on IT networks versus OT networks versus cloud networks
IT networks and OT networks are fundamentally similar. They are so similar, in fact, that it is easy to mistake a common action that is permitted on IT networks, such as port scanning, as being fine on an OT network and ending up bringing operations to a halt. If this is the first time you are hearing about this difference, the only thing that you need to take away is to stay off OT networks until you can learn about them in depth, with lots of training in a segregated training environment.
The vast majority of personnel in cybersecurity have built their entire careers on IT networks. The software they use, tactics, and experiences are all centered around what is normal on systems. Reactions to finding non-standard software or connections, such as a bot that is connected to a command-and-control server is bad and should be removed immediately, are very common. However, on an OT network, these ideas and concepts do not...