OT Security Monitoring & Investigation

Read the operation behind the OT alert

Investigated OT incidents against known backup behaviour and helped define the telemetry and response ownership around Claroty and Sentinel monitoring.

UK Water UtilityOT investigation and response requirements2 min read

I investigated OT alerts with both the security signal and the operating environment in view. For Claroty and OT Sentinel activity, an alert needed enough identity, endpoint and operational context to support a conclusion and a response the responsible team could carry out.

I reviewed five incidents against earlier investigations and known backup behaviour. The comparison supported expected activity, and I recorded the basis for closing those incidents as false positives. That conclusion came from corroborating the traffic with its operational context.

I also contributed to OT monitoring architecture, coverage material and runbook discussions. This included defining the on-premises identity and endpoint context an investigation would need, and clarifying the responsibilities of SOC, MDR and OT teams for investigation, impact assessment and response.

Closer to the work

Backup activity and OT context

I treated backup activity as an explanation to verify against the observed OT traffic and previous investigations. The aim was to determine whether the activity matched an understood operational process and to retain the supporting evidence in the incident record.

Open this detail ↗
Corroborating the traffic

I compared five incidents with earlier cases and known backup behaviour, documented the evidence and closed them as false positives. The result applies to those investigated cases. The investigation combined security-monitoring context with knowledge of how the OT environment was expected to operate.

Open this detail ↗
Response ownership and telemetry

I helped define responsibilities around Claroty alerts and OT Sentinel events, including who investigates, validates operational impact and carries out response. The wider monitoring discussions addressed identity and endpoint telemetry from the on-premises environment, evidence requirements and usable runbooks.

Open this detail ↗

Skills established through this work

This work connects to

SOC & incident response

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Skills, achievements, technical detail. Follow the evidence.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.