Security monitoring is becoming more critical for systems that were primarily set up for reliable process control; industrial systems are increasingly connected. This project focuses on the feasibility of a small simulated operational technology (OT) setup with a monitoring solution based on Wazuh. A Windows PC was employed to serve as a software PLC, Kali Linux for a security-testing machine and Wazuh for the central monitoring platform. The simulated PLC transmitted data of the simulated temperature, pressure, tank level, motor status, and valve position as Modbus TCP and provided changing values. A variety of practical tests were run: Failed Windows authentication, PowerShell activity, Linux file-integrity events, Modbus communication checks, and Nmap service discovery. Wazuh obviously recognized the Windows authentication and PowerShell testing and also got file-integrity events from Kali. Modbus communication was successfully set up without any problems. But the execution of Nmap was not finally detected as a Wazuh alert and, in the same way, the EICAR antivirus test did not trigger a Wazuh event. The study also highlights the value of Wazuh for endpoint-focused visibility in an OT environment, which can be complemented by more network and OT-aware monitoring if comprehensive visibility in an industrial environment is desired.
Monitoring should be added to the next phase of the project that would be able to directly observe OT network behavior, not primarily endpoint logs. The passive network sensor could be monitoring the Modbus TCP communications traffic without software being installed on the simulated PLC. It would allow for the analysis of unusual Modbus requests, unexpected write operations, repeated connection attempts, and reconnaissance patterns. The Windows endpoint could also be configured to forward more detailed Microsoft Defender and PowerShell operational telemetry to be correlated with Wazuh alerts by security-product events. The Nmap experiment can be repeated once the persistent audit configuration has been fully validated and the event generated by Nmap is correctly mapped in Wazuh. A good experiment would be to send a controlled Modbus write message to the simulator and then automatically return to the process value to its normal state. Many repetitions of each experiment would allow for more accurate calculation of average detection latency, detection rate and false-positive behavior. Lastly, experiments could be mapped to MITRE ATT&CK for ICS and NIST OT security guidance to create a stronger link between what was observed in real tests and existing cybersecurity frameworks
References
[1] K. Stouffer et al., βGuide to Operational Technology (OT) Security,β NIST Special Publication 800-82 Rev. 3, National Institute of Standards and Technology, 2023. https://csrc.nist.gov/pubs/sp/800/82/r3/final [2] Wazuh, βArchitecture,β Wazuh Documentation. https://documentation.wazuh.com/current/getting-started/architecture.html [3] Wazuh, βWazuh agent,β Wazuh Documentation. https://documentation.wazuh.com/current/getting-started/components/wazuh-agent.html [4] Wazuh, βFile Integrity Monitoring: How it works,β Wazuh Documentation. https://documentation.wazuh.com/current/user-manual/capabilities/file-integrity/how-it-works.html [5] Wazuh, βConfiguring log collection for different operating systems,β Wazuh Documentation. https://documentation.wazuh.com/current/user-manual/capabilities/log-data-collection/configuration.html [6] MITRE ATT&CK, βCommand and Scripting Interpreter: PowerShell, T1059.001.β https://attack.mitre.org/techniques/T1059/001/ [7] MITRE ATT&CK, βValid Accounts, T1078.β https://attack.mitre.org/techniques/T1078/ [8] EICAR, βAnti-Malware Testfile,β European Institute for Computer Antivirus Research. https://www.eicar.org/download-anti-malware-testfile/
π How to Cite This Paper
Priyank Kumar Kartikey, Apoorva Khare (2026). Design and Evaluation of a Wazuh-Based Security Monitoring Framework for a Simulated OT Environment. International Journal of Engineering and Techniques, 12(5), 316β325. ISSN: 2395-1303. DOI: https://doi.org/10.5281/zenodo.23187506