Skip to main navigation Skip to search Skip to main content

OTuHunt: An Aggregated Threat Hunting & Intelligence Platform for OT/ICS Environment and MSSP Services

  • Fatimah Alaliwat*
  • , Lena Alqahtani
  • , Manar Alzahrani
  • , Nouf Alamoudi
  • , Shaima Hakami
  • , Abdulrahman Alharby
  • , Nawaf Alharbi
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The convergence of IT and OT systems has height-ened cybersecurity risks, especially in OT/ICS environments where attacks can impact critical infrastructure. This paper proposes "OTuHunt", a conceptual framework to automate the extraction of Indicator of Compromise (IoC) and Tactics, Techniques, and Procedures (TTPs) from local reports and unstructured Cyber Threat Intelligence (CTI), using Natural Language Processing (NLP), aligning with the Managed Security Service Provider (MSSP) model. Extracted TTPs are mapped to MITRE ATT&CK for ICS and transformed into Security Information and Event Management (SIEM)-compatible queries. While still in the proposal stage, "OTuHunt"aims to provide an end-to-end automated threat hunting pipeline tailored to OT/ICS, addressing gaps in current solutions and enhancing early Advanced Persistent Threat (APT) detection in support of secure digital transformation.

Original languageEnglish
Title of host publicationProceeding - 12th International Conference on Information Technology
Subtitle of host publicationInnovation Technologies, ICIT 2025
EditorsKhalid Mohammad Jaber
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages39-46
Number of pages8
ISBN (Electronic)9798331508944
DOIs
StatePublished - 2025
Event12th International Scientific Conference on Information Technology, ICIT 2025 - Amman, Jordan
Duration: 27 May 202530 May 2025

Publication series

NameProceeding - 12th International Conference on Information Technology: Innovation Technologies, ICIT 2025

Conference

Conference12th International Scientific Conference on Information Technology, ICIT 2025
Country/TerritoryJordan
CityAmman
Period27/05/2530/05/25

Fingerprint

Dive into the research topics of 'OTuHunt: An Aggregated Threat Hunting & Intelligence Platform for OT/ICS Environment and MSSP Services'. Together they form a unique fingerprint.

Cite this