The Challenge

You can’t hand a class a real water plant

A lecture can describe a cyberattack. It can’t let a student feel one. The most durable lessons in incident response come from doing the work — pulling the logs, reconstructing the timeline, and figuring out what actually happened and in what order.

The problem is that “doing the work” requires a convincing target: the computers, the network, the control systems, and a believable attack to investigate. Operational technology (OT) and industrial control systems (ICS) — the equipment that runs water treatment, energy, and manufacturing — make it harder still, because the environments are specialized and the real-world consequences are physical. That is exactly the gap Red Knight’s Cyber Colosseum closes, and exactly where BayaniCyber contributed.

Anatomy of an ICS breach: how a public web portal became a path to SCADA — the WaterWerks Module 2 attack chain from external web compromise to critical chlorine impact.
The WaterWerks Module 2 attack chain — from an external web-portal compromise to critical impact on the water-treatment controls. Students investigate this backward, from the alarm to the first web request.
The Engagement

From the open internet to the water supply

Red Knight’s WaterWerks environment is a simulated small rural water utility — the kind common across Texas — running inside the Cyber Colosseum cyber range. Red Knight owns and operates it: the range infrastructure, the network and systems engineering, the day-to-day operations, and the plant simulator at its core — a SCADA server and terminal client that models the utility’s water-treatment controls. BayaniCyber’s job was to develop a new attack scenario on top of that environment — Module 2: External Compromise — and deliver it to Red Knight’s standards.

We designed the scenario around a threat every defender should understand: Log4Shell (CVE-2021-44228), the Log4j vulnerability that shook the internet in late 2021 and remains a textbook example of how one internet-facing flaw becomes a doorway. It connects well-understood enterprise attack tradecraft to critical-infrastructure targeting — the precise intersection where cyber operations meet cybersecurity.

The scenario tells a complete story. An outside attacker exploits the utility’s public-facing web portal, gains a foothold, performs reconnaissance to understand the internal network, and pivots across it toward the control systems — a segmented network with no direct path to the plant, which forces a realistic multi-stage route. The attack ends where it hurts: the water-treatment control system, with the chlorine setpoint forced far past the safe limit and a critical alarm firing at the operator’s screen. Students don’t watch this happen — they walk into the aftermath and work backward from the alarm, through control-system logs, authentication records, and web-server evidence, to reconstruct the whole chain.

To make it a finished teaching product, BayaniCyber delivered the full package: the scenario objectives, the threat logic and attack-chain design, a student guide, and an instructor guide with the setup, expected outcomes, and reset procedures needed to run it repeatedly. We integrated Module 2 with Red Knight’s earlier scenario so the range gained a richer, more varied exercise library. Then we finished it: the scenario was developed, tested in the live environment, demonstrated to Red Knight, and accepted into the WaterWerks baseline scenario library and merged into production. It is a deployable deliverable, not a prototype.

How We Work

Disciplined, AI-accelerated delivery

The engagement ran on Bayani Forge, our structured framework for AI-assisted engineering. Forge sets up each project with defined roles, review gates, and after-action capture from day one, and pairs human architects with AI agents that carry deep working knowledge of the technology stack — ICS/SCADA design, automation, infrastructure-as-code, and CI/CD pipelines.

Humans stay focused on architecture and scenario-design judgment; AI agents handle the breadth — configuration, scripting, and boilerplate — under a review-until-correct loop that keeps quality high. And because Forge learns as it goes, each project leaves the framework stronger for the next, compounding our OT/ICS capability with every engagement.

An Added Deliverable

A next-generation plant simulator

Alongside the scenario work, BayaniCyber invested in the road ahead by building ICS Water Sim — a more advanced, software-only water-treatment plant simulator designed to support richer, more demanding WaterWerks scenarios in the future.

The current WaterWerks environment runs on Red Knight’s existing simulator, a SCADA server and terminal client. ICS Water Sim extends that concept into a fuller platform with four components: an authoritative plant server and simulator, a terminal client, a network gateway that exposes a safe remote-facing surface, and a web-based Human-Machine Interface (HMI) dashboard that stands in for the operator’s screen. It models the parameters a real plant lives and dies by — chlorine and fluoride levels, pH, turbidity, alkalinity, tank level, pressure, and flow — with the pumps, valves, and dosing controls to match.

Status: a forward investment

ICS Water Sim is not deployed in the range today — current scenarios run on Red Knight’s simulator. It is a more capable foundation, ready to underpin the next generation of WaterWerks scenarios as the training program grows.

Results

What we delivered

  • A complete, tested, and accepted WaterWerks Module 2 scenario — attack-chain design, student guide, and instructor guide — demonstrated live to Red Knight and merged into the production range library.
  • A realistic multi-stage OT/ICS scenario connecting a real-world initial-access technique to genuine control-system impact, built to develop real defender judgment.
  • A reusable scenario-development approach — threat-logic design, artifact packaging, partner coordination, and after-action capture — now applied to further Cyber Colosseum work.
  • A next-generation plant simulator (ICS Water Sim) built and ready to support more advanced future scenarios — an additional, forward-looking deliverable beyond the engagement itself.
  • A clean teaming model: BayaniCyber develops the adversary-side scenario content; Red Knight operates and supports the range.

BayaniCyber develops its scenario content under partner authorization and controlled disclosure. Sensitive implementation details — exploit specifics, infrastructure configuration, credentials, and instructor-only materials — are deliberately kept out of public materials like this one.

Interested in the cyber range? Talk to Red Knight.

The Cyber Colosseum — the realistic, hands-on cyber range where scenarios like this come to life — is Red Knight’s platform. If you want to put your team through immersive OT/ICS and enterprise attack simulations, or you’re an institution looking to stand up hands-on cyber training, reach out to Red Knight.