This session investigates attacks against PLCs from two different perspectives. We show how to circumvent current host-based detection mechanisms applicable to PLCs by avoiding typical function hooking and by leveraging dynamic memory. We then introduce a specific type of attack against a PLC that allows the adversary to stealthily manipulate the physical process it controls by tampering with the device I/O at a low level. The attack exploit the latency in the I/O interfaces of a PLC which make it hard to differentiate between a clean and infected PLC. Our study is meant to be used as a basis for the design of more robust detection techniques specifically tailored for PLCs.