Texas A&M Cybersecurity faculty are dedicated to the facilitation of ground-breaking, basic, and applied cybersecurity research. The sheer number of publications produced by our faculty, as well as the thousands of citations to their scholarly works combined, indicate that A&M researchers are making significant contributions to the advancement of cybersecurity knowledge. An increasing majority of the US population accesses the internet on a daily basis, giving cyber criminals more and more avenues to harvest personal information of every day citizens. Research conducted at Texas A&M aims to utilize university resources to combat these ever-changing threats to our security.

Research Themes

  • Resilient Adversary-Tolerant Systems
  • Malware and Malware Infrastructure Analysis
  • Cybersecurity Assessment and Vulnerability Analysis of the “Internet of Things”
  • Predictive Cyber Modeling
  • Cryptography
  • The Human Dimensions of Cybersecurity
    • Including: Business, Behavioral Science, Policy, Sociology, Statistics, Law, among others

Research Application Areas

  • Critical Infrastructure Protection
    • Focus on Energy, Transportation, Emergency Services, Public Health and Agriculture sectors
  • Interconnected and Autonomous Systems
  • Mobile Platforms and Communications
  • Privacy and Cyber Ethics
  • Cybersecurity Workforce Development and Cyber Operations

Research Facilities

The Texas Cyber Range (TxCR) provides scalable, virtualized environments where students, researchers, and cybersecurity professionals can conduct training, research, and cyber exercises using realistic network and system simulations. The Texas SCADA Testbed (TST) complements these capabilities by offering a specialized research environment focused on operational technology (OT) and industrial control systems that support critical infrastructure such as energy, manufacturing, transportation, and utilities.

Together, these facilities enable hands-on learning, advanced cybersecurity research, workforce development, and collaborative exercises for academic institutions, government agencies, and industry partners. By combining enterprise IT environments with critical infrastructure technologies, the facilities support the development, testing, and evaluation of cybersecurity solutions in realistic and adaptable settings.

TxCR

Texas Cyber Range

Established in 2017 by the Texas A&M Cybersecurity Center, the Texas Cyber Range (TxCR) provides scalable, virtual cybersecurity environments powered by XCP-ng. Hosted on the Texas A&M network, it supports remote education, research, training, workforce development, and cyber exercises for students, government agencies, and organizations.

Purpose

Initiated by the Texas A&M Cybersecurity Center in 2017, the Texas Cyber Range (TxCR) has become a cornerstone for cybersecurity innovation. At its core, TxCR leverages the power of XCP-ng, an open-source hypervisor renowned for its scalability, reliability, and adaptability. This platform empowers TxCR to offer a comprehensive, large-scale interactive simulation of intricate network infrastructures, system tools, and applications in a sophisticated virtual environment. With TxCR, participants are immersed in a world that supports groundbreaking research, intensive training, and hands-on cybersecurity exercises, cementing its role as a pivotal force for education, workforce development, and advanced cyber operations.

Harnessing the power of XCP-ng, the TxCR offers an unparalleled virtual environment that  enables students and participants to connect remotely, quickly, and precisely. Hosted on the robust Texas A&M University network, the TxCR provides a scalable and adaptable platform tailored to serve the diverse needs of various organizations. From Federal to Texas-specific entities, including state agencies, TxCR stands ready to support myriad requirements—education, pioneering research, hands-on training, workforce development, or specialized cybersecurity exercises.

Education, Training, Workforce Development
  • Certification Labs: Tailored environments for academic training and industry-standard certifications, including CompTIA, EC-Council, and Linux.
  • Competitive Platforms: An ideal hosting environment for events such as capture-the-flag competitions, fostering real-world cyber challenges.
  • Hands-On Workshops: Dive deep into practice operations from digital forensics to Wi-Fi hacking—experience specialized sessions on social engineering, phishing demonstrations, and more.
  • Industry-Standard Emulations: With lab simulations tailored for Cisco Academy, Juniper Academy, Palo Alto Academy, and beyond, TxCR ensures students get a feel for the tools professionals use.
  • Empowering Educators: Our commitment extends to providing K12 teachers with specialized cybersecurity development training, ensuring solid foundational knowledge for future generations.
Exercises
  • Ethical Hacking: Comprehensive training covering both offensive and defensive  cybersecurity strategies.
  • Red/Blue Team Scenarios: Engage in dynamic attack-and-defend simulations, honing collaborative and strategic skills.
  • Network Emulation: Replicate production environments to practice defense, identify vulnerabilities, and implement recovery techniques.
Faculty Advisor
TST

Texas SCADA Testbed

The Texas SCADA Testbed (TST) is a research platform for critical infrastructure cybersecurity, providing virtualized SCADA systems, industrial controllers, and engineering tools for OT research, training, and cyber exercises. Integrated with the Texas Cyber Range, it enables secure remote access for academic, government, and industry partners.

Purpose

The Texas SCADA Testbed (TST) is a cutting-edge research facility dedicated to advancing the operational technology (OT) that underpins critical infrastructure such as power grids, manufacturing facilities, traffic control systems, and oil and gas pipelines. The TST is designed to enable up-tempo, reconfigurable research through virtualization of physical components wherever possible. The facility was developed by a team of highly skilled OT engineers selected from the Cyber Leader Development Program (CLDP), and offers research opportunities to a wide range of organizations, from academic institutions to the Department of Defense.

At the core of the TST is a state-of-the-art supervisory control and data acquisition (SCADA) system, which provides a time-series database management system and user access to control via a human-machine interface (HMI). The SCADA system commands a series of programmable logic controllers from three leading manufacturers in the industrial control system (ICS) market – Siemens, Rockwell (Allen-Bradley), and Beckhoff. The TST’s network is integrated with the Texas Cyber Range (TxCR), which offers remote researchers off-site access to the testbed.

The TST’s OT network, which includes the SCADA system and programmable controllers, is supported by an information technology (IT) network comprised of production servers that use Xen-Orchestra to manage four virtual machines hosting engineering workstations running Windows 11 and Linux. These workstations are equipped with popular engineering software such as Studio5K, TIA Portal, TwinCAT 3, and Ignition Designer.

The TST’s enterprise network, which encompasses both OT and IT, employs a variety of internet and industrial fieldbus protocols, including TCP/IP, Ethernet/Industrial Protocol (EN/IP), ProfiNET, and Modbus TCP/IP. Overall, the TST offers a cutting-edge platform for applied research into critical infrastructure technology, and serves as a valuable resource for organizations looking to stay ahead of the curve in this rapidly evolving field.

AggieSCaPE

Step into the world of critical infrastructure cybersecurity with AggieSCaPE (Aggie Secure City and Physical Environment). This hands-on operational technology (OT) environment gives students the chance to explore, hack, and secure systems similar to the ones that keep our nation running. From energy and water to transportation, students work through realistic cyber scenarios that show what happens when digital threats meet physical systems. AggieSCaPE turns cybersecurity concepts into experience, giving students opportunities to solve problems, respond to threats, and build practical skills aligned with Department of Defense Cyber Workforce Framework (DCWF) work roles. Along the way, students can explore how their interests and abilities connect to real cyber careers while developing experience they can carry into internships, competitions, future coursework, and the workforce. It’s more than learning how cybersecurity works. It’s learning how to protect the systems people depend on every day.

Students will gain experience with:

  • PLC Security Interact with programmable logic controllers, examine control logic, identify vulnerabilities or unauthorized changes, and investigate how manipulation of a PLC can affect a physical process.
  • Vulnerability Assessments Inventory OT assets, identify vulnerabilities and misconfigurations, evaluate their operational impact, and prioritize remediation based on both cyber risk and mission consequences.
  • IT-to-OT Attack Scenarios Students investigate how an attacker might gain access through a traditional IT system and then move toward operational systems, reinforcing why IT and OT security cannot be treated as completely separate worlds.
  • Cyber-Physical Impact Exercises Students see how a cyber action can produce a physical consequence, such as changing a pump, valve, sensor, motor, or process setting.
  • Critical Infrastructure Mission Scenarios Exercises can be built around water treatment, energy distribution, transportation, or other infrastructure sectors so students learn cybersecurity within an operational mission rather than through isolated technical tasks.
  • Tabletop-to-Technical Exercises Students could begin with a scenario-based tabletop exercise, make operational and cybersecurity decisions, and then move into AggieSCaPE to test those decisions in the technical environment.
  • Digital Forensics Following an incident, students collect and analyze evidence to reconstruct what happened, identify the attack path, determine affected systems, and recommend corrective actions.

Accessibility improvements are in progress ahead of the April 2027 deadline. If you need immediate access, visit our Accommodations page.