#1Tools for assessing and securing Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS).
Kitploit recommended

Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to…

A pre-authenticated RCE exploit for Inductive Automation Ignition

Technical vulnerability analysis and CVE briefing for CVE-2026-9645 affecting ScadaBR.

Detect Tactics, Techniques & Combat Threats

A Curated list of Security Resources for all connected things

Working exploit for Phoenix Contact CHARX SEC-3100 using Scapy raw Ethernet packets to trigger vulnerabilities and obtain an interactive connect-back…

Proof-of-concept exploit for OPC UA authentication bypass using None security policy, including a simulated server to demonstrate unauthorized…

Free BACnet/BMS vulnerability scanner for building automation systems. Detects CVE-2026-3611 (CVSS 10.0), CVE-2026-24060, and exposed HVAC/BAS…

Rail-OT-Protector (ROP) — free, open-source cybersecurity scanning tool for rail and transit OT/SCADA networks. PowerShell + Bash scanners for…

ICS-Park Smart Park Management System v2.0

PoC Modbus TCP exploit demonstrating spoofed writes to read-only coils in simulated PLCs, highlighting SCADA/ICS access control flaws.

Proof-of-concept reproducing CVE-2021-22681's hardcoded-key flaw and validating a per-device mutual TLS/CRL fix over simulated EtherNet/IP, with IEC…

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

Real world and CTFs exploiting web/binary POCs.

Small script to retrieve passwords from many types of Moxa device, including NPort, OnCell, MGate, etc.

Active Scanning and Information Gathering in ICS/SCADA Networks using Network Mapper (NMAP) (Turkish)

Purdue Model for Industrial Control System (ICS) Environments (Turkish)

This repository contains a few vulnerabilities that were found and reported during vulnerability assessments.