#1Tools for assessing and securing Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS).
Kitploit recommended

This repository includes the code and files needed to test and execute a PoC for CVE-2025-41656
To reproduce CVE-2021-31630

A curated list of resources related to Industrial Control System (ICS) security.

Exploit for CVE-2021-31630 in OpenPLC, providing a Python script and manual steps to achieve remote code execution via malicious ST file upload and…

OpenPLC Runtime suffers from a persistent denial of service (DoS) vulnerability in the /upload-program-action endpoint.


Java-based mission control framework with YAML configuration, supporting telemetry, commanding, and simulation for spacecraft operations. Includes…

Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without…

DejaVU - Open Source Deception Framework

CVE-2025-41646 - Critical Authentication bypass

Modbus Packet Injection on Advantech WISE 4060LAN / IoT Gateway for door control

SpiderControl SCADA Web Server File Upload Vulnerability

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

Tools, tips, tricks, and more for exploring ICS Security.

A collection of fascinating and bizarre Censys Search Queries

Multi-protocol honeypot simulator supporting 50+ network services with deep interaction, TCP/UDP/ICMP logging, JA3 fingerprinting, and virtual…

Proof Of Concept for the CVE-2012-1831 (Kingview Touchview 6.53). This is a Industrial Control Systems Vulnerability

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…