#1Tools for assessing and securing Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS).
Kitploit recommended

A pre-authenticated RCE exploit for Inductive Automation Ignition
Self-hosted network discovery and search engine with continuous port scanning, deep protocol probing across ~100 services, local CVE matching, and…

Small script to retrieve passwords from many types of Moxa device, including NPort, OnCell, MGate, etc.

Automated Security Risk Identification Using AutomationML-based Engineering Data

A Zeek package for the passive detection of "Ripple20" vulnerabilities in the Treck TCP/IP stack.

Instrumented fuzzer for PLC-based ICS control applications, targeting Codesys runtime on Wago controllers to uncover memory corruption and…

PoC C&C for the Industroyer malware

A tool to manipulate Schneider Electric PLC archive files

Working exploit for Phoenix Contact CHARX SEC-3100 using Scapy raw Ethernet packets to trigger vulnerabilities and obtain an interactive connect-back…

A high-performance, asynchronous SCADA/ICS scanner

Proof-of-concept exploit for CVE-2021-26828 enabling authenticated remote code execution on ScadaBR SCADA systems via JSP file upload. Supports…

CVE-2018-11311 | mySCADA myPRO 7 Hardcoded FTP Username and Password Vulnerability

Description and exploit of CVE-2023-33831 affecting FUXA web-based Process Visualization (SCADA/HMI/Dashboard) software.

Proof-of-concept exploit for authentication bypass via capture-replay in Dingtian DT-R002 relay, allowing unauthorized control of relays through HTTP…

proof of Concept (PoC) exploit for CVE-2021-31630, targeting the OpenPLC service running on the WifineticTwo box on the Hack The Box platform.

Analyzing and Reproducing the Command Injection Vulnerability (CVE-2023-0861) in NetModule Routers

ISAF aims to be a framework that provides the necessary tools for the correct security audit of industrial (OT) environments.

Sanitized offline fixture verifier for CVE-2026-81861 in SCADAPack Secure Lock