Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Redpoint — Nmap NSE scripts for ICS/SCADA discovery and enumeration—BACnet, EtherNet/IP, CoDeSys, Fox, Modicon, Omron, S7—using protocol queries for security assessments. | Kitploit
Tools/GitHubGitHub/digitalbond/redpoint
ReconnaissanceSCADA/ICS SecurityInformation GatheringNetwork SecurityPenetration TestingTop in SCADA/ICS Security #5
GitHubdigitalbond/redpoint

Redpoint

Nmap NSE scripts for ICS/SCADA discovery and enumeration—BACnet, EtherNet/IP, CoDeSys, Fox, Modicon, Omron, S7—using protocol queries for security assessments.

View Repository
4721498010 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

#Redpoint

###Digital Bond's ICS Enumeration Tools

Redpoint is a Digital Bond research project to enumerate ICS applications and devices.

We use our Redpoint tools in assessments to discover ICS devices and pull information that would be helpful in secondary testing. A portion of those tools will be made available as Nmap NSE scripts to the public in this repository.

The Redpoint tools use legitimate protocol or application commands to discover and enumerate devices and applications. There is no effort to exploit or crash anything. However many ICS devices and applications are fragile and can crash or respond in an unexpected way to any unexpected traffic so use with care.

Each script is documented below and available in a .nse file in this repository.

  • BACnet-discover-enumerate.nse - Identify and enumerate BACnet devices

  • codesys-v2-discover.nse - Identify and enumerate CoDeSys V2 controllers

  • enip-enumerate.nse - Identify and enumerate EtherNet/IP devices from Rockwell Automation and other vendors

  • fox-info.nse - Identify and enumerate Niagara Fox devices

  • modicon-info.nse - Identify and enumerate Schneider Electric Modicon PLCs

  • omron-info.nse - Identify and enumerate Omron PLCs

  • pcworx-info.nse - Identify and enumerate PC Worx Protocol enabled PLCs

  • proconos-info.nse - Identify and enumerate ProConOS enabled PLCs

  • s7-enumerate.nse - Identify and enumerate Siemens SIMATIC S7 PLCs

==

###BACnet-discover-enumerate.nse

![BACnet-discover-enumerate Sample Output] (http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2014/03/BACnet-nse.png)

####Authors

Stephen Hilt and Michael Toecker
Digital Bond, Inc

####Purpose and Description

The purpose of BACnet-discover-enumerate.nse is to first identify if an IP connected devices is running BACnet. This works by querying the device with a pre-generated BACnet message. Newer versions of the BACnet protocol will respond with an acknowledgement, older versions will return a BACnet error message. Presence of either the acknowledgement or the error is sufficient to prove a BACnet capable device is at the target IP Address.

Second, if an acknowledgement is received, this script will also attempt to enumerate several BACnet properties on a responsive BACnet device. Again, the device is queried with a pregenerated BACnet message. Successful enumeration uses specially crafted requests, and will not be successful if the BACnet device does not support the property.

BACnet properties queried by this script are:

  1. Vendor ID - A number that corresponds to a registered BACnet Vendor. The script returns the associated vendor name as well.

  2. Vendor Number - A String that represents the Vendor Name that is configured on the device. This can differ from the Vendor ID as the Vendor ID is the Number registered with ASHARE.

  3. Object Identifier - A number that uniquely identifies the device. If the Object-Identifier is known, it is possible to send commands with BACnet client software, including those that change values, programs, schedules, and other operational information on BACnet devices. This is a required property for all BACnet devices.

  4. Firmware Revision - The revision number of the firmware on the BACnet device.

  5. Application Software Revision - The revision number of the software being used for BACnet communication.

  6. Object Name - A user defined string that assigns a name to the BACnet device, commonly entered by technicians on commissioning. This is a required property for all BACnet devices.

  7. Model Name - The model of the BACnet device

  8. Description - A user defined string for describing the device, commonly entered by technicians on commissioning

  9. Location - A user defined string for recording the physical location of the device, commonly entered by technicians on commissioning

  10. Broadcast Distribution Table (BDT) - A list of the BACnet Broadcast Management Devices (BBMD) in the BACnet network. This will identify all of the subnets that are part of the BACnet network.

  11. Foreign Device Table (FDT) - A list of foreign devices registered with the BACnet device. A foreign device is any device that is not on a subnet that is part of the BACnet network, not in the BDT. Foreign devices often are located on external networks and could be an attacker's IP address.

The BDT and FDT can be large lists and may be not desired in a large Nmap scan. The basic script will not pull down the BDT and FDT. Run the command with the --script-args full=yes to pull the BDT and FDT, see the Usage section.

![BACnet-discover-enumerate Sample Output with BDT and FDT] (http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2014/08/screenshot_bacnet-1.png)

This script uses a feature added in 2004 to the BACnet specification in order to retrieve the Object Identifier of a device with a single request, and without joining the BACnet network as a foreign device. (See ANSI/ASHRAE Addendum a to ANSI/ASHRAE Standard 135-2001 for details)

####History and Background

From Wikipedia article on BACnet http://en.wikipedia.org/wiki/BACnet:

BACnet is a communications protocol for building automation and control networks. It is an ASHRAE, ANSI, and ISO standard[1] protocol. The default port for BACnet traffic is UDP/47808.

BACnet is used in building automation and control systems for applications such as heating, ventilating, and air-conditioning control, lighting control, access control, and fire detection systems and their associated equipment. The BACnet protocol provides mechanisms for computerized building automation devices to exchange information, regardless of the particular building service they perform.

####Installation

This script requires nmap to run. If you do not have Nmap download and Install Nmap based off the Nmap instructions. http://nmap.org/download.html

#####Windows

After downloading bacnet-discover.nse you'll need to move it into the NSE Scripts directory, this will have to be done as an administrator. Go to Start -> Programs -> Accessories, and right click on 'Command Prompt'. Select 'Run as Administrator'.

move BACnet-discover-enumerate.nse C:\Program Files (x86)\Nmap\scripts

#####Linux

After Downloading BACnet-discover-enumerate.nse you'll need to move it into the NSE Scripts directory, this will have to be done as sudo/root.

sudo mv BACnet-discover-enumerate.nse /usr/share/nmap/scripts
	

####Usage

Inside a Terminal Window/Command Prompt use one of the following commands where host is the target you wish you scan for BACNet. Use --script-args full=yes if you want the output to included the BDT and FDT.

Windows: nmap -sU -p 47808 --script BACnet-discover-enumerate <host>
Windows: nmap -sU -p 47808 --script BACnet-discover-enumerate --script-args full=yes <host>

Linux: sudo nmap -sU -p 47808 --script BACnet-discover-enumerate <host> 
Linux: sudo nmap -sU -p 47808 --script BACnet-discover-enumerate --script-args full=yes <host>

To speed up results by not performing DNS lookups during the scan use the -n option, also disable pings to determine if the device is up by doing a -Pn option for full results.

nmap -sU -Pn -p 47808 -n --script BACnet-discover-enumerate <host>

	

####Notes

Download Tool