A curated list of resources related to Industrial Control System (ICS) security.
A curated list of resources related to Industrial Control System (ICS) security.
Feel free to contribute.
| AttkFinder | AttkFinder is a tool that performs static program analysis of PLC programs, and produce Data-oriented Attack vectors. In a nutshell, AttkFinder takes PLC programs written under the standard IEC-61131-3 in xml-format or structured text, and builds a Data-Flow graph (DFG), a Control-Flow graph (CFG) and translates the program into a Structured Intermediate Representation Language (STIR) version. A symbolic execution engine analyses the stir-version code searching for attack vectors that can be exploited by a malicious actuator. |
| CSET | The Cyber Security Evaluation Tool (CSET®) assists organizations in protecting their key national cyber assets. This tool provides users with a systematic and repeatable approach for assessing the security posture of their cyber systems and networks. It includes both high-level and detailed questions related to all industrial control and IT systems. |
| Digital Bond's 3S CoDeSys Tools | Digital Bond created three tools for interacting with PLCs that run CoDeSys, consisting of a command shell, file transfer and NMap script. |
| Digital Bond's ICS Enumeration Tools | Redpoint is a Digital Bond research project to enumerate ICS applications and devices using nmap extensions. It can be used during assessments to discover ICS devices and pull information that would be helpful in secondary testing. The Redpoint tools use legitimate protocol or application commands to discover and enumerate devices and applications. There is no effort to exploit or crash anything, but be wise and careful. |
| GRASSMARLIN | GRASSMARLIN provides IP network situational awareness of industrial control systems (ICS) and Supervisory Control and Data Acquisition (SCADA) networks to support network security. Passively map, and visually display, an ICS/SCADA network topology while safely conducting device discovery, accounting, and reporting on these critical cyber-physical systems. |
| ics_mem_collect | Memory collector for GE D20MX. The project itself can be extended to work with other devices. |
| ISF | The Industrial Exploitation Framework (ISF) is an exploitation framework similar to Metasploit written in Python. It is based on the open source Routersploit tool. It contains exploits for several types of controllers, such as QNX, Siemens and Schneider devices and includes several scanners. |
| ISEF | The Industrial Security Exploitation Framework (ISEF) is an exploitation framework based on the Equation Group Fuzzbunch toolkit as released by Shadow Brokers. It's developed by the ICSMASTER Security Team. |
| ICSREF | A modular framework that automates the reverse engineering process of CODESYS binaries compiled with the CODESYS v2 compiler. |
| ICSFuzz | A PLC-side fuzzing tool for uncovering vulnerabilities in ICS control applications. The current version supports only applications based on the Codesys platform which has been modified and adapted for the Wago PLC. |
| ꓘamerka GUI | Ultimate Internet of Things/Industrial Control Systems reconnaissance tool. |
| mbtget | mbtget - Simple perl script for make some modbus transaction from the command line. |
| MiniCPS | MiniCPS: A toolkit for security research on Cyber-Physical Systems from Singapore University of Technology and Design (SUTD). |
| MODBUS Penetration Testing Framework | smod is a modular framework with every kind of diagnostic and offensive feature you could need in order to pentest modbus protocol. It is a full Modbus protocol implementation using Python and Scapy. The framework can be used to perform vulnerability assessments. |
| ModbusPal | ModbusPal is a MODBUS slave simulator. Its purpose is to offer an easy to use interface with the capabilities to reproduce complex and realistic MODBUS environments. |
| ModScan | ModScan is a new tool designed to map a SCADA MODBUS TCP based network. |
| NetToPLCSim | TCP/IP-Network extension for the PLC simulation software Siemens PLCSim. |
| OpenDNP3 | OpenDNP3 is the de facto reference implementation of IEEE-1815 (DNP3) provided under the Apache License. It is currently in maintenance-only mode and new features are no longer being added. Automatak has rebranded as Step Function I/O and is now focused on writing protocol libraries in Rust. |
| PLCinject | PLCinject can be used to inject code into PLCs. |
| plcscan | Tool for scaning PLC devices over the s7comm or modbus protocol. |