
DeTTECT
Detect Tactics, Techniques & Combat Threats

Detect Tactics, Techniques & Combat Threats



Rail-OT-Protector (ROP) — free, open-source cybersecurity scanning tool for rail and transit OT/SCADA networks. PowerShell + Bash scanners for…


Repository that tracks public exploits, vulnerabilities and advisories that I [co-]discovered or [co-]authored.

A Zeek package for the passive detection of "Ripple20" vulnerabilities in the Treck TCP/IP stack.

Python scripts for security assessment of industrial PLCs: scanning, enumeration, control, and exploitation of Beckhoff, Siemens, Schneider,…

Fuzzer for the Sparkplug B IIoT protocol

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR


Defensive security demo: seL4 microkernel gateway protecting vulnerable ICS from CVE-2019-14462

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

Modbus Packet Injection on Advantech WISE 4060LAN / IoT Gateway for door control

CVE-2025-41646 - Critical Authentication bypass

ISAF aims to be a framework that provides the necessary tools for the correct security audit of industrial (OT) environments.

Critical vulnerability in Siemens RuggedCom ROS devices allowing attackers to derive a hidden factory account password from the device MAC address…