
Redpoint
Nmap NSE scripts for ICS/SCADA discovery and enumeration—BACnet, EtherNet/IP, CoDeSys, Fox, Modicon, Omron, S7—using protocol queries for security…

Nmap NSE scripts for ICS/SCADA discovery and enumeration—BACnet, EtherNet/IP, CoDeSys, Fox, Modicon, Omron, S7—using protocol queries for security…

A curated list of resources related to Industrial Control System (ICS) security.

Small script to retrieve passwords from many types of Moxa device, including NPort, OnCell, MGate, etc.

CVE-2018-11517 | mySCADA myPRO v7.0.46 has another vulnerability to discover all projects in the system.

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

TROMMEL: Sift Through Embedded Device Files to Identify Potential Vulnerable Indicators


DejaVU - Open Source Deception Framework

IoT and Operational Technology Honeypot



Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Ultimate Internet of Things/Industrial Control Systems reconnaissance tool.

Python scripts for security assessment of industrial PLCs: scanning, enumeration, control, and exploitation of Beckhoff, Siemens, Schneider,…

BOF (Boiboite Opener Framework) is a testing framework for industrial protocols implementations and devices.

Proof-of-concept exploit for authentication bypass via capture-replay in Dingtian DT-R002 relay, allowing unauthorized control of relays through HTTP…

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE