
APOLOGEE
APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

ISAF aims to be a framework that provides the necessary tools for the correct security audit of industrial (OT) environments.

Paracosme is a zero-click remote memory corruption exploit that compromises ICONICS Genesis64 which was demonstrated successfully on stage during the…

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

PoC Modbus TCP exploit demonstrating spoofed writes to read-only coils in simulated PLCs, highlighting SCADA/ICS access control flaws.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Repository that tracks public exploits, vulnerabilities and advisories that I [co-]discovered or [co-]authored.

This repository contains a few vulnerabilities that were found and reported during vulnerability assessments.

Low Interaction Mobile Honeypot

Deploys realistic virtual SCADA/ICS testbeds with IEC 60870-5-104 and OPC-UA nodes, enabling attack simulations, legitimate packet generation, and…

A pre-authenticated RCE exploit for Inductive Automation Ignition

Description and exploit of CVE-2023-33831 affecting FUXA web-based Process Visualization (SCADA/HMI/Dashboard) software.

Analyzing and Reproducing the Command Injection Vulnerability (CVE-2023-0861) in NetModule Routers

Modbus Slave缓冲区溢出漏洞CVE-2022-1068分析与复现

Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without…