What problem does it solve?
SCADA/ICS environments are often exposed to protocol weaknesses and visibility gaps, making comprehensive security evaluations difficult without specialized tooling. This Skill bundles a complete SCADA/ICS security assessment framework, including payloads, guides, and reference materials to enable safe, lab-based testing, reproducible findings, and actionable recommendations.
Core Features & Use Cases
- Protocol coverage: Modbus TCP, S7comm, DNP3, EtherNet/IP, OPC UA, BACnet, and GOOSE with structured test cases and payloads
- Comprehensive methodology: passive reconnaissance, active enumeration, vulnerability assessment, honeypot deployment, and incident-response workflows
- Practical tooling: plcscan, s7scan, modbus-cli, mbpoll, enip-client, python-opcua, conpot integration
- Use cases: ICS device discovery, protocol vulnerability testing, ICS network segmentation validation, and honeypot-based detection testing
- Safety and defense: Purdue Model alignment, MITRE ATT&CK ICS mapping TA0100, and defense-in-depth recommendations
Quick Start
Run the ICS security assessment suite in a lab environment; begin by wiring up an isolated ICS lab, then follow the guides to perform protocol discovery, vulnerability testing, honeypot deployment, and reporting.