scada-ics-security

Identify and mitigate SCADA/ICS security risks across major ICS protocols.

60|14|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/brucesongs/kali-claw --skill scada-ics-security
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: scada-ics-security
Source: https://github.com/brucesongs/kali-claw/tree/main/skills/scada-ics-security
Command: npx skills add https://github.com/brucesongs/kali-claw --skill scada-ics-security

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

SCADA/ICS environments are often exposed to protocol weaknesses and visibility gaps, making comprehensive security evaluations difficult without specialized tooling. This Skill bundles a complete SCADA/ICS security assessment framework, including payloads, guides, and reference materials to enable safe, lab-based testing, reproducible findings, and actionable recommendations.

Core Features & Use Cases

  • Protocol coverage: Modbus TCP, S7comm, DNP3, EtherNet/IP, OPC UA, BACnet, and GOOSE with structured test cases and payloads
  • Comprehensive methodology: passive reconnaissance, active enumeration, vulnerability assessment, honeypot deployment, and incident-response workflows
  • Practical tooling: plcscan, s7scan, modbus-cli, mbpoll, enip-client, python-opcua, conpot integration
  • Use cases: ICS device discovery, protocol vulnerability testing, ICS network segmentation validation, and honeypot-based detection testing
  • Safety and defense: Purdue Model alignment, MITRE ATT&CK ICS mapping TA0100, and defense-in-depth recommendations

Quick Start

Run the ICS security assessment suite in a lab environment; begin by wiring up an isolated ICS lab, then follow the guides to perform protocol discovery, vulnerability testing, honeypot deployment, and reporting.

Frequently Asked Questions about scada-ics-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a SCADA security assessment for Modbus TCP and DNP3 protocols?

SCADA security assessment involves using this framework's structured test cases and payloads for Modbus TCP and DNP3 to identify protocol vulnerabilities through lab-based active enumeration and passive reconnaissance.

What is the best way to discover ICS devices across an OT network?

ICS device discovery is best achieved using integrated scanning tools like plcscan and s7scan to perform passive reconnaissance and active enumeration, mapping out SCADA environment assets safely before deeper vulnerability testing.

Can I use this toolkit to test ICS network segmentation against the Purdue Model?

Yes, you can validate ICS network segmentation using this toolkit, which aligns its assessment methodology with the Purdue Model and MITRE ATT&CK ICS mapping to verify defense-in-depth controls in OT environments.

How do I deploy deception-based defense for SCADA environments?

To deploy deception-based defense for SCADA environments, the framework integrates conpot to deploy honeypots, enabling detection testing and incident-response preparation against attackers targeting ICS protocols.

Do I need an isolated lab environment to test SCADA vulnerabilities?

Yes, you need an isolated lab environment to safely test SCADA vulnerabilities, as this framework is designed for lab-focused testing to ensure operational technology safety while running protocol payloads and assessments.