CSET The Cyber Evaluation Tool (CSET®) assists organizations in protecting their key national cyber assets. This tool provides users with a systematic and repeatable approach for assessing the posture of their cyber systems and networks. It includes both high-level and detailed questions related to all and IT systems. Digital Bond’s 3S CoDeSys Tools Digital Bond created three for interacting with PLCs that run CoDeSys, consisting of a command shell, file transfer and NMap script. Digital Bond’s ICS Enumeration Tools Redpoint is a Digital Bond research project to enumerate applications and devices using nmap extensions. It can be used during assessments to discover devices and pull information that would be helpful in secondary testing. The Redpoint tools use legitimate protocol or application commands to discover and enumerate devices and applications. There is no effort to exploit or crash anything, but be wise and careful. GRASSMARLIN GRASSMARLIN provides IP network situational awareness of industrial control systems (ICS) and Supervisory Control and Acquisition (SCADA) networks to support network security. Passively map, and visually display, an ICS/SCADA network topology while safely conducting device discovery, accounting, and reporting on these critical cyber-physical systems. mbtget mbtget – Simple perl script for make some modbus transaction from the command line. MiniCPS MiniCPS: A toolkit for security research on Cyber-Physical Systems from Singapore University of Technology and Design (SUTD). MODBUS Penetration Testing Framework smod is a modular framework with every kind of diagnostic and offensive feature you could need in order to pentest modbus protocol. It is a full Modbus protocol implementation using Python and Scapy. The framework can be used to perform vulnerability assessments. ModbusPal ModbusPal is a MODBUS slave simulator. Its purpose is to offer an easy to use interface with the capabilities to reproduce complex and realistic MODBUS environments. ModScan ModScan is a new tool designed to map a SCADA MODBUS TCP based network. NetToPLCSim TCP/IP-Network extension for the PLC simulation Siemens PLCSim. Opendnp3 Opendnp3 is the de facto reference implementation of IEEE-1815 (DNP3) provided under the Apache License. PLCinject PLCinject can be used to inject code into PLCs. plcscan Tool for scaning PLC devices over the s7comm or modbus protocol. Quickdraw IDS The Quickdraw IDS project by Digital Bond includes Snort rules for SCADA devices and so-called preprocessors for network traffic. The preprocessors provide significant additional value because of their ability to reconstruct the protocol and state for use by Snort. SCADAShutdownTool SCADAShutdownTool is an industrial control system automation and testing tool allows security researchers and to test SCADA security systems, enumerate slave controllers, read controller’s registers values and rewrite registers data. Snap7 Snap7 is an open source, 32/64 bit, multi-platform Ethernet communication suite for interfacing natively with Siemens S7 PLCs. The new CPUs 1200/1500, the old S7200, the small LOGO 0BA7/0BA8 and SINAMICS Drives are also partially supported. S7 Password Bruteforcer A tool to bruteforce the password used by S7 instances from a PCAP using a dictionary. Originalcreated by SCADAStrangelove. splonebox splonebox is an open source network assessment tool with focus on modularity. It offers an ongoing analysis of a network and its devices. One major design decision features development of custom plugins, including ones for industrial communication protocols. Wireshark Wireshark is the world’s foremost network protocol analyzer. It lets you see what’s happening on your network at a microscopic level. It is the de facto (and often de jure) standard across many industries and educational institutions. It has support for many protocols used in ICS.

Source link


Please enter your comment!
Please enter your name here