Skip to main content

ics-ot-overview

ICS / OT attack category — Modbus, BACnet, S7Comm, DNP3. Routing skill: fingerprint the industrial protocol by port + Wireshark dissector, then load the matching sub-skill. SAFETY-CRITICAL: always confirm written scope before any write/control class action.

Jump to install

Source facts

Repository
BitterSecurity/Decepticon
Last source activity
May 30, 2026 at 11:42
Detected SKILL.md language
English
Stars
5,565
Forks
1,053

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.

File Explorer
8 files

Showing SKILL.md

SKILL.md
Source instructions · Read-only preview
name
ics-ot-overview
description
ICS / OT attack category — Modbus, BACnet, S7Comm, DNP3. Routing skill: fingerprint the industrial protocol by port + Wireshark dissector, then load the matching sub-skill. SAFETY-CRITICAL: always confirm written scope before any write/control class action.
allowed-tools
Bash Read Write
metadata
{"when_to_use":"ics ot industrial scada plc rtu modbus bacnet s7 siemens dnp3 hmi mes opc opc-ua profinet ethernet/ip cip","subdomain":"ics-ot","tags":"ics, ot, scada, industrial","mitre_attack":"T0855, T0836, T0846, T0816"}
# Industrial Control Systems / OT Category This is a routing skill for industrial protocol engagements. Identify the protocol by port + wire format, then load the matching sub-skill. ## SAFETY FIRST Writes to ICS/OT devices can move physical actuators — open valves, trip breakers, freeze pumps, override safety setpoints. **Confirm written scope authorization for any write/control class operation. Read-only enumeration is generally safe.** If unsure, default to read-only. ## Protocol routing | Protocol | TCP/UDP Port | Sub-skill | Wire fingerprint | |---|---|---|---| | **Modbus TCP** | TCP 502 | `modbus` | MBAP header, function codes 1-127 | | **BACnet/IP** | UDP 47808 | `bacnet` | APDU PDU types 0-15, Who-Is/I-Am | | **Siemens S7Comm** | TCP 102 | `s7comm` | ISO-on-TCP (RFC 1006) + S7 protocol IDs | | **DNP3** | TCP 20000 | `dnp3` | Start bytes 0x05 0x64, link layer | | **EtherNet/IP + CIP** | TCP 44818, UDP 2222 | (use enumeration; CVE-driven exploits) | ENIP encapsulation header | | **PROFINET RT** | UDP 34962-34964 | (use enumeration) | EtherType 0x8892 (L2) | | **OPC UA** | TCP 4840 | (use enumeration) | OPC UA Binary protocol | ## Quick fingerprint sweep ```bash nmap -sV -p 102,502,20000,44818,4840 --script="*ics*,*scada*,modbus-discover,s7-info,dnp3-info,bacnet-info,enip-info" 10.0.0.0/24 ``` ## Useful tooling | Tool | Use | |---|---| | `pymodbus`, `mbtget` | Modbus client | | `bacpypes`, `bacnet-stack` | BACnet client | | `snap7`, `python-snap7` | S7Comm client | | `opendnp3`, `dnp3-toolkit` | DNP3 master | | `cip-py`, `pylogix` | EtherNet/IP / CIP (Allen-Bradley) | | `python-opcua` / `opcua-asyncio` | OPC UA | | `ISF` (Industrial Security Framework) | Mass enumeration + exploit framework | | `PLCinject` | Siemens S7 logic injection | ## Defender baseline (useful for triage) ICS-CERT advisories (https://www.cisa.gov/uscert/ics/advisories), Dragos Threat Intel Briefs, Nozomi / Claroty / Tenable.ot for telemetry. Understanding what defenders see helps you stay below detection thresholds.
View on GitHub