Skip to main content

ics-ot-overview

ICS / OT attack category — Modbus, BACnet, S7Comm, DNP3. Routing skill: fingerprint the industrial protocol by port + Wireshark dissector, then load the matching sub-skill. SAFETY-CRITICAL: always confirm written scope before any write/control class action.

Ir a la instalación

Datos de origen

Repositorio
BitterSecurity/Decepticon
Última actividad en el origen
30 de mayo de 2026 a las 11:42
Idioma detectado de SKILL.md
inglés
Estrellas
5611
Forks
1061

Opciones de instalación

De forma predeterminada está seleccionado el prompt que primero revisa el origen. Puedes cambiar a un comando directo o descargar una copia local.

Revisa los archivos de origen

Lee SKILL.md y los archivos complementarios que muestra SkillsMP antes de decidir si quieres instalarlo.

Explorador de archivos
8 archivos

Mostrando SKILL.md

SKILL.md
Instrucciones de origen · Vista previa de solo lectura
name
ics-ot-overview
description
ICS / OT attack category — Modbus, BACnet, S7Comm, DNP3. Routing skill: fingerprint the industrial protocol by port + Wireshark dissector, then load the matching sub-skill. SAFETY-CRITICAL: always confirm written scope before any write/control class action.
allowed-tools
Bash Read Write
metadata
{"when_to_use":"ics ot industrial scada plc rtu modbus bacnet s7 siemens dnp3 hmi mes opc opc-ua profinet ethernet/ip cip","subdomain":"ics-ot","tags":"ics, ot, scada, industrial","mitre_attack":"T0855, T0836, T0846, T0816"}
# Industrial Control Systems / OT Category This is a routing skill for industrial protocol engagements. Identify the protocol by port + wire format, then load the matching sub-skill. ## SAFETY FIRST Writes to ICS/OT devices can move physical actuators — open valves, trip breakers, freeze pumps, override safety setpoints. **Confirm written scope authorization for any write/control class operation. Read-only enumeration is generally safe.** If unsure, default to read-only. ## Protocol routing | Protocol | TCP/UDP Port | Sub-skill | Wire fingerprint | |---|---|---|---| | **Modbus TCP** | TCP 502 | `modbus` | MBAP header, function codes 1-127 | | **BACnet/IP** | UDP 47808 | `bacnet` | APDU PDU types 0-15, Who-Is/I-Am | | **Siemens S7Comm** | TCP 102 | `s7comm` | ISO-on-TCP (RFC 1006) + S7 protocol IDs | | **DNP3** | TCP 20000 | `dnp3` | Start bytes 0x05 0x64, link layer | | **EtherNet/IP + CIP** | TCP 44818, UDP 2222 | (use enumeration; CVE-driven exploits) | ENIP encapsulation header | | **PROFINET RT** | UDP 34962-34964 | (use enumeration) | EtherType 0x8892 (L2) | | **OPC UA** | TCP 4840 | (use enumeration) | OPC UA Binary protocol | ## Quick fingerprint sweep ```bash nmap -sV -p 102,502,20000,44818,4840 --script="*ics*,*scada*,modbus-discover,s7-info,dnp3-info,bacnet-info,enip-info" 10.0.0.0/24 ``` ## Useful tooling | Tool | Use | |---|---| | `pymodbus`, `mbtget` | Modbus client | | `bacpypes`, `bacnet-stack` | BACnet client | | `snap7`, `python-snap7` | S7Comm client | | `opendnp3`, `dnp3-toolkit` | DNP3 master | | `cip-py`, `pylogix` | EtherNet/IP / CIP (Allen-Bradley) | | `python-opcua` / `opcua-asyncio` | OPC UA | | `ISF` (Industrial Security Framework) | Mass enumeration + exploit framework | | `PLCinject` | Siemens S7 logic injection | ## Defender baseline (useful for triage) ICS-CERT advisories (https://www.cisa.gov/uscert/ics/advisories), Dragos Threat Intel Briefs, Nozomi / Claroty / Tenable.ot for telemetry. Understanding what defenders see helps you stay below detection thresholds.
Ver en GitHub