Loading...
Loading...
Used for authorized OT/ICS security assessments, covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.
npx skill4agent add zhaoxuya520/reverse-skill ot-icsNOW../field-journal/precedent-pentest.mdNOWNOWready_for_actNEXTACTMUST NOT perform the following without explicit permission:
- Write coils/registers to PLCs
- High-rate scanning of the entire production OT network
- Interrupt paths related to Safety Instrumented Systems (SIS)
Prioritize: read-only identification, traffic mirroring, offline firmware/configuration analysis□ Sketch of Purdue L0–L5: Field devices → Control → Supervision → Site DMZ → Enterprise
□ Asset inventory: PLC/RTU/HMI/Engineer workstations/Historical databases/Jump hosts
□ Protocol and port baseline (authorized network segments only)□ SPAN/mirrored PCAP → protocol-reverse / Wireshark industrial control dissectors
□ Offline audit of configuration and engineering files (e.g., exports from TIA/RSLogix)
□ Record default passwords and plaintext protocols (e.g., unauthenticated Modbus) as Findings; do not write or modify values□ Low-speed identification, maintenance window only
□ Prioritize read-only function codes
□ Document evidence for each step; stop immediately and report any anomalies□ Controller firmware version → CVE mapping (do not blindly flash firmware)
□ Conduct offline image analysis in conjunction with firmware-pentest| Tool | Purpose | Notes |
|---|---|---|
| Wireshark industrial control dissectors | Passive parsing | Mirrored traffic only |
| Nmap NSE (restricted) | Identification | Rate and time window restrictions |
| Claroty/Nozomi, etc. | Asset discovery | Commercial/on-site tools |
| PLC vendor engineering software | Configuration audit | Prioritize offline use |
| binwalk / Ghidra | Firmware analysis | Offline only |
references/ot-safe-assessment.md../firmware-pentest/../protocol-reverse/../networkfirmware-pentestprotocol-reversewindows-adattack-chain