Redpoint Logo

Redpoint

0
Free
Visit Website

Redpoint is a Digital Bond research project to enumerate ICS applications and devices. We use our Redpoint tools in assessments to discover ICS devices and pull information that would be helpful in secondary testing. A portion of those tools will be made available as Nmap NSE scripts to the public in this repository. The Redpoint tools use legitimate protocol or application commands to discover and enumerate devices and applications. There is no effort to exploit or crash anything. However many ICS devices and applications are fragile and can crash or respond in an unexpected way to any unexpected traffic so use with care. Each script is documented below and available in a .nse file in this repository. BACnet-discover-enumerate.nse - Identify and enumerate BACnet devices codesys-v2-discover.nse - Identify and enumerate CoDeSys V2 controllers enip-enumerate.nse - Identify and enumerate EtherNet/IP devices from Rockwell Automation and other vendors fox-info.nse - Identify and enumerate Niagara Fox devices modicon-info.nse - Identify and enumerate Schneider Electric Modicon PLCs omron-info.nse - Identify and enumerate Omron PLCs pcworx

FEATURES

ALTERNATIVES

A set of Bro/Zeek scripts that detect ATT&CK-based adversarial activity and raise notices

Passive sniffer tool for analyzing traffic patterns.

Romana automates cloud native network creation and secures applications with a distributed firewall.

Authenticated SSRF in Grafana

Detects and prevents SSRF attacks

NBD is a user-space network protocol for sharing block devices over a network, allowing clients to access block devices on a server as if they were local.

A fast and flexible web fuzzer for identifying vulnerabilities in web applications

6Guard is an IPv6 attack detector sponsored by Google Summer of Code 2012 and supported by The Honeynet Project organization.