Redpoint is a Digital Bond research project to enumerate ICS applications and devices. We use our Redpoint tools in assessments to discover ICS devices and pull information that would be helpful in secondary testing. A portion of those tools will be made available as Nmap NSE scripts to the public in this repository. The Redpoint tools use legitimate protocol or application commands to discover and enumerate devices and applications. There is no effort to exploit or crash anything. However many ICS devices and applications are fragile and can crash or respond in an unexpected way to any unexpected traffic so use with care. Each script is documented below and available in a .nse file in this repository. BACnet-discover-enumerate.nse - Identify and enumerate BACnet devices codesys-v2-discover.nse - Identify and enumerate CoDeSys V2 controllers enip-enumerate.nse - Identify and enumerate EtherNet/IP devices from Rockwell Automation and other vendors fox-info.nse - Identify and enumerate Niagara Fox devices modicon-info.nse - Identify and enumerate Schneider Electric Modicon PLCs omron-info.nse - Identify and enumerate Omron PLCs pcworx
An analyzer for parsing GQUIC traffic in Zeek, supporting versions Q039 to Q046, with a fingerprinting method named 'CYU' for detecting anomalous GQUIC traffic.
Azure DDoS Protection and Mitigation Services by Microsoft Azure for secure cloud solutions.
A honeytoken-based tripwire for Microsoft's Active Directory to detect privilege escalation attempts
Port listener / honeypot in Rust with protocol guessing, safe string display and rudimentary SQLite logging.
A set of Bro/Zeek scripts that detect ATT&CK-based adversarial activity and raise notices
A tool for taking a list of resolved subdomains and outputting any corresponding CNAMES en masse.
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.