Redpoint Logo

Redpoint

0
Free
Visit Website

Redpoint is a Digital Bond research project to enumerate ICS applications and devices. We use our Redpoint tools in assessments to discover ICS devices and pull information that would be helpful in secondary testing. A portion of those tools will be made available as Nmap NSE scripts to the public in this repository. The Redpoint tools use legitimate protocol or application commands to discover and enumerate devices and applications. There is no effort to exploit or crash anything. However many ICS devices and applications are fragile and can crash or respond in an unexpected way to any unexpected traffic so use with care. Each script is documented below and available in a .nse file in this repository. BACnet-discover-enumerate.nse - Identify and enumerate BACnet devices codesys-v2-discover.nse - Identify and enumerate CoDeSys V2 controllers enip-enumerate.nse - Identify and enumerate EtherNet/IP devices from Rockwell Automation and other vendors fox-info.nse - Identify and enumerate Niagara Fox devices modicon-info.nse - Identify and enumerate Schneider Electric Modicon PLCs omron-info.nse - Identify and enumerate Omron PLCs pcworx

FEATURES

ALTERNATIVES

Normalize, index, enrich, and visualize network capture data using Potiron.

LogRhythm NetMon is a network traffic analytics tool that provides real-time visibility, automated threat detection, and investigation capabilities for organizational networks.

Provides AI-driven cybersecurity solutions including assessments, training, compliance services, and insurance audits to help organizations reduce risk and build a security-aware culture.

A powerful directory/file, DNS and VHost busting tool written in Go.

Automated signature creation using honeypots for network intrusion detection systems.

A free open-source security tool for macOS to detect unauthorized physical access.

Exploiting simple stack overflow vulnerabilities using return oriented programming (ROP) to defeat data execution prevention - DEP.

An analyzer for parsing GQUIC traffic in Zeek, supporting versions Q039 to Q046, with a fingerprinting method named 'CYU' for detecting anomalous GQUIC traffic.