Redpoint Logo

Redpoint

0
Free
Visit Website

Redpoint is a Digital Bond research project to enumerate ICS applications and devices. We use our Redpoint tools in assessments to discover ICS devices and pull information that would be helpful in secondary testing. A portion of those tools will be made available as Nmap NSE scripts to the public in this repository. The Redpoint tools use legitimate protocol or application commands to discover and enumerate devices and applications. There is no effort to exploit or crash anything. However many ICS devices and applications are fragile and can crash or respond in an unexpected way to any unexpected traffic so use with care. Each script is documented below and available in a .nse file in this repository. BACnet-discover-enumerate.nse - Identify and enumerate BACnet devices codesys-v2-discover.nse - Identify and enumerate CoDeSys V2 controllers enip-enumerate.nse - Identify and enumerate EtherNet/IP devices from Rockwell Automation and other vendors fox-info.nse - Identify and enumerate Niagara Fox devices modicon-info.nse - Identify and enumerate Schneider Electric Modicon PLCs omron-info.nse - Identify and enumerate Omron PLCs pcworx

FEATURES

ALTERNATIVES

Stenographer is a high-performance full-packet-capture utility for intrusion detection and incident response purposes.

A powerful command-line packet analyzer and a portable C/C++ library for network traffic capture with comprehensive documentation.

Zeek Remote desktop fingerprinting script for fingerprinting Remote Desktop clients.

Smart traffic sniffing tool for penetration testers

CrowdSec is a behavior detection engine with a global IP reputation network.

A tool for scanning networks, enumerating Siemens PLCs, and gathering detailed information about them.

A free, open-source network protocol analyzer for capturing and displaying packet-level data.

A collection of PCAPs for ICS/SCADA utilities and protocols with the option for users to contribute.