Use for authorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.
75
92%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
NOW: 读取 ../field-journal/precedent-pentest.md — 工控环境误操作可致物理危害NOW: 书面授权必须写清:站点、网段、是否允许主动扫描/写寄存器NOW: case-init;默认 passive-first;ready_for_act 前禁止对 PLC 写操作NEXT: tool-index;多数工控工具需手动与隔离实验网ACT: 资产与分区识别 → 暴露面 → 只读验证MUST NOT 在未明确允许时:
- 对 PLC 写线圈/寄存器
- 全网高速率扫描生产 OT
- 中断安全仪表系统(SIS)相关路径
优先:只读识别、流量镜像、离线固件/配置分析□ Purdue L0–L5 草图:现场设备 → 控制 → 监督 → 站点 DMZ → 企业
□ 资产清单:PLC/RTU/HMI/工程师站/历史库/Jump host
□ 协议与端口基线(仅授权网段)□ SPAN/镜像 PCAP → protocol-reverse / Wireshark 工控解析器
□ 配置与工程文件离线审计(TIA/RSLogix 导出等)
□ 默认口令与明文协议(Modbus 无认证)记录为 Finding,不写盘改值□ 低速识别,维护窗口
□ 只读功能码优先
□ 每步 Evidence;异常立即停止并通报□ 控制器固件版本 → CVE 映射(不盲刷固件)
□ 联合 firmware-pentest 做离线镜像分析| 工具 | 用途 | 注意 |
|---|---|---|
| Wireshark 工控 dissectors | 被动解析 | 镜像流量 |
| Nmap NSE(受限) | 识别 | 速率与时间窗 |
| Claroty/Nozomi 等 | 资产发现 | 商业/现场 |
| PLC 厂商工程软件 | 配置审计 | 离线优先 |
| binwalk / Ghidra | 固件 | 离线 |
references/ot-safe-assessment.md../firmware-pentest/ ../protocol-reverse/ ../network via pentest-tools上游: MASTER R28
下游: 固件深挖 firmware-pentest;协议 protocol-reverse;IT 横向 windows-ad/attack-chain
同级: 不要用普通 Web 扫默认参数打 OT
6aa1362
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.