Back to skills
SKILL.md
Ot Ics
ASecurityUse for authorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.
- 434 stars
- 0 votes
- 0 copies
- 0 views
- Added September 23, 2026
Security analysis
100/100Pro scans all 2 files and shows the line behind each finding
npx -y skills add coco-research/coco --skill ot-ics --agent claude-codeAre you the author of Ot Ics?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/coco-research-ot-ics)---
name: ot-ics
description: Use for authorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.
user-invocable: true
---
# OT / ICS Security
## 适用场景
- 工控/SCADA/DCS 安全评估(授权)
- Purdue 模型分区与跨区通道
- Modbus/DNP3/S7/EtherNet/IP 等协议暴露
- 工程师站、HMI、历史库、跳板主机
- IT/OT 融合边界(防火墙规则、单向闸)
## 安全铁律(MUST)
```text
MUST NOT 在未明确允许时:
- 对 PLC 写线圈/寄存器
- 全网高速率扫描生产 OT
- 中断安全仪表系统(SIS)相关路径
优先:只读识别、流量镜像、离线固件/配置分析
```
## 工作流
### Phase 1 — 分区与资产
```text
□ Purdue L0–L5 草图:现场设备 → 控制 → 监督 → 站点 DMZ → 企业
□ 资产清单:PLC/RTU/HMI/工程师站/历史库/Jump host
□ 协议与端口基线(仅授权网段)
```
### Phase 2 — 被动与只读
```text
□ SPAN/镜像 PCAP → protocol-reverse / Wireshark 工控解析器
□ 配置与工程文件离线审计(TIA/RSLogix 导出等)
□ 默认口令与明文协议(Modbus 无认证)记录为 Finding,不写盘改值
```
### Phase 3 — 受限主动(仅授权)
```text
□ 低速识别,维护窗口
□ 只读功能码优先
□ 每步 Evidence;异常立即停止并通报
```
### Phase 4 — 固件/补丁面
```text
□ 控制器固件版本 → CVE 映射(不盲刷固件)
□ 联合 firmware-pentest 做离线镜像分析
```
## 工具链
| 工具 | 用途 | 注意 |
|------|------|------|
| Wireshark 工控 dissectors | 被动解析 | 镜像流量 |
| Nmap NSE(受限) | 识别 | 速率与时间窗 |
| Claroty/Nozomi 等 | 资产发现 | 商业/现场 |
| PLC 厂商工程软件 | 配置审计 | 离线优先 |
| binwalk / Ghidra | 固件 | 离线 |
## 参考
- `references/ot-safe-assessment.md`
- `../firmware-pentest/` `../protocol-reverse/` `../network` via pentest-tools
Files in this skill
- SKILL.md
- references/ot-safe-assessment.md
Attribution
Comments
Loading comments…