SCADAsploit

COMMAND & CONTROL / INDUSTRIAL SECURITY

C2 for
Offensive OT Security.

Adversary Simulation. IT → OT pivoting. Industrial security research. A Command & Control framework built to test attack paths across converged IT and OT environments.

REMOTE COMMANDERC2.OT
SCADAsploit Remote Commander showing connected nodes and operator panels.
Actual SCADAsploit interface · Example environment
ITPIVOTOT / ICS
PRESENTED ATBlack Hat Europe ArsenalLondon · December 2023

OFFENSIVE SECURITY INDUSTRIAL BY DESIGN

01 / THE FRAMEWORK

Industrial systems.
An offensive perspective.

SCADAsploit combines IT offensive capabilities with modules designed for PLC, SCADA and other industrial systems. It supports penetration testing, Red Teaming and OT/ICS research through a distributed C2 architecture.

Follow an attack path beyond the enterprise network: identify assets, examine reachable industrial devices and test how defensive controls respond.

01 / CAPABILITY

Adversary Simulation

Emulate stages of an attack across IT and OT. Give Red and Blue Teams a concrete sequence to investigate and validate.

02 / CAPABILITY

Asset discovery

Identify industrial devices, map network relationships and collect device information to inform the assessment.

03 / CAPABILITY

IT operations

Staged and stageless beacons support operations in IT environments, providing the starting point for converged IT/OT assessments.

04 / CAPABILITY

IT → OT pivoting

Explore reachable network paths from an IT foothold toward industrial devices. Test segmentation against an actual assessment path.

05 / CAPABILITY

OT enumeration

Use industrial modules to investigate devices and vulnerabilities, with the context needed to select the next test.

06 / CAPABILITY

Industrial protocols

Protocol-aware modules support industrial research. Public examples include Modbus/TCP discovery and Schneider UMAS enumeration.

02 / FROM IT TO OT

Follow the connection.
Validate the boundary.

An illustrative assessment sequence, from an authorized IT foothold to industrial security validation. Each engagement defines its own scope, access and operational constraints.

  1. 01

    Initial access

    Establish the agreed entry point

  2. 02

    IT compromise

    Assess the enterprise foothold

  3. 03

    Beacon

    Connect the assessment agent

  4. 04

    Lateral movement

    Explore reachable systems

  5. 05

    Network pivot

    Cross the IT / OT boundary

  6. 06

    OT discovery

    Identify industrial assets

  7. 07

    Industrial target

    Test the scoped device

  8. 08

    Security validation

    Review controls and response

03 / DISTRIBUTED BY DESIGN

One framework.
Connected operations.

The Remote Commander, teamserver and beacon separate operator interaction, C2 coordination and activity in the assessed environment.

SCADAsploit / topologyLOGICAL VIEW
  1. 01 / OPERATOR INTERFACE

    Remote Commander

    Graphical client for framework operations.

  2. 02 / COORDINATION

    Teamserver

    Server-side sessions, modules and operator coordination.

  3. 03 / ASSESSED ENVIRONMENT

    Beacon / Agent

    Staged or stageless agent for remote operations.

IT

IT environment

Hosts, sessions and remote operations

IT → OT

Network pivot

OT / ICS environment

PLC · SCADA · HMI · Remote I/O

Conceptual architecture · Not a live networkLogical relationships only. Network placement and connectivity depend on the authorized assessment design.

INDUSTRIAL FOCUS

Beyond the IT endpoint.

SCADAsploit’s research focus includes major industrial ecosystems. Capabilities depend on the device, protocol and module; vendor names are not a claim of universal product coverage.

Schneider ElectricSiemensRockwell AutomationABB
  • PLC
  • SCADA
  • HMI
  • Remote I/O
  • Industrial networks
  • IIoT
PUBLICLY DOCUMENTED PROTOCOL EXAMPLES
Modbus/TCPSchneider UMAS

04 / ADVERSARY SIMULATION

Don’t assume your OT
defenses work. Test them.

SCADAsploit brings an offensive sequence into a shared technical discussion. Red Teams execute scoped tests; SOC, Blue Team and OT security teams examine what their controls observed and how they responded.

Detection & monitoring

Compare assessment activity with what defenders can observe.

Segmentation & attack paths

Evaluate whether the intended network boundaries constrain the tested path.

Response & controls

Review investigation and response to improve the next defensive iteration.

THE INTERFACE / IN CONTEXT

Real tools.
Real operator views.

Explore the publicly documented interface. These screenshots show example environments, not live sessions.

REMOTE COMMANDER

See the assessment path.

A real view of the SCADAsploit graphical commander, showing connected nodes alongside operational panels.

01 / 03
SCADAsploit / commanderPRODUCT INTERFACE
SCADAsploit Remote Commander with a network topology and operator panels.
REMOTE COMMANDER Actual interface · Example environment

SESSION VIEW

Keep operations in context.

The session interface brings host information and command output into the same operator workspace.

02 / 03
SCADAsploit / sessionsPRODUCT INTERFACE
SCADAsploit session table and remote-operation output in the graphical client.
SESSION VIEW Actual interface · Example environment

ASSET DISCOVERY

Map industrial reachability.

An example network view connects IT hosts with industrial PLC and HMI targets, alongside the listener and event panels.

03 / 03
SCADAsploit / discoveryPRODUCT INTERFACE
SCADAsploit network map connecting IT hosts with Schneider Electric PLC and HMI devices.
ASSET DISCOVERY Actual interface · Example environment

05 / WORKSHOPS

Understand the attack.
Build the defense.

Technical training grounded in industrial systems and real protocols. Learn why a vulnerability exists, reproduce its effects in a controlled setting and understand the countermeasure.

INDUSTRIAL DEFENSE2 DAYS

Advanced OT

Advanced · OT fundamentals required

Build practical knowledge of industrial cybersecurity, from information-security fundamentals to resilient architectures and incident response. Connect device protection with network design and industrial best practices.

DESIGNED FOR

Industrial system designers, PLC/SCADA programmers, network specialists and OT cybersecurity professionals.

  • Information security: attacks, risks, vulnerability identification and the human role
  • Protection of OT devices
  • Secure networks and communication protocols
Explore the workshop
SECURITY BY DESIGN2 DAYS

Secure PLC Programming

Advanced · PLC programming required

Apply cybersecurity principles to PLC application software. Design more resilient control applications and diagnose the effects of cyber incidents on PLC program execution.

DESIGNED FOR

PLC programmers, maintenance technicians, system integrators, machine builders, plant operators and automation engineers.

  • Cybersecurity requirements specific to OT applications
  • Identify cyber risks in an automation system
  • Design more resilient PLC, HMI and SCADA applications
Explore the workshop

06 / BUILT FROM INDUSTRIAL EXPERIENCE

Created by
Omar Morando.

SCADAsploit is created and developed by Omar Morando, Offensive OT Security researcher and Co-Founder & CTO of BlackFox. His background spans industrial automation, PLC/SCADA systems, embedded software and cybersecurity.

The continued development of SCADAsploit sits within Omar’s technology and research work in the BlackFox ecosystem.

Meet the creator ↗

PRODUCT / RESEARCH / TRAINING

Talk industrial
security with us.

For questions about SCADAsploit, industrial security research, authorized assessments or advanced technical training.

Product & research

Framework enquiries, research and technical collaboration.

Workshops & training

Course content, prerequisites and training enquiries.