Adversary Simulation
Emulate stages of an attack across IT and OT. Give Red and Blue Teams a concrete sequence to investigate and validate.
FRAMEWORK / CAPABILITIES
SCADAsploit combines IT offensive capabilities with modules designed for PLC, SCADA and other industrial systems. It supports penetration testing, Red Teaming and OT/ICS research through a distributed C2 architecture.
Explore the architecture ↗Emulate stages of an attack across IT and OT. Give Red and Blue Teams a concrete sequence to investigate and validate.
Identify industrial devices, map network relationships and collect device information to inform the assessment.
Staged and stageless beacons support operations in IT environments, providing the starting point for converged IT/OT assessments.
Explore reachable network paths from an IT foothold toward industrial devices. Test segmentation against an actual assessment path.
Use industrial modules to investigate devices and vulnerabilities, with the context needed to select the next test.
Protocol-aware modules support industrial research. Public examples include Modbus/TCP discovery and Schneider UMAS enumeration.
Auxiliary, exploitation and remote-command modules support different phases of a controlled assessment.
A graphical Remote Commander connects to a teamserver. Manage sessions and coordinate work through a distributed client/server architecture.
Use offensive observations to evaluate monitoring, detection, response and segmentation with the teams responsible for industrial defense.
TECHNICAL OVERVIEW
A concise view of the existing architecture, remote operations and industrial modules.
The client/server design separates the graphical Remote Commander from the teamserver. The published architecture supports collaboration between operators and remote control of framework functions.
Documented connection options include WireGuard and Blu5 SElink. Connection design and deployment remain specific to the assessment environment.
The documented beacon supports staged and stageless operation, with Windows executable, DLL and shellcode output formats. The framework includes payload handling and module upload capabilities.
Public documentation describes obfuscation, anti-debugging and anti-sandboxing options, plus WinAPI, NTAPI and indirect system-call approaches. These are technical capabilities, not a guarantee of bypassing defensive controls.
Published transport and pivot options include SMB and TCP, with WMI, WinRM and RPC-based remote operations. The remote client provides command execution, shell access and file-transfer functions.
The documented external C2 design allows custom communication channels. This overview describes the architecture without providing an operational deployment procedure.
Asset inventory and network views bring discovered targets into the operator workflow. Auxiliary and exploitation modules support vulnerability investigation in SCADA, PLC and IIoT environments.
Public discovery examples include collecting device and firmware information over Modbus/TCP, with additional Schneider Modicon information through UMAS. Scope and device behavior determine which checks are appropriate.
INDUSTRIAL FOCUS
SCADAsploit’s research focus includes major industrial ecosystems. Capabilities depend on the device, protocol and module; vendor names are not a claim of universal product coverage.
04 / ADVERSARY SIMULATION
SCADAsploit brings an offensive sequence into a shared technical discussion. Red Teams execute scoped tests; SOC, Blue Team and OT security teams examine what their controls observed and how they responded.
Compare assessment activity with what defenders can observe.
Evaluate whether the intended network boundaries constrain the tested path.
Review investigation and response to improve the next defensive iteration.
REMOTE CLIENT / ACTUAL INTERFACE
The session interface brings host information and command output into the same operator workspace.
