SCADAsploit

FRAMEWORK / CAPABILITIES

Offensive capability.
Industrial context.

SCADAsploit combines IT offensive capabilities with modules designed for PLC, SCADA and other industrial systems. It supports penetration testing, Red Teaming and OT/ICS research through a distributed C2 architecture.

Explore the architecture ↗
01 / CAPABILITY

Adversary Simulation

Emulate stages of an attack across IT and OT. Give Red and Blue Teams a concrete sequence to investigate and validate.

02 / CAPABILITY

Asset discovery

Identify industrial devices, map network relationships and collect device information to inform the assessment.

03 / CAPABILITY

IT operations

Staged and stageless beacons support operations in IT environments, providing the starting point for converged IT/OT assessments.

04 / CAPABILITY

IT → OT pivoting

Explore reachable network paths from an IT foothold toward industrial devices. Test segmentation against an actual assessment path.

05 / CAPABILITY

OT enumeration

Use industrial modules to investigate devices and vulnerabilities, with the context needed to select the next test.

06 / CAPABILITY

Industrial protocols

Protocol-aware modules support industrial research. Public examples include Modbus/TCP discovery and Schneider UMAS enumeration.

07 / CAPABILITY

Pre & post-exploitation

Auxiliary, exploitation and remote-command modules support different phases of a controlled assessment.

08 / CAPABILITY

Remote operations

A graphical Remote Commander connects to a teamserver. Manage sessions and coordinate work through a distributed client/server architecture.

09 / CAPABILITY

Security validation

Use offensive observations to evaluate monitoring, detection, response and segmentation with the teams responsible for industrial defense.

TECHNICAL OVERVIEW

The documented building blocks.

A concise view of the existing architecture, remote operations and industrial modules.

Distributed C2 & remote client

The client/server design separates the graphical Remote Commander from the teamserver. The published architecture supports collaboration between operators and remote control of framework functions.

Documented connection options include WireGuard and Blu5 SElink. Connection design and deployment remain specific to the assessment environment.

Beacon & payload options

The documented beacon supports staged and stageless operation, with Windows executable, DLL and shellcode output formats. The framework includes payload handling and module upload capabilities.

Public documentation describes obfuscation, anti-debugging and anti-sandboxing options, plus WinAPI, NTAPI and indirect system-call approaches. These are technical capabilities, not a guarantee of bypassing defensive controls.

Pivoting & remote access

Published transport and pivot options include SMB and TCP, with WMI, WinRM and RPC-based remote operations. The remote client provides command execution, shell access and file-transfer functions.

The documented external C2 design allows custom communication channels. This overview describes the architecture without providing an operational deployment procedure.

Discovery, mapping & modules

Asset inventory and network views bring discovered targets into the operator workflow. Auxiliary and exploitation modules support vulnerability investigation in SCADA, PLC and IIoT environments.

Public discovery examples include collecting device and firmware information over Modbus/TCP, with additional Schneider Modicon information through UMAS. Scope and device behavior determine which checks are appropriate.

INDUSTRIAL FOCUS

Beyond the IT endpoint.

SCADAsploit’s research focus includes major industrial ecosystems. Capabilities depend on the device, protocol and module; vendor names are not a claim of universal product coverage.

Schneider ElectricSiemensRockwell AutomationABB
PUBLICLY DOCUMENTED PROTOCOL EXAMPLES
Modbus/TCPSchneider UMAS

04 / ADVERSARY SIMULATION

Don’t assume your OT
defenses work. Test them.

SCADAsploit brings an offensive sequence into a shared technical discussion. Red Teams execute scoped tests; SOC, Blue Team and OT security teams examine what their controls observed and how they responded.

Detection & monitoring

Compare assessment activity with what defenders can observe.

Segmentation & attack paths

Evaluate whether the intended network boundaries constrain the tested path.

Response & controls

Review investigation and response to improve the next defensive iteration.

REMOTE CLIENT / ACTUAL INTERFACE

Operations in one workspace.

The session interface brings host information and command output into the same operator workspace.

SCADAsploit / sessionsPRODUCT INTERFACE
SCADAsploit session table and remote-operation output in the graphical client.
SESSION VIEW Actual interface · Example environment