Loading...
Loading...
Compare original and translation side by side
NOW../field-journal/precedent-pentest.mdNOWNOWready_for_actNEXTACTNOW../field-journal/precedent-pentest.mdNOWNOWready_for_actNEXTACTMUST NOT 在未明确允许时:
- 对 PLC 写线圈/寄存器
- 全网高速率扫描生产 OT
- 中断安全仪表系统(SIS)相关路径
优先:只读识别、流量镜像、离线固件/配置分析MUST NOT perform the following without explicit permission:
- Write coils/registers to PLCs
- High-rate scanning of the entire production OT network
- Interrupt paths related to Safety Instrumented Systems (SIS)
Prioritize: read-only identification, traffic mirroring, offline firmware/configuration analysis□ Purdue L0–L5 草图:现场设备 → 控制 → 监督 → 站点 DMZ → 企业
□ 资产清单:PLC/RTU/HMI/工程师站/历史库/Jump host
□ 协议与端口基线(仅授权网段)□ Sketch of Purdue L0–L5: Field devices → Control → Supervision → Site DMZ → Enterprise
□ Asset inventory: PLC/RTU/HMI/Engineer workstations/Historical databases/Jump hosts
□ Protocol and port baseline (authorized network segments only)□ SPAN/镜像 PCAP → protocol-reverse / Wireshark 工控解析器
□ 配置与工程文件离线审计(TIA/RSLogix 导出等)
□ 默认口令与明文协议(Modbus 无认证)记录为 Finding,不写盘改值□ SPAN/mirrored PCAP → protocol-reverse / Wireshark industrial control dissectors
□ Offline audit of configuration and engineering files (e.g., exports from TIA/RSLogix)
□ Record default passwords and plaintext protocols (e.g., unauthenticated Modbus) as Findings; do not write or modify values□ 低速识别,维护窗口
□ 只读功能码优先
□ 每步 Evidence;异常立即停止并通报□ Low-speed identification, maintenance window only
□ Prioritize read-only function codes
□ Document evidence for each step; stop immediately and report any anomalies□ 控制器固件版本 → CVE 映射(不盲刷固件)
□ 联合 firmware-pentest 做离线镜像分析□ Controller firmware version → CVE mapping (do not blindly flash firmware)
□ Conduct offline image analysis in conjunction with firmware-pentest| 工具 | 用途 | 注意 |
|---|---|---|
| Wireshark 工控 dissectors | 被动解析 | 镜像流量 |
| Nmap NSE(受限) | 识别 | 速率与时间窗 |
| Claroty/Nozomi 等 | 资产发现 | 商业/现场 |
| PLC 厂商工程软件 | 配置审计 | 离线优先 |
| binwalk / Ghidra | 固件 | 离线 |
| Tool | Purpose | Notes |
|---|---|---|
| Wireshark industrial control dissectors | Passive parsing | Mirrored traffic only |
| Nmap NSE (restricted) | Identification | Rate and time window restrictions |
| Claroty/Nozomi, etc. | Asset discovery | Commercial/on-site tools |
| PLC vendor engineering software | Configuration audit | Prioritize offline use |
| binwalk / Ghidra | Firmware analysis | Offline only |
references/ot-safe-assessment.md../firmware-pentest/../protocol-reverse/../networkreferences/ot-safe-assessment.md../firmware-pentest/../protocol-reverse/../networkfirmware-pentestprotocol-reversewindows-adattack-chainfirmware-pentestprotocol-reversewindows-adattack-chain