Some nmap scripts to detetct the infomations of the different ICS
Here are 16 main ics protocal scan-scripts include Modbus, S7 and so on.
- s7-enumerate.nse Simatic S7 102
- modicon-info.nse Schneider Electric Modicon(Modbus) 502
- cr3-fingerprint.nse Crimson V3 789
- codesys-v2-discover.nse 3S-Smart Software 1200 or 2455
- fox-info.nse Niagara Fox 1911
- pcworx-info.nse Pcworx 1962
- cspv4-info.nse CSPV4 on AB PLC5 systems 2222
- iec-identify.nse IEC 60870-5-104 2404
- melsecq-discover.ns MELSEC-Q 5007
- omronudp-info.nse Omron 9600
- atg-info.nse Guardian AST Automatic Tank Gauge 10001
- dnp3-info.nse DNP3 20000
- procoos-info.nse ProConOs 20547
- enip-enumerate.nse Rockwell Automation EtherNet/IP 44818
- BACnet-discover-enumerate.nse BACnet 47808
- melsecq-discover-udp.nse MELSEC-Q(UDP) 5007
- modbus-discover.nse Modbus 502