Atomic Red Team
Library tes ATT&CK termasuk teknik OT-relevant.
Asset discovery, IDS/IPS, SIEM, EDR, forensics, threat intel, pentest, SBOM — lengkap dengan link official, deployment model, dan protokol industrial yang didukung.
Library tes ATT&CK termasuk teknik OT-relevant.
Adversary emulation platform dengan plugin Caldera for OT.
Plugin Caldera khusus protokol OT (Modbus, BACnet, DNP3, Profinet).
Cloud-focused adversary emulation.
Visibility OT, threat detection & vulnerability management khusus ICS.
CPS Protection Platform dengan asset discovery, risk & vulnerability management.
Continuous Threat Detection on-prem untuk OT/ICS.
Passive OT/IoT discovery dengan anomaly detection & vulnerability assessment.
SaaS visibility multi-site OT/IoT.
Agentless asset intelligence IT/OT/IoT/IoMT.
OT network monitoring (formerly SilentDefense) untuk discovery & threat detection.
Agentless network detection untuk OT/IoT (eks-CyberX) terintegrasi Sentinel.
Passive network mapping untuk ICS (PCAP-based).
PLC discovery scanner Siemens S7 & Modbus TCP.
NSE scripts untuk Modbus, S7, EtherNet/IP, BACnet, DNP3, IEC-104.
Active+passive asset inventory dengan OT-safe scanning.
Search engine internet-exposed device termasuk ICS protocol fingerprints.
Internet-wide scanning & attack surface management.
OT network visibility & threat detection.
OT systems management & vulnerability orchestration.
Backup enterprise dengan immutable repository.
Backup + ransomware recovery.
Encrypted, deduplicated backup CLI.
Dedup backup dengan kompresi.
Generic SIEM rule format dengan ICS rule set.
Web tool mapping TTPs & detection coverage termasuk ATT&CK for ICS.
Score & compare detection coverage vs ATT&CK.
Diagramming gratis dengan shape ICS.
Cloud diagramming kolaboratif.
Diagramming klasik dengan stencils Allen-Bradley & Siemens.
Cloud-native EDR/XDR dengan modul Insight for OT.
Autonomous EDR/XDR dengan Singularity for IoT.
XDR terintegrasi Defender for Endpoint/Identity/IoT.
Endpoint visibility via SQL queries.
Remote live forensics framework untuk endpoint.
Endpoint visibility, forensics & threat hunting via VQL.
Memory forensics framework.
Digital forensics GUI di atas The Sleuth Kit.
Library & tools analisis disk image.
Kroll Artifact Parser and Extractor untuk triage cepat.
Super timeline forensic engine.
Pattern matching swiss-army knife untuk malware.
Automation & hardening playbooks (CIS Benchmarks).
Security compliance scanning (SCAP/STIG/CIS).
CIS Benchmarks assessor tool.
Linux/Unix security auditing tool.
Identity & SSO (OIDC/SAML) open source.
Network security monitor dengan ICS protocol parser via ICSNPP.
Zeek package: Industrial Control Systems Network Protocol Parsers.
IDS/IPS engine dengan ruleset ICS (Modbus, DNP3, S7).
High-performance IDS/IPS/NSM dengan Modbus, DNP3, ENIP keywords.
Collaborative case management untuk SOC/CSIRT.
Observable analyzer & responder companion TheHive.
SOAR open source modular.
No-code automation & SOAR.
Enterprise SOAR (formerly Demisto).
Network protocol analyzer dengan banyak dissector industrial (Modbus, S7, DNP3, IEC-61850).
CLI packet capture portable & ringan.
High-speed traffic analysis & flow collection.
Large-scale full packet capture & indexed search.
Network traffic analysis suite untuk ICS (Arkime + Zeek + Suricata).
Distro NSM & log management (Zeek+Suricata+Elastic+TheHive).
Suricata + Elastic + Kibana + Scirius live distro.
OT visibility + industrial firewall.
Industrial NGFW dengan OT protocol DPI.
NGFW dengan App-ID untuk protokol industri.
Industrial firewall rugged dengan DPI Modbus & DNP3.
Industrial security appliance plug-and-protect.
Firewall open source berbasis FreeBSD.
Fork pfSense dengan UI modern.
Hardware data diode untuk replikasi historian satu arah.
Cross-domain & data diode untuk CI.
Certified data diode untuk pemerintahan & utilitas.
Privileged access management enterprise dengan modul OT.
Privileged Remote Access untuk vendor & internal.
Exploitation framework dengan modul SCADA.
Metasploit-like framework khusus ICS exploits.
Framework eksploitasi ICS multi-vendor.
Tools injection ladder logic ke Siemens S7-300/400.
CLI sederhana untuk read/write register Modbus.
Modular Modbus penetration testing framework.
Distro pentest dengan banyak tools default.
Adversary simulation & red team platform.
Open source cross-platform C2.
AD attack path analysis untuk pivot ke OT.
Secure Remote Access khusus OT (eks-Secure Remote Access).
Zero-trust access broker untuk OT/IoT.
User-to-asset access controlled untuk CI.
Clientless remote desktop gateway (RDP/VNC/SSH).
Identity-aware access proxy SSH/K8s/DB/Apps.
Modern fast VPN protocol.
VPN klasik proven enterprise.
Mesh VPN berbasis WireGuard.
ICS honeypot Modbus/S7/IEC-104/BACnet/HTTP.
Multi-honeypot platform termasuk Conpot.
SSH/Telnet honeypot untuk attacker profiling.
Deception assets fisik & virtual.
OT risk assessment & management automation.
Risk assessment automation berbasis ISA/IEC 62443.
Cyber Security Evaluation Tool dengan modul NIST CSF, 62443, NEI.
Structured Assessment For Engineering Toolkit dari Idaho National Lab.
OT Cybersecurity Maturity Model assessment.
SBOM standard & tooling.
SBOM standard ISO/IEC 5962.
Generate SBOM dari container & filesystem.
Vulnerability scanner SBOM/image.
All-in-one security scanner container/IaC/SBOM.
Continuous component & vulnerability analysis.
OPC UA SDK C99 untuk riset & integration.
Library Python Modbus client/server.
S7 communication library multi-bahasa.
IEC 61850 & 60870-5 client/server library.
Reference implementation OPC UA .NET.
Secrets, certificates, encryption-as-a-service.
SIEM enterprise dengan Add-on Industrial Asset Intelligence.
SIEM gratis dengan ICS detection rules & integrations.
SIEM/XDR open source dengan rule pack OT.
Log management dengan threat detection bawaan.
SIEM enterprise dengan QRadar OT/ICS content.
Cloud-native SIEM/SOAR di Azure dengan Defender for IoT connector.
Cloud-native SIEM dengan kapasitas petabyte.
Threat intelligence sharing platform dengan taxonomies ICS.
Knowledge graph CTI dengan konektor MITRE ATT&CK ICS.
Your Everyday Threat Intelligence platform.
Real-time threat intelligence & risk scoring.
Threat intel & breach analytics dengan modul OT.
ICS-specific threat intelligence subscription.
Known Exploited Vulnerabilities catalog (gratis & dapat di-feed).
Open Threat Exchange community pulses.
Cyber range simulator dengan skenario OT/SCADA.
Hands-on challenge berbasis ICS.
Komunitas + lab gratis untuk belajar OT.
DOT-based graph rendering untuk arsitektur.
Vulnerability scanning aktif/pasif untuk OT (eks-Indegy).
VM enterprise dengan policy compliance.
Cloud-based vulnerability management & detection.
Vulnerability scanner open source dengan feed harian.
Vulnerability scanner deep dengan ICS plugins.
Wireless detector & sniffer 802.11/BLE/Zigbee.
Suite WPA/WEP audit.
SDR framework untuk analisis sinyal radio industri.
Hardware SDR 1 MHz–6 GHz.