Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.5 KiB

SCADA HMI Security Assessment - API Reference

SCADA Protocol Ports

Port Protocol Description
102 S7comm Siemens S7 PLC communication
502 Modbus TCP Industrial automation protocol
2222 EtherNet/IP Allen-Bradley, Rockwell
4840 OPC UA Open Platform Communications Unified Architecture
20000 DNP3 Distributed Network Protocol
47808 BACnet Building Automation and Control

Port Scanning (socket stdlib)

import socket
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock.settimeout(2.0)
result = sock.connect_ex((target, port))  # 0 = open
sock.close()

pyshark for Protocol Analysis

import pyshark
cap = pyshark.FileCapture("traffic.pcap")
for pkt in cap:
    for layer in pkt.layers:
        print(layer.layer_name)  # modbus, s7comm, dnp3, etc.
cap.close()

Insecure SCADA Protocols

These protocols lack built-in encryption and authentication:

  • Modbus TCP - No auth, no encryption, commands in plaintext
  • S7comm - No auth (pre-V4), no encryption
  • DNP3 - Optional Secure Authentication (SA), rarely deployed
  • BACnet - No native security mechanisms
  • EtherNet/IP - No encryption, device enumeration possible

HMI Configuration Checks

Check Severity Description
Authentication disabled Critical HMI allows anonymous access
No session timeout High Sessions persist indefinitely
TLS disabled High Communications in plaintext
Remote access without VPN Critical HMI exposed without tunnel
No RBAC High Single role or no access control
Default credentials Critical Factory-default username/password

Common Default Credentials

Username Password Platform
admin admin Generic HMI
admin 1234 Siemens WinCC
operator operator Wonderware
engineer engineer GE iFIX
guest guest Various

ICS Security Standards

  • IEC 62443 - Industrial communication network security
  • NIST SP 800-82 - Guide to ICS Security
  • NERC CIP - Critical Infrastructure Protection (power grid)

Output Schema

{
  "report": "scada_hmi_security_assessment",
  "target": "192.168.1.100",
  "total_findings": 6,
  "severity_summary": {"critical": 2, "high": 3, "medium": 1},
  "findings": [{"type": "open_scada_port", "severity": "high"}]
}

CLI Usage

python agent.py --target 192.168.1.100 --pcap traffic.pcap --config hmi.json --output report.json