feat(ics): dynamic Modbus/TCP probe for PLC/SPS devices (#148)
CI / Check (pull_request) Failing after 4m3s
CI / Detect Changes (pull_request) Has been skipped
CI / Deploy Agent (pull_request) Has been skipped
CI / Deploy Dashboard (pull_request) Has been skipped
CI / Deploy Docs (pull_request) Has been skipped
CI / Deploy MCP (pull_request) Has been skipped

Adds the first dynamic dimension to PLC/SPS targets: probe the running device
over industrial protocols, complementing the static control-logic rules.

- New ScanType::IcsProbe (+ phase), offered for PlcSps with a reachable endpoint
  (opt-in / default-off).
- pipeline::ics::modbus — a minimal, read-only Modbus/TCP client: issues Read
  Holding Registers + Read Device Identification, never writes to the live
  process. Detects an endpoint that answers unauthenticated Modbus and reads its
  device identity (vendor/product/revision).
- pipeline::ics::probe_target — emits findings: `ics-modbus-exposed` (Critical,
  CWE-306 — Modbus/TCP has no auth/encryption by protocol design) and
  `ics-device-disclosure` (Low, CWE-200). Targets the Modbus port (502) of the
  target's Live URL, independent of any WebVisu HTTP port.
- orchestrator: a PLC/SPS target runs the ICS probe when planned (alongside the
  control-logic scan and DAST).

Unit-tested against an in-process mock Modbus server + endpoint-parsing and
device-id parsing tests. Docs: new "Dynamic testing — ICS protocol probe" section.

First increment of #148 (soft-PLC + industrial-protocol probing); OPC UA /
EtherNet-IP and the OpenPLC soft-PLC harness (orca-infra) follow. Tracker #167.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Sharang Parnerkar
2026-07-16 18:05:34 +02:00
co-authored by Claude Opus 4.8
parent a3f3f1d4f5
commit 5e8250f7e9
8 changed files with 428 additions and 1 deletions
+19
View File
@@ -76,3 +76,22 @@ guard-aware), cleartext/insecure communication (CWE-319), insecure protocol port
The **SBOM** view lists the CODESYS libraries (`pkg:codesys/<name>@<version>`) and
the runtime; matching runtime components (e.g. the `Cmp*` / `3SLicense` libraries)
surface real CODESYS advisories as CVE alerts.
## Dynamic testing — ICS protocol probe
Beyond the static analysis, Certifai can **probe the running device** over
industrial protocols. Attach a **Live URL** artifact (the device host / WebVisu
URL) to the PLC/SPS target and enable the **ICS Probe** scan.
The probe is **read-only** — it never writes to the live process. It currently
speaks **Modbus/TCP** (port 502): it confirms whether the device answers
unauthenticated Modbus requests and reads its device identity (vendor / product /
revision). Because Modbus/TCP has no authentication or encryption in the protocol,
a reachable endpoint that answers is reported as an exposed control interface
(CWE-306). OPC UA and EtherNet/IP probes are planned.
::: warning
The ICS probe connects to the live device. It is **opt-in** (off by default) and
should only be run against targets you are authorized to test. It performs reads
only, never writes.
:::