Adds the first dynamic dimension to PLC/SPS targets: probe the running device
over industrial protocols, complementing the static control-logic rules.
- New ScanType::IcsProbe (+ phase), offered for PlcSps with a reachable endpoint
(opt-in / default-off).
- pipeline::ics::modbus — a minimal, read-only Modbus/TCP client: issues Read
Holding Registers + Read Device Identification, never writes to the live
process. Detects an endpoint that answers unauthenticated Modbus and reads its
device identity (vendor/product/revision).
- pipeline::ics::probe_target — emits findings: `ics-modbus-exposed` (Critical,
CWE-306 — Modbus/TCP has no auth/encryption by protocol design) and
`ics-device-disclosure` (Low, CWE-200). Targets the Modbus port (502) of the
target's Live URL, independent of any WebVisu HTTP port.
- orchestrator: a PLC/SPS target runs the ICS probe when planned (alongside the
control-logic scan and DAST).
Unit-tested against an in-process mock Modbus server + endpoint-parsing and
device-id parsing tests. Docs: new "Dynamic testing — ICS protocol probe" section.
First increment of #148 (soft-PLC + industrial-protocol probing); OPC UA /
EtherNet-IP and the OpenPLC soft-PLC harness (orca-infra) follow. Tracker #167.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
New `compliance-mcp` crate providing a Model Context Protocol server
with 7 tools: list/get/summarize findings, list SBOM packages, SBOM
vulnerability report, list DAST findings, and DAST scan summary.
Supports stdio (local dev) and Streamable HTTP (deployment via MCP_PORT).
Includes Dockerfile, CI clippy check, and Coolify deploy job.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Sharang Parnerkar <parnerkarsharang@gmail.com>
Reviewed-on: #5