CI compiles the test build with RUSTFLAGS=-D warnings; the two explicit
tokio::io trait imports in the modbus test module were redundant with
`use super::*` and failed the "Main Tests" step as unused imports.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Adds the first dynamic dimension to PLC/SPS targets: probe the running device
over industrial protocols, complementing the static control-logic rules.
- New ScanType::IcsProbe (+ phase), offered for PlcSps with a reachable endpoint
(opt-in / default-off).
- pipeline::ics::modbus — a minimal, read-only Modbus/TCP client: issues Read
Holding Registers + Read Device Identification, never writes to the live
process. Detects an endpoint that answers unauthenticated Modbus and reads its
device identity (vendor/product/revision).
- pipeline::ics::probe_target — emits findings: `ics-modbus-exposed` (Critical,
CWE-306 — Modbus/TCP has no auth/encryption by protocol design) and
`ics-device-disclosure` (Low, CWE-200). Targets the Modbus port (502) of the
target's Live URL, independent of any WebVisu HTTP port.
- orchestrator: a PLC/SPS target runs the ICS probe when planned (alongside the
control-logic scan and DAST).
Unit-tested against an in-process mock Modbus server + endpoint-parsing and
device-id parsing tests. Docs: new "Dynamic testing — ICS protocol probe" section.
First increment of #148 (soft-PLC + industrial-protocol probing); OPC UA /
EtherNet-IP and the OpenPLC soft-PLC harness (orca-infra) follow. Tracker #167.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>