Github腳本:
1. https://github.com/atimorin/scada-tools
2. https://github.com/atimorin/PoC2013
3. https://github.com/drainware/nmap-scada
Exploit-db腳本:
1. https://www.exploit-db.com/exploits/19833/
2. https://www.exploit-db.com/exploits/19831/
其它:
1.modbus-discover.nse
(Modbus TCP裝置發現腳本,該腳本可以調用Modbus 43(2B功能碼)功能碼讀取裝置資訊)
2.modbus-enum.nse
(Modbus TCP裝置枚舉腳本)
3.s7-enumerate.nse
(西門子S7 PLC裝置發現腳本,可以枚舉PLC的一些基本資訊)
4.enip-enumerate.nse
(可以讀取EtherNet/IP裝置的基本資訊)
5.BACnet-discover-enumerate.nse
(可以讀取BACnet裝置的基本資訊)
6.iec-identify.nse
(IEC104協定asdu address枚舉腳本)
7.mms-identify.nse
(IEC-61850-8-1協定資訊枚舉腳本)
8.Siemens-CommunicationsProcessor.nse
9.Siemens-HMI-miniweb.nse
10.Siemens-SIMATIC-PLC-S7.nse
11.Siemens-Scalance-module.nse
12.Siemens-WINCC.nse