Github脚本:
1. https://github.com/atimorin/scada-tools
2. https://github.com/atimorin/PoC2013
3. https://github.com/drainware/nmap-scada
Exploit-db脚本:
1. https://www.exploit-db.com/exploits/19833/
2. https://www.exploit-db.com/exploits/19831/
其它:
1.modbus-discover.nse
(Modbus TCP设备发现脚本,该脚本可以调用Modbus 43(2B功能码)功能码读取设备信息)
2.modbus-enum.nse
(Modbus TCP设备枚举脚本)
3.s7-enumerate.nse
(西门子S7 PLC设备发现脚本,可以枚举PLC的一些基本信息)
4.enip-enumerate.nse
(可以读取EtherNet/IP设备的基本信息)
5.BACnet-discover-enumerate.nse
(可以读取BACnet设备的基本信息)
6.iec-identify.nse
(IEC104协议asdu address枚举脚本)
7.mms-identify.nse
(IEC-61850-8-1协议信息枚举脚本)
8.Siemens-CommunicationsProcessor.nse
9.Siemens-HMI-miniweb.nse
10.Siemens-SIMATIC-PLC-S7.nse
11.Siemens-Scalance-module.nse
12.Siemens-WINCC.nse