Skip to content

Industrial protocols (Modbus)

Industrial protocols (Modbus, DNP3, S7, EtherNet/IP, Profinet) were designed decades ago for isolated, trusted networks: most have no authentication or encryption. Understanding this explains why access to the OT network is so critical: whoever reaches the network can often read and write the process directly.

- designed for ISOLATED, trusted networks -> no auth, no encryption, no integrity
- anyone with network access can read values and SEND commands to a PLC
- "security" was physical isolation (air gap), today eroded by IT/OT convergence
Modbus TCP port 502; function codes to read/write registers and coils
FC 01/02 read coils / discrete inputs
FC 03/04 read holding / input registers
FC 05/06 write a coil / register (a command to the process!)
FC 15/16 write multiple
# no authentication: a write FC from the network changes the physical state
DNP3 utilities (energy/water); with optional Secure Authentication (rarely deployed)
S7comm Siemens S7 PLCs (Stuxnet abused it)
EtherNet/IP CIP (Rockwell/Allen-Bradley), port 44818
Profinet automation (Siemens)
BACnet/Modbus buildings (BMS)
# nmap NSE and specific scripts enumerate versions/registers -> ONLY in a lab
- discover devices and supported function codes (passive tools preferred)
- reading registers reveals the process state; writing MANIPULATES it
- an aggressive active scan can HANG a fragile PLC -> prefer passive capture
- Shodan/Censys show thousands of ICS devices exposed on the Internet (don't touch)
Enumeration nmap (modbus/s7/enip scripts), modbus-cli, pymodbus (prototype)
Analysis Wireshark (Modbus/DNP3/S7 dissectors), passive capture
Monitoring Nozomi/Claroty/Dragos (per protocol, without touching the device)
  • Since the protocols don’t authenticate, the defense is network-based: Purdue segmentation and controlling who talks to the PLCs (SCADA / ICS).
  • Allowlisting of authorized peers (only the HMI/historian talks to the PLC), not anyone.
  • Passive monitoring alerting on unexpected write function codes or new peers.
  • Where available, enable the secure variants (DNP3-SA, OPC UA with security); never expose :502 to the Internet.
  • Stuxnet manipulated S7comm to reprogram PLCs without the HMI noticing.
  • Thousands of Modbus/BACnet devices exposed on the Internet (Shodan) with no authentication.
  • Industroyer speaks electric protocols (IEC 60870-5-104, IEC 61850) to operate breakers.
  • Identify protocols in use (Modbus/DNP3/S7/EtherNet-IP)
  • Passive capture to map peers and function codes (avoid active scanning in prod)
  • Verify no ICS ports (502, 44818…) exposed to the Internet
  • Allowlisting: only authorized peers talk to the PLCs
  • Passive monitoring of unexpected writes/commands
  • Enable secure protocol variants where they exist
  • Tests only in a lab/authorized window