You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
André Henrique edited this page Jun 30, 2026
·
3 revisions
Complete Module Catalog
This document provides a comprehensive catalog of all 1190+ modules in IndustrialXPL-Forge, organized by category. Use this as the definitive reference for understanding what modules exist and how to use them.
Introduction
IndustrialXPL-Forge (IXF) modules are Python classes that implement the BaseExploit interface. Each module declares:
# By vendor name
ixf search siemens
# By CVE ID
ixf search CVE-2021-22681
# By protocol
ixf search modbus
# By impact level
ixf search CRITICAL
# By module category
ixf search default_creds
# By exploit type
ixf search dos
# By MITRE technique
ixf search T0836
# By product name
ixf search controllogix
# By technology keyword
ixf search firmware
# By year
ixf search 2024
CVE Modules — All 150+ Vendors
Vendor Summary Table
Vendor
Module Count
Top CVEs
Path
Schneider Electric
39
CVE-2022-24323, CVE-2022-32512, CVE-2023-37195
cve/schneider_electric/
Rockwell Automation
38
CVE-2022-1161, CVE-2023-3595, CVE-2021-33012
cve/rockwell/ + cve/rockwell_automation/
Siemens
27
CVE-2021-22681, CVE-2022-38465, CVE-2019-13945
cve/siemens/
ABB
22
CVE-2022-0228, CVE-2023-0232, CVE-2024-2461
cve/abb/
Honeywell
20
CVE-2023-5389, CVE-2021-38461, CVE-2022-30312
cve/honeywell/
GE / GE Vernova
18
CVE-2022-29951, CVE-2023-1955, CVE-2024-9037
cve/ge/ + cve/ge_vernova/
Emerson
16
CVE-2022-29965, CVE-2020-12030, CVE-2023-51761
cve/emerson/
AVEVA / OSIsoft
14
CVE-2023-34982, CVE-2022-23854, CVE-2021-26382
cve/aveva/ + cve/osisoft_aveva/
Advantech
15
CVE-2022-3157, CVE-2023-2573, CVE-2021-22690
cve/advantech/
Moxa
12
CVE-2019-9084, CVE-2021-45741, CVE-2022-40224
cve/moxa/
Omron
12
CVE-2022-31206, CVE-2023-27396, CVE-2021-43985
cve/omron/
Phoenix Contact
9
CVE-2021-33543, CVE-2022-31800, CVE-2023-46145
cve/phoenix_contact/
Beckhoff
8
CVE-2022-25920, CVE-2019-5637, CVE-2020-27267
cve/beckhoff/
Mitsubishi
8
CVE-2021-20608, CVE-2023-2726, CVE-2022-25151
cve/mitsubishi/
Inductive Automation
6
CVE-2023-39476, CVE-2022-35876, CVE-2021-42615
cve/ignition/ + cve/inductive_automation/
Tridium
7
CVE-2021-33009, CVE-2019-15521, CVE-2022-29856
cve/tridium/
Unitronics
5
CVE-2023-6448, CVE-2024-22178, CVE-2021-43466
cve/unitronics/
WAGO
4
CVE-2022-45138, CVE-2021-34593, CVE-2019-5074
cve/wago/
Pilz
4
CVE-2021-34596, CVE-2022-40206, CVE-2020-12516
cve/pilz/
Codesys
5
CVE-2023-41706, CVE-2022-31802, CVE-2021-34595
cve/codesys/
Delta Electronics
5
CVE-2023-1133, CVE-2022-2109, CVE-2021-38404
cve/delta_electronics/
Eaton
5
CVE-2021-23276, CVE-2022-22805, CVE-2023-43772
cve/eaton/
Johnson Controls
5
CVE-2023-4486, CVE-2022-21939, CVE-2021-36206
cve/johnson_controls/
Yokogawa
5
CVE-2022-27192, CVE-2021-20248, CVE-2019-5911
cve/yokogawa/
Dassault Systemes
4
CVE-2021-22177, CVE-2022-26527, CVE-2023-2456
cve/dassault_systemes/
7 Technologies
1
CVE-2011-3486
cve/7_technologies/
Alstom
2
CVE-2019-14932, CVE-2021-31539
cve/alstom/
Altus
3
CVE-2022-1701, CVE-2023-38578, CVE-2021-4107
cve/altus/
Apache (ICS)
2
CVE-2021-44228 (Log4Shell ICS), CVE-2022-42889
cve/apache/
APT Malware TTPs
26
FrostyGoop, Industroyer, NotPetya, EKANS, TRITON
cve/malware/
AspenTech
3
CVE-2021-26030, CVE-2022-1498, CVE-2020-12028
cve/aspentech/
AutomationDirect
3
CVE-2022-2003, CVE-2021-33013, CVE-2023-0615
cve/automationdirect/
Automated Logic
2
CVE-2021-24280, CVE-2022-38361
cve/automated_logic/
Axiomtek
2
CVE-2022-26165, CVE-2023-2974
cve/axiomtek/
Baker Hughes
2
CVE-2021-42834, CVE-2022-25257
cve/baker_hughes/
Bedrock Automation
2
CVE-2021-31347, CVE-2022-12905
cve/bedrock_automation/
Belden/Hirschmann
2
CVE-2022-35862, CVE-2021-20117
cve/belden_hirschmann/
Bentley Systems
2
CVE-2021-32031, CVE-2022-29928
cve/bentley_systems/
Bihl+Wiedemann
1
CVE-2023-45315
cve/bihl_wiedemann/
Bosch Rexroth
3
CVE-2023-48255, CVE-2022-45139, CVE-2021-20127
cve/bosch_rexroth/
B&R Automation
2
CVE-2022-37026, CVE-2021-22286
cve/br_automation/
Broadwin
2
CVE-2020-17439, CVE-2021-31789
cve/broadwin/
Burkert
1
CVE-2022-45866
cve/burkert/
Carlo Gavazzi
1
CVE-2022-45444
cve/carlo_gavazzi/
Chint
2
CVE-2022-45701, CVE-2023-41920
cve/chint/
Cisco (OT)
3
CVE-2022-20695, CVE-2023-20198, CVE-2021-1135
cve/cisco/
Compressor Controls
2
CVE-2021-27451, CVE-2022-30612
cve/compressor_controls/
Comtrol
1
CVE-2020-25171
cve/comtrol/
Critical Manufacturing
1
CVE-2023-4498
cve/critical_manufacturi/
Danfoss
2
CVE-2021-34587, CVE-2022-22428
cve/danfoss/
Delixi
1
CVE-2023-40542
cve/delixi/
Delta Controls
1
CVE-2021-27902
cve/delta_controls/
Digi International
3
CVE-2022-26210, CVE-2021-34552, CVE-2023-5558
cve/digi/
Digicon
2
CVE-2022-39832, CVE-2023-28379
cve/digicon/
Distech Controls
1
CVE-2022-26069
cve/distech_controls/
Eaton
5
CVE-2021-23276, CVE-2022-22805, CVE-2023-43772
cve/eaton/
ELIPSE
2
CVE-2023-28378, CVE-2022-40692
cve/elipse/
Endress+Hauser
2
CVE-2022-27187, CVE-2021-34854
cve/endress_hauser/
Exploits (generic)
—
Generic protocol exploits
cve/exploits/
FANUC
2
CVE-2021-22681, CVE-2022-25158
cve/fanuc/
FATEK
2
CVE-2021-32998, CVE-2022-30269
cve/fatek/
Festo
3
CVE-2022-30310, CVE-2021-34527, CVE-2023-0432
cve/festo/
Flowserve
1
CVE-2021-33000
cve/flowserve/
Framatome
1
CVE-2022-26162
cve/framatome/
FrangoTeam
1
CVE-2022-29858
cve/frangoteam/
Fuji Electric
2
CVE-2021-32992, CVE-2022-22452
cve/fuji_electric/
Grundfos
1
CVE-2023-2877
cve/grundfos/
Hach
1
CVE-2022-26078
cve/hach/
Harting
1
CVE-2021-20121
cve/harting/
Hilscher
2
CVE-2022-30612, CVE-2021-20120
cve/hilscher/
HIMA
2
CVE-2020-12523, CVE-2022-27191
cve/hima/
Hitachi
2
CVE-2022-41988, CVE-2021-20589
cve/hitachi/
Hiwin
1
CVE-2023-28346
cve/hiwin/
HMS Networks
2
CVE-2022-35862, CVE-2021-37163
cve/hms_networks/
Hollysys
1
CVE-2022-34045
cve/hollysys/
IEI Integration
1
CVE-2023-40543
cve/iei_integration/
ifm electronic
1
CVE-2022-43556
cve/ifm_electronic/
Iconics
4
CVE-2023-29474, CVE-2022-23127, CVE-2021-27992
cve/iconics/
Inovance
2
CVE-2022-36131, CVE-2023-40541
cve/inovance/
INVT
1
CVE-2022-43778
cve/invt/
Itron
2
CVE-2022-29485, CVE-2021-36208
cve/itron/
JTEKT
2
CVE-2022-21134, CVE-2021-20626
cve/jtekt/
Kepware
3
CVE-2022-29825, CVE-2021-23297, CVE-2020-25158
cve/kepware/
Keyence
2
CVE-2022-43552, CVE-2021-20603
cve/keyence/
Kinco
2
CVE-2022-40202, CVE-2023-40540
cve/kinco/
KMC Controls
2
CVE-2022-26167, CVE-2021-38458
cve/kmc_controls/
Kongsberg
3
CVE-2022-31207, CVE-2021-32987, CVE-2023-2712
cve/kongsberg/
Kontron
2
CVE-2022-45702, CVE-2023-28378
cve/kontron/
Koyo
1
CVE-2020-25176
cve/koyo/
Krohne
1
CVE-2022-27188
cve/krohne/
Landis+Gyr
2
CVE-2022-27286, CVE-2021-21815
cve/landis_gyr/
Lenze
2
CVE-2022-3225, CVE-2021-20131
cve/lenze/
LS Electric
4
CVE-2022-3232, CVE-2021-26981, CVE-2023-2586
cve/ls_electric/
Magnetrol
1
CVE-2022-22435
cve/magnetrol/
Malware TTPs
26
See Malware TTP Modules section
cve/malware/
Measuresoft
2
CVE-2021-32955, CVE-2022-27187
cve/measuresoft/
MES/ERP
2
CVE-2022-44512, CVE-2021-38374
cve/mes_erp/
Metso
1
CVE-2022-29848
cve/metso/
Mettler-Toledo
1
CVE-2022-44545
cve/mettler_toledo/
MikroTik (ICS-adjacent)
2
CVE-2023-30799, CVE-2022-3617
cve/mikrotik/
Moore Industries
1
CVE-2022-26168
cve/moore_industries/
Motorola Solutions
1
CVE-2022-47896
cve/motorola_solutions/
National Instruments
3
CVE-2023-1545, CVE-2022-23130, CVE-2021-23181
cve/national_instruments/
Nidec
2
CVE-2022-45133, CVE-2021-20626
cve/nidec/
Novus
2
CVE-2022-43553, CVE-2023-40539
cve/novus/
Opto22
2
CVE-2021-32963, CVE-2022-27192
cve/opto22/
OSIsoft
3
CVE-2023-34982, CVE-2021-26382, CVE-2022-23854
cve/osisoft/
OSIsoft/AVEVA
3
Combined modules
cve/osisoft_aveva/
Panasonic
1
CVE-2022-29958
cve/panasonic/
Pepperl+Fuchs
2
CVE-2022-44544, CVE-2021-20127
cve/pepperl_fuchs/
Prominent
1
CVE-2022-27193
cve/prominent/
Prosoft
2
CVE-2022-29851, CVE-2021-33009
cve/prosoft/
PTC
2
CVE-2022-25247, CVE-2021-23220
cve/ptc/
R.Stahl
1
CVE-2021-33002
cve/r_stahl/
Realflex
1
CVE-2020-25169
cve/realflex/
Red Lion
2
CVE-2022-40222, CVE-2021-20127
cve/red_lion/
Reliable Controls
1
CVE-2022-29854
cve/reliable_controls/
Ruggedcom (Siemens)
2
CVE-2022-25751, CVE-2021-37204
cve/ruggedcom/
S&C Electric
1
CVE-2022-30304
cve/s_and_c_electric/
Saia-Burgess
2
CVE-2022-30312, CVE-2021-27453
cve/saia_burgess/
Sauter AG
1
CVE-2022-22423
cve/sauter_ag/
SEL (Schweitzer)
3
CVE-2023-31168, CVE-2022-29959, CVE-2021-20125
cve/sel/
Sensata
1
CVE-2022-40203
cve/sensata/
SEW-Eurodrive
2
CVE-2022-43783, CVE-2021-20130
cve/sew_eurodrive/
Sick AG
2
CVE-2022-27188, CVE-2021-21816
cve/sick_ag/
Sierra Wireless
2
CVE-2022-26168, CVE-2021-40513
cve/sierra_wireless/
SMAR
2
CVE-2022-44540, CVE-2023-41921
cve/smar/
Sofrel
2
CVE-2022-30612, CVE-2021-34856
cve/sofrel/
Softing
2
CVE-2022-22519, CVE-2021-33009
cve/softing/
Step Electric
1
CVE-2022-43784
cve/step_electric/
Supcon
1
CVE-2022-27194
cve/supcon/
Teltonika
2
CVE-2023-32348, CVE-2022-22427
cve/teltonika/
Thales
1
CVE-2022-38458
cve/thales/
Trench Group
1
CVE-2022-27195
cve/trench_group/
Trend Control
1
CVE-2021-27466
cve/trend_control/
Turck
2
CVE-2022-45135, CVE-2021-34858
cve/turck/
VEGA
1
CVE-2022-44543
cve/vega/
Vigor
2
CVE-2022-40224, CVE-2023-25380
cve/vigor/
VMware/Spring (ICS)
2
CVE-2022-22965 (Spring4Shell), CVE-2022-22963
cve/vmware_spring/
VxWorks/URGENT11
4
CVE-2019-12255, CVE-2019-12258, CVE-2019-12262
cve/vxworks_urgent11/
Wabtec
1
CVE-2022-30612
cve/wabtec/
Wartsila
2
CVE-2022-29853, CVE-2021-34857
cve/wartsila/
Weatherford
1
CVE-2022-29850
cve/weatherford/
WEG
3
CVE-2023-38573, CVE-2022-44539, CVE-2024-1234
cve/weg/
Weidmuller
1
CVE-2022-45137
cve/weidmuller/
Weintek
2
CVE-2022-3361, CVE-2021-43982
cve/weintek/
Westermo
1
CVE-2022-30612
cve/westermo/
Westinghouse
2
CVE-2022-29852, CVE-2021-21813
cve/westinghouse/
Wind River (VxWorks)
3
CVE-2019-12255, CVE-2020-25211, CVE-2021-31170
cve/wind_river/
Xylem
1
CVE-2022-40207
cve/xylem/
Yaskawa
2
CVE-2022-43780, CVE-2021-20620
cve/yaskawa/
Zyxel
2
CVE-2023-28771, CVE-2022-26413
cve/zyxel/
Protocol Exploit Modules — All 50 Protocols with Module Paths
Each malware module simulates the specific attack techniques used by real ICS malware, allowing defenders to test their detection and response capabilities.
STUXNET Modules (2)
Module
Technique
Simulation
malware/stuxnet/stuxnet_s7_rootkit
T0857, T0851, T0836
Simulates Stuxnet's approach: intercept S7comm reads (report fake values), modify frequency converter setpoints while hiding changes from SCADA
malware/stuxnet/stuxnet_plc_intercept
T0831, T0873
Simulates Stuxnet OB35 injection pattern: add malicious code to existing PLC program organization blocks
CRASHOVERRIDE / INDUSTROYER Modules (4)
Module
Technique
Simulation
malware/industroyer/industroyer_iec104_exec
T0855, T0803
IEC 104 direct breaker trip (Ukraine 2016 attack pattern)
malware/industroyer/industroyer_modbus_exec
T0855, T0806
Modbus output manipulation component
malware/industroyer/industroyer_dos
T0813, T0814
SCADA denial-of-service (Industroyer DoS wiper component)
Simulate bypass of SIS safe state — allow unsafe condition to persist
INCONTROLLER / PIPEDREAM Modules (5)
Module
Technique
Target Protocol
Simulation
malware/pipedream/pipedream_modbus_module
T0855, T0806
Modbus TCP
INCONTROLLER Modbus attack module
malware/pipedream/pipedream_omron_fins
T0855, T0866
Omron FINS
INCONTROLLER Omron module
malware/pipedream/pipedream_opcua_module
T0855, T0802
OPC UA
INCONTROLLER OPC UA data collector
malware/pipedream/pipedream_plc_wiper
T0809, T0843
PLC memory
INCONTROLLER PLC wiper function
malware/pipedream/pipedream_codesys
T0843, T0857
Codesys V3
INCONTROLLER Codesys V3 exploit
Complete Module Usage Examples
Loading any module from the catalog
# Protocol exploit example
ixf > use exploits/protocols/dnp3/dnp3_direct_operate
ixf > set target 10.0.0.101
ixf > set outstation_addr 10
ixf > set trip_close LATCH_ON
ixf > run
# Scanner example
ixf > use scanners/ics/bacnet_scanner
ixf > set target 192.168.100.0/24
ixf > set threads 10
ixf > run
# Malware TTP example
ixf > use malware/industroyer/industroyer_iec104_exec
ixf > show info
ixf > set target 10.0.0.20
ixf > run
Batch module execution
# Run a list of modules non-interactivelyformodulein \
"use scanners/ics/modbus_scanner set target 192.168.1.0/24 run" \
"use scanners/ics/s7_comm_scanner set target 192.168.1.50 run" \
"use scanners/ics/enip_scanner set target 192.168.1.0/24 run";do
ixf $moduledone
Using search to find modules by technique
ixf > search T0836
[*] Search results for: T0836
use exploits/protocols/modbus/modbus_write_register
use exploits/protocols/modbus/modbus_unauthorized_coil_set
use exploits/protocols/s7comm/s7_write_memory
use exploits/protocols/dnp3/dnp3_analog_output
use exploits/protocols/iec104/iec104_command_injection
use assessment/mitre_ics/t0836_modify_parameter
use malware/stuxnet/stuxnet_s7_rootkit
... (18 results)
Finding all CRITICAL modules
ixf > search CRITICAL
[*] Filtering by severity: CRITICAL (241 modules)
use cve/schneider/cve_2018_7789_modicon_auth_bypass CVSS 9.8
use cve/rockwell/cve_2022_1161_controllogix_firmware CVSS 9.8
use cve/siemens/cve_2021_22681_s7_1200_hardcoded_key CVSS 9.8
... (238 more CRITICAL modules)
# View all options for loaded module
ixf (module) > show options
# View full metadata
ixf (module) > show info
# View MITRE mapping only
ixf (module) > show mitre
# View references and CVE details
ixf (module) > show refs
# Check connectivity without running exploit
ixf (module) > check
Complete CVE ID Cross-Reference (Selected Highlights)
CVE ID
Vendor
CVSS
Module Count
IXF Path
CVE-2018-7789
Schneider
9.8
1
cve/schneider/cve_2018_7789_*
CVE-2021-22681
Siemens
9.8
1
cve/siemens/cve_2021_22681_*
CVE-2022-1161
Rockwell
9.8
1
cve/rockwell/cve_2022_1161_*
CVE-2022-26857
Delta
9.8
1
cve/delta_electronics/cve_2022_26857_*
CVE-2023-25078
Honeywell
9.8
1
cve/honeywell/cve_2023_25078_*
CVE-2022-34151
Omron
9.8
1
cve/omron/cve_2022_34151_*
CVE-2017-16744
Tridium
9.8
1
cve/tridium/cve_2017_16744_*
CVE-2018-10952
GE
9.8
1
cve/ge/cve_2018_10952_*
CVE-2023-34982
AVEVA
9.8
1
cve/aveva/cve_2023_34982_*
CVE-2023-39468
Inductive
9.8
1
cve/inductive/cve_2023_39468_*
CVE-2021-38413
Delta
9.8
1
cve/delta_electronics/cve_2021_38413_*
CVE-2022-3323
Advantech
9.8
1
cve/advantech/cve_2022_3323_*
CVE-2019-7232
ABB
9.8
1
cve/abb/cve_2019_7232_*
CVE-2023-0364
ABB
9.8
1
cve/abb/cve_2023_0364_*
CVE-2022-23854
AVEVA
9.8
1
cve/aveva/cve_2022_23854_*
CVE-2020-10636
Emerson
9.8
1
cve/emerson/cve_2020_10636_*
CVE-2021-22655
FANUC
9.8
1
cve/fanuc/cve_2021_22655_*
CVE-2022-26376
ABB
9.8
1
cve/abb/cve_2022_26376_*
CVE-2019-12407
Phoenix
9.8
1
cve/phoenix_contact/cve_2019_12407_*
CVE-2020-7493
Schneider
9.8
1
cve/schneider/cve_2020_7493_*
Module Index Verification
After installation, verify the full module index is intact:
# Quick count
python -c "from industrialxpl.core.exploit.utils import index_modulesmods = index_modules()print(f'Total: {len(mods)} modules')# Count by categoryfrom collections import Countercats = Counter(m.split('/')[0] for m in mods)for cat, count in sorted(cats.items(), key=lambda x: -x[1]): print(f' {cat:30s} {count:4d}')"
Inject GOOSE with high stNum to override legitimate publisher
exploits/protocols/iec61850/sv_timestamp_forge
Forge Sampled Values timestamp
exploits/protocols/iec61850/mms_getnamelist
Enumerate all IED logical nodes
Credential Module Details — Full Credential Lists
creds/generic/http_default — Credentials Tested
Username
Password
Type
admin
admin
Factory default
admin
password
Common weak
admin
(blank)
No password
admin
1234
Numeric default
admin
12345678
Numeric default
root
root
Unix default
root
(blank)
Unix no-password
user
user
Generic
operator
operator
OT operator role
Administrator
(blank)
Windows default
administrator
admin
Windows variant
guest
guest
Read-only
support
support
Vendor support
service
service
Field service
system
system
System account
creds/generic/snmp_community — Community Strings Tested
Community String
Type
Risk
public
Default read
HIGH — information disclosure
private
Default write
CRITICAL — configuration write
admin
Common
HIGH
0
Common legacy
HIGH
community
Common
HIGH
snmp
Common
HIGH
CISCO
Cisco default
HIGH
5nmp
Obfuscated
MEDIUM
manager
HP/3Com
HIGH
monitor
Monitoring
MEDIUM
network
Common
MEDIUM
access
Common
MEDIUM
write
Explicit write
CRITICAL
Using IXF Modules for Compliance Evidence
Generating Evidence for IEC 62443 Audits
IXF simulate-mode outputs serve as documented evidence that specific attack vectors were tested:
# Run all relevant tests in simulate mode and generate evidence report
ixf assess iec62443/zone_conduit_audit
ixf use exploits/protocols/modbus/modbus_unauthorized_coil_set
ixf set target 192.168.1.100
ixf run # simulate output documents the attack would succeed without controls
ixf report json # report contains simulate output as evidence
The JSON report can be attached to IEC 62443 assessment artifacts as evidence that:
Specific attack vectors were tested
Controls were (or were not) effective
MITRE technique coverage was assessed
Generating Evidence for NIST 800-82 Audits
# Run full NIST checklist and export
ixf assess nist_sp800_82/control_checklist
ixf assess network/ics_firewall_audit
ixf report markdown # human-readable for audit documentation
Generating a Penetration Test Report
# Full pentest workflow with report
ixf mitre-scan 192.168.1.0/24 # Phase 1: discovery
ixf assess risk/ics_risk_scorer # Phase 2: risk scoring
ixf assess iec62443/zone_conduit_audit # Phase 3: compliance
ixf report html # Generate HTML pentest report
ixf report json # Machine-readable output for ticketing
ixf report navigator # MITRE Navigator layer for visualization
Frequently Asked Questions — Module Catalog
How many modules target Modbus-based systems?
Over 200 modules interact with Modbus in some way: the 10 Modbus-specific protocol exploit modules, the 2 Modbus scanners, the 34 credential modules (many use HTTP to manage Modbus-accessible devices), and numerous CVE modules targeting devices that use Modbus TCP (Schneider Modicon, Rockwell, generic RTUs).
Can I run all CVE modules against a single target?
Yes, using a custom loop or the mitre-scan command which chains multiple modules:
ixf mitre-scan 192.168.1.100 # runs all technique-mapped modules
ixf ttp T0866 192.168.1.100 # runs all modules for T0866 (Exploitation of Remote Services)
In simulate mode (default): yes, all modules print what they would do without sending packets.
In live mode (set simulate false): use only on authorized test systems. The check command sends a read-only connectivity probe and is generally safe on production.
# Check IXF changelog for new modules
pip show industrialxpl-forge
# Check PyPI for latest version
pip index versions industrialxpl-forge
# Upgrade to latest
pip install --upgrade industrialxpl-forge
# Check what changed
python -c "import industrialxplprint(industrialxpl.__version__)from industrialxpl.core.exploit.utils import index_modulesm = index_modules()print(f'Modules in installed version: {len(m)}')"
Module Security Policy
All modules in the IXF catalog comply with the following policies:
No real credentials — modules never contain actual passwords, API keys, or authentication tokens. Test credentials are from public vendor documentation or public CVE disclosures.
Simulate-first — every module MUST have a working simulate=True path before live execution is available. A module that only executes live will not be accepted.
Impact accuracy — impact levels must accurately reflect the real-world consequence. Understating impact (e.g., marking CATASTROPHIC as HIGH) is never acceptable.
Attribution — malware TTP modules correctly attribute the original threat actor and include references to public reporting.
No 0-day — IXF only covers publicly disclosed vulnerabilities with CVE identifiers or well-documented TTPs. No unpublished research or live 0-day exploitation.
Physical impact documentation — every CVE module must explicitly state the physical consequence in the simulation output.
All scanner modules share a common base set of options. Here is the full options reference using modbus_scanner as a representative example:
ixf > use scanners/ics/modbus_scanner
ixf (Modbus TCP Scanner) > show options
Options — Modbus TCP Scanner (CIDR Range)
═══════════════════════════════════════════════════════════════════════════
+──────────────────+──────────+──────────+────────────────────────────────────────────────+
| Option | Value | Required | Description |
+──────────────────+──────────+──────────+────────────────────────────────────────────────+
| target | | yes | Target IP, hostname, or CIDR range |
| port | 502 | no | Modbus TCP port (default: 502) |
| unit_id_start | 1 | no | Starting unit ID for sweep (1-247) |
| unit_id_end | 10 | no | Ending unit ID for sweep |
| timeout | 3 | no | Per-host connection timeout in seconds |
| threads | 10 | no | Parallel threads for CIDR scan |
| simulate | True | no | Simulate mode (no packets sent) |
| output_format | table | no | Output format: table / json / csv |
+──────────────────+──────────+──────────+────────────────────────────────────────────────+
ixf (Modbus TCP Scanner) > set target 192.168.1.0/24
[*] target => 192.168.1.0/24
ixf (Modbus TCP Scanner) > set threads 20
[*] threads => 20
ixf (Modbus TCP Scanner) > run
[SIMULATE MODE — no packets sent]
Module: Modbus TCP Scanner — CIDR Range
Target: 192.168.1.0/24 Threads: 20
Step 1: Resolve 192.168.1.0/24 to 254 host addresses (192.168.1.1–192.168.1.254)
Step 2: Spawn 20 threads; each tests up to 13 hosts
Step 3: Per host: TCP SYN to port 502, timeout 3s
Step 4: For responsive hosts: send Modbus FC4 (Read Input Registers) probe
Step 5: Verify MBAP Transaction ID echo in response
Step 6: For confirmed Modbus devices: sweep unit IDs 1-10
Step 7: Report all Modbus devices with responding unit IDs
[i] Live output (example):
192.168.1.50 port 502 OPEN Unit 1: Input Register[0]=0x0064 DETECTED
192.168.1.100 port 502 OPEN Unit 1: Input Register[0]=0x0032 DETECTED
192.168.1.100 port 502 OPEN Unit 2: Input Register[0]=0x0000 DETECTED
192.168.1.155 port 502 OPEN Unit 1: no response (non-Modbus service)
[i] MITRE ATT&CK for ICS: T0888 (Remote System Information Discovery)
Scanner Output Formats
# Table (default) — human readable
ixf use scanners/ics/modbus_scanner set target 192.168.1.0/24 run
# JSON — for parsing and integration
ixf use scanners/ics/modbus_scanner set target 192.168.1.0/24 set output_format json run > scan.json
# CSV — for spreadsheet import
ixf use scanners/ics/modbus_scanner set target 192.168.1.0/24 set output_format csv run > scan.csv
Complete Protocol Exploit Module Reference
Module Severity and MITRE Mapping
Module Category
Severity Distribution
Key MITRE Techniques
Modbus exploits
HIGH (80%), MEDIUM (20%)
T0855, T0836, T0806, T0802
S7comm exploits
CRITICAL (60%), HIGH (40%)
T0855, T0881, T0843, T0845
EtherNet/IP
HIGH (78%), CRITICAL (22%)
T0855, T0861, T0843, T0808
DNP3
CRITICAL (50%), HIGH (50%)
T0855, T0803, T0813
BACnet
HIGH (71%), MEDIUM (29%)
T0855, T0836, T0802
IEC 60870-5-104
CRITICAL (67%), HIGH (33%)
T0855, T0803
IEC 61850
CRITICAL (60%), HIGH (40%)
T0855, T0829, T0876
OPC UA
HIGH (67%), MEDIUM (33%)
T0855, T0802, T0866
MQTT
HIGH (75%), MEDIUM (25%)
T0802, T0855
SNMP
MEDIUM (60%), HIGH (40%)
T0802, T0888
Credential Module — Detailed Coverage
Vendor-Specific Credential Database
The IXF credential database contains 34 modules covering the most common default credential exposures in OT environments. Each module tests credentials specific to the vendor's implementation.
Siemens HMI Web Server Default Credentials
ixf > use creds/siemens/siemens_web_hmi_default
ixf > set target 192.168.1.50
ixf > set port 80
ixf > run
[SIMULATE MODE — no packets sent]
Module: Siemens SIMATIC HMI Web Server Default Credentials
Target: http://192.168.1.50:80
Credential pairs that would be tested:
Path: /api/jsonrpc (Siemens WinCC Web Navigator)
+──────────────────────────────────────+────────────────────+
| Username | Password |
+──────────────────────────────────────+────────────────────+
| admin | admin |
| admin | siemens |
| service | service |
| User | (blank) |
| Administrator | (blank) |
| Siemens | Siemens |
+──────────────────────────────────────+────────────────────+
[i] HMI web server found on Siemens TP1500, TP700, KP900, SMART panels
[i] MITRE: T0812 (Default Credentials)
# Export JSON report to file
ixf report json
# Parse findings and send to Splunk HTTP Event Collector
python -c "import json, requestswith open('./ixf-report-2026年06月01日.json') as f: report = json.load(f)for finding in report['findings']: event = { 'sourcetype': 'ixf:finding', 'event': finding } requests.post( 'https://splunk.corp.example.com:8088/services/collector', headers={'Authorization': 'Splunk <token>'}, json=event )"
Integrating with Nozomi Networks / Claroty
IXF simulate-mode output can be used to validate that Claroty/Nozomi/Dragos OT NDR solutions detect the attack patterns:
# 1. Enable NDR detection mode (passive)# 2. Run IXF in LIVE mode (set simulate false) against test PLC# 3. Verify NDR alerts were generated
ixf use exploits/protocols/modbus/modbus_unauthorized_coil_set
ixf set target 192.168.1.100 # test PLC only
ixf set simulate false
ixf set destructive true
ixf run # triggers real Modbus write — NDR should alert
Using IXF in CI/CD for OT Security Regression Testing