Industrial Control Systems
ICS / SCADA threat hunting
Protocol Support
Netcap offers audit records for the following protocols seen in industrial control systems:
Ethernet/IP
CIP - Common Industrial Protocol
Modbus / ModbusTCP
The encoders are enabled by default.
Modbus
message Modbus {
string Timestamp = 1;
int32 TransactionID = 2; // Identification of a MODBUS Request/Response transaction
int32 ProtocolID = 3; // It is used for intra-system multiplexing
int32 Length = 4; // Number of following bytes (includes 1 byte for UnitIdentifier + Modbus data length
int32 UnitID = 5; // Identification of a remote slave connected on a serial line or on other buses
bytes Payload = 6;
bool Exception = 7;
int32 FunctionCode = 8;
PacketContext Context = 9;
}CIP
ENIP
Last updated