ics-ctf
Audited by Socket on Sep 5, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS: the content is internally aligned with an ICS/OT CTF/offensive-lab purpose, but that purpose itself grants an AI agent broad exploit-style capabilities: protocol writes, MITM, credential harvesting from project/config files, AD/IT-to-OT pivots, and transitive skill loading. Static command-injection hits are mostly false positives from documentation, and there is no confirmed malware or hidden exfiltration endpoint, but the skill is high-risk because it operationalizes offensive security actions beyond cautious read-only analysis.
The provided fragment is highly actionable offensive guidance for OT/ICS sabotage and telemetry falsification. It includes concrete techniques to (1) inject false data via timed Modbus writes (FDI/race condition) and (2) perform L2 MITM with ARP spoof + NFQUEUE + scapy packet rewriting to alter Modbus responses in transit. It further provides pivot guidance to engineering workstations/HMIs/historians to obtain tag mappings and credentials that enable the attack workflow. There is no obfuscation, and the described misuse can directly impact operator-visible outcomes and process integrity.