Who's Knocking on Your PLC? A Honeypot View of Internet-Wide Interest in ICS/OT Protocols
ID: 73aa6427-6d2d-595c-afa6-21fb3b2dd88e
STIX ID: report--73aa6427-6d2d-595c-afa6-21fb3b2dd88e
Feed Name: Censys Blog
**Executive Summary:** This report presents the results of multi-protocol ICS/OT honeypots that observed widespread, mostly reconnaissance-focused scanning of Modbus, Siemens S7, BACnet, IPMI and related protocols; while most contacts were shallow scans, a smaller but significant subset demonstrated protocol-aware, stateful Modbus interactions and malformed/exploit-tagged Modbus payloads, and port-twisting experiments show Modbus and S7 can be fingerprinted by payload rather than port—leading to the recommendation that ICS services must not be exposed to the public Internet and should be protected via segmentation, VPNs, continuous attack-surface scanning, and deployment of defensive honeypots.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
