Gridwolf is a fully functional passive ICS/SCADA network discovery and security assessment platform. It analyzes captured network traffic (PCAP files) to automatically identify industrial devices, map communication patterns, detect protocol anomalies, perform C2/beacon detection, match CVEs, and generate professional assessment reports β without transmitting a single packet to the monitored network.
Hey everyone π Anand here β creator of Gridwolf.
I built Gridwolf after repeatedly seeing the same challenge in real-world OT/ICS environments: active scanning is often not allowed, yet most tools depend on it. That leaves teams with limited visibility into whatβs actually happening inside industrial networks.
So the idea was simple β what if we could extract meaningful security insights purely from passive data?
Gridwolf focuses on analyzing PCAP files to:
- Understand ICS protocols like Modbus, S7, DNP3, BACnet, IEC 104
- Classify assets based on the Purdue Model
- Detect behavioral anomalies like beaconing or suspicious communication
- Map findings to MITRE ATT&CK for ICS
- Generate assessment-style outputs instead of just dashboards
The goal is to simulate a real OT security assessment workflow without touching production systems.
This is still evolving, and Iβm actively looking for feedback from:
- OT/ICS security engineers
- Red teamers / blue teamers
- Anyone working in critical infrastructure
Would really appreciate if you can try it out, break it, and share your thoughts π
GitHub: https://github.com/valinorintell...
Report
No reviews yetBe the first to leave a review for Gridwolf