Continuous vulnerability monitoring for OT
Map your OT environment against 3,600+ CISA advisories — KEV and EPSS prioritized. Hosted dashboard or open-source CLI.
The engine — also runnable as a single-binary CLI
# Discover devices on a network segment (8 protocols)
$ deadband --cidr 10.0.1.0/24 --mode auto
[CIP] 10.0.1.10 Rockwell 1756-L83E/B v33.011
[S7] 10.0.1.22 Siemens S7-1500 v2.9.4
[OPC UA] 10.0.1.40 Beckhoff CX2040 v3.1.4024
# Check firmware with risk enrichment
$ deadband -i devices.csv --prioritize --min-cvss 7.0
CRITICAL ICSA-23-306-01 Rockwell 1756-L83E/B v33.011
CVE-2023-3595 CVSS 9.8 [KEV] EPSS 94.2% Risk: 100
HIGH ICSA-24-011-03 Siemens S7-1500 v2.9.4
CVE-2023-44374 CVSS 7.5 EPSS 12.8% Risk: 53
# Generate an HTML report with compliance mappings
$ deadband -i devices.csv --out-format html --compliance iec62443 -o report.htmlCISA publishes 3,600+ ICS advisories. Your devices report their firmware versions. deadband connects the two — matching devices to known vulnerabilities, enriching results with real-time threat intelligence, and mapping findings to compliance frameworks.
Core Capabilities
A complete vulnerability assessment toolkit — discovery, matching, enrichment, reporting, and drift detection.
Multi-Protocol Discovery
8 protocolsScan networks with 8 native ICS protocols simultaneously — CIP, S7, Modbus, MELSEC, BACnet, FINS, GE-SRTP, and OPC UA.
Advisory Matching
3,600+ advisoriesThree-tier matching engine with vendor normalization, model pattern matching, and semver + prose version comparison.
KEV + EPSS Enrichment
risk scoringEnrich findings with CISA Known Exploited Vulnerabilities catalog and EPSS exploit probability scores for risk prioritization.
Compliance Mapping
3 frameworksMap findings to IEC 62443, NIST CSF 2.0, and NERC CIP controls. Include compliance context in HTML and JSON reports.
Passive PCAP Analysis
passiveExtract device identities from packet captures without generating network traffic. Ideal for monitoring taps and span ports.
Device Baseline & Drift
drift detectionSave a device baseline after each scan and detect drift — new devices, removed devices, firmware changes, and new vulnerabilities.
Native ICS Protocol Support
Active scanning with 8 industrial protocols — read-only by construction. Identity reads and port probes only, never writes.
CIP/EIP
UDP 44818ListIdentity broadcast + unicast
S7comm
TCP 102COTP + S7 Setup + SZL 0x001C
Modbus TCP
TCP 502Device ID (FC 43 / MEI 14)
MELSEC/SLMP
TCP 5007Read Type Name command
BACnet/IP
UDP 47808Who-Is + ReadProperty
FINS
UDP 9600Controller Data Read
GE-SRTP
TCP 18245INIT handshake + Type Read
OPC UA
TCP 4840GetEndpoints binary protocol
Run it yourself
The CLI side: three steps from zero to vulnerability report.
Update Database
Fetch the latest CISA ICS advisories plus KEV and EPSS enrichment data. Cached locally for offline use.
$ deadband --updateDiscover or Import
Scan your network with 8 protocols, import a CSV/JSON inventory, or analyze a pcap capture passively.
$ deadband --cidr 10.0.1.0/24Assess & Report
Match firmware against known CVEs, prioritize by risk score, and export as text, CSV, JSON, HTML, or SARIF.
$ deadband -i devices.csv --prioritize -o report.htmlCLI quick start
Up and running with the open-source binary in under a minute.
# Download the latest release
$ curl -LO https://github.com/jmeltz/deadband/releases/latest/download/deadband-linux-amd64
$ chmod +x deadband-linux-amd64 && mv deadband-linux-amd64 /usr/local/bin/deadband
# Fetch advisory database + enrichment data (~30s)
$ deadband --update
# Scan a network segment
$ deadband --cidr 10.0.1.0/24 --prioritize
# Or analyze a pcap capture passively
$ deadband pcap traffic.pcap --out-format html -o report.html
# Save a baseline for drift detection
$ deadband -i devices.csv --save-baseline
# Launch the web UI
$ deadband serveEarly-access partners
Now acceptingWe're looking for OT operators to help shape deadband. Selected partners get free Pro for the first year in exchange for monthly product feedback.
Start scanning your OT environment today.
Sign up for the free hosted cloud in 30 seconds, or run the open-source CLI on your own infrastructure. Same probe code underneath; pick the operating model that fits.
