deadband logodeadband
Cloud + open-source CLI

Continuous vulnerability monitoring for OT

Map your OT environment against 3,600+ CISA advisories — KEV and EPSS prioritized. Hosted dashboard or open-source CLI.

The engine — also runnable as a single-binary CLI

terminal
# Discover devices on a network segment (8 protocols)
$ deadband --cidr 10.0.1.0/24 --mode auto
[CIP]    10.0.1.10  Rockwell 1756-L83E/B  v33.011
[S7]     10.0.1.22  Siemens S7-1500      v2.9.4
[OPC UA] 10.0.1.40  Beckhoff CX2040       v3.1.4024

# Check firmware with risk enrichment
$ deadband -i devices.csv --prioritize --min-cvss 7.0

CRITICAL  ICSA-23-306-01  Rockwell 1756-L83E/B v33.011
         CVE-2023-3595  CVSS 9.8  [KEV]  EPSS 94.2%  Risk: 100
HIGH      ICSA-24-011-03  Siemens S7-1500 v2.9.4
         CVE-2023-44374 CVSS 7.5  EPSS 12.8%  Risk: 53

# Generate an HTML report with compliance mappings
$ deadband -i devices.csv --out-format html --compliance iec62443 -o report.html

CISA publishes 3,600+ ICS advisories. Your devices report their firmware versions. deadband connects the two — matching devices to known vulnerabilities, enriching results with real-time threat intelligence, and mapping findings to compliance frameworks.

3,600+CISA AdvisoriesICS-CERT CSAF feed
500+Vendors Coveredacross all sectors
8Discovery Protocolsnative ICS scanning
5Output Formatstext, CSV, JSON, HTML, SARIF

Core Capabilities

A complete vulnerability assessment toolkit — discovery, matching, enrichment, reporting, and drift detection.

Multi-Protocol Discovery

8 protocols

Scan networks with 8 native ICS protocols simultaneously — CIP, S7, Modbus, MELSEC, BACnet, FINS, GE-SRTP, and OPC UA.

Advisory Matching

3,600+ advisories

Three-tier matching engine with vendor normalization, model pattern matching, and semver + prose version comparison.

KEV + EPSS Enrichment

risk scoring

Enrich findings with CISA Known Exploited Vulnerabilities catalog and EPSS exploit probability scores for risk prioritization.

Compliance Mapping

3 frameworks

Map findings to IEC 62443, NIST CSF 2.0, and NERC CIP controls. Include compliance context in HTML and JSON reports.

Passive PCAP Analysis

passive

Extract device identities from packet captures without generating network traffic. Ideal for monitoring taps and span ports.

Device Baseline & Drift

drift detection

Save a device baseline after each scan and detect drift — new devices, removed devices, firmware changes, and new vulnerabilities.

Native ICS Protocol Support

Active scanning with 8 industrial protocols — read-only by construction. Identity reads and port probes only, never writes.

CIP/EIP

UDP 44818

ListIdentity broadcast + unicast

Rockwell Automation

S7comm

TCP 102

COTP + S7 Setup + SZL 0x001C

Siemens

Modbus TCP

TCP 502

Device ID (FC 43 / MEI 14)

Schneider ElectricABBDeltaMoxaPhoenix ContactWAGO

MELSEC/SLMP

TCP 5007

Read Type Name command

Mitsubishi Electric

BACnet/IP

UDP 47808

Who-Is + ReadProperty

TraneHoneywellJohnson ControlsCarrier

FINS

UDP 9600

Controller Data Read

Omron

GE-SRTP

TCP 18245

INIT handshake + Type Read

Emerson / GE

OPC UA

TCP 4840

GetEndpoints binary protocol

SiemensBeckhoffB&RKepwareCODESYS

Run it yourself

The CLI side: three steps from zero to vulnerability report.

01

Update Database

Fetch the latest CISA ICS advisories plus KEV and EPSS enrichment data. Cached locally for offline use.

$ deadband --update
02

Discover or Import

Scan your network with 8 protocols, import a CSV/JSON inventory, or analyze a pcap capture passively.

$ deadband --cidr 10.0.1.0/24
03

Assess & Report

Match firmware against known CVEs, prioritize by risk score, and export as text, CSV, JSON, HTML, or SARIF.

$ deadband -i devices.csv --prioritize -o report.html

CLI quick start

Up and running with the open-source binary in under a minute.

quick-start.sh
# Download the latest release
$ curl -LO https://github.com/jmeltz/deadband/releases/latest/download/deadband-linux-amd64
$ chmod +x deadband-linux-amd64 && mv deadband-linux-amd64 /usr/local/bin/deadband

# Fetch advisory database + enrichment data (~30s)
$ deadband --update

# Scan a network segment
$ deadband --cidr 10.0.1.0/24 --prioritize

# Or analyze a pcap capture passively
$ deadband pcap traffic.pcap --out-format html -o report.html

# Save a baseline for drift detection
$ deadband -i devices.csv --save-baseline

# Launch the web UI
$ deadband serve

Early-access partners

Now accepting

We're looking for OT operators to help shape deadband. Selected partners get free Pro for the first year in exchange for monthly product feedback.

Learn more

Start scanning your OT environment today.

Sign up for the free hosted cloud in 30 seconds, or run the open-source CLI on your own infrastructure. Same probe code underneath; pick the operating model that fits.