Features
Everything you need to assess firmware vulnerabilities across your ICS/OT environment — discovery, matching, enrichment, compliance mapping, and reporting in a single, portable binary.
Multi-Protocol Network Discovery
Scan for industrial devices using 8 native ICS protocols simultaneously. Read-only by construction — identity reads and port probes only, never writes.
CIP/EIP
UDP 44818ListIdentity broadcast + unicast
S7comm
TCP 102COTP + S7 Setup + SZL 0x001C
Modbus TCP
TCP 502Device ID (FC 43 / MEI 14)
MELSEC/SLMP
TCP 5007Read Type Name command
BACnet/IP
UDP 47808Who-Is + ReadProperty
FINS
UDP 9600Controller Data Read
GE-SRTP
TCP 18245INIT handshake + Type Read
OPC UA
TCP 4840GetEndpoints binary protocol
$ deadband --cidr 10.0.1.0/24 # Auto-detect all 8 protocols
$ deadband --cidr 10.0.1.0/24 --mode cip # CIP/EIP only
$ deadband --cidr 10.0.1.0/24 --mode opcua # OPC UA only
$ deadband --cidr 10.0.1.0/24 --concurrency 100 # Faster scanningPassive PCAP Analysis
CLI-only. Extract device identities from packet captures without generating network traffic. Pure Go — no CGO, no libpcap dependency.
Zero Network Impact
Analyze captures from span ports or network taps. No packets sent, no device interaction.
All 8 Protocols
Same protocol parsers as active discovery — CIP, S7, Modbus, MELSEC, BACnet, FINS, GE-SRTP, OPC UA.
Full Pipeline
Extracted devices feed directly into vulnerability matching, enrichment, and reporting.
$ deadband pcap /captures/ot-network.pcap --prioritize -o report.html
Processed 482,391 packets, found 12 devices (0 errors)Intelligent Matching Engine
Three-tier matching system that normalizes vendor names, matches models with substring and glob patterns, and compares firmware versions using both semver and prose heuristics.
Vendor Normalization
Static alias mapping handles vendor name variations automatically.
Rockwell → Rockwell, Allen-Bradley, A-B, RA
Siemens → Siemens, SIMATIC
Schneider → Schneider Electric, SE, Modicon
Model Matching
Substring and glob pattern matching for flexible model identification.
1756-EN2T/D → matches 1756-EN2T
1756-L83E → matches 1756-L8*
S7-1500 → matches S7-1500, S7-15*
Version Comparison
Two-tier approach: clean semver parsing plus regex extraction from prose ranges.
Tier 1: <=33.011 (clean semver)
Tier 2: "v33 and prior" (prose heuristic)
Confidence Levels
| Confidence | Criteria |
|---|---|
| HIGH | Vendor + model exact match, firmware in advisory range (clean semver) |
| MEDIUM | Vendor + model match, version comparison ambiguous or prose-based |
| LOW | Vendor match only, model is partial/wildcard match |
KEV + EPSS Risk Enrichment
Go beyond CVSS — prioritize findings with real-world exploit intelligence from CISA KEV and FIRST EPSS.
CISA KEV
Flag CVEs in CISA's Known Exploited Vulnerabilities catalog, including ransomware indicators. KEV entries get maximum risk priority.
EPSS Scores
Exploit Prediction Scoring System probabilities for every CVE. Percentile rankings contextualize risk relative to all known vulnerabilities.
Composite Risk Score
Weighted scoring: KEV+ransomware=100, KEV=90, then EPSS and CVSS blended. Sort results by what matters most.
$ deadband -i devices.csv --prioritize --min-cvss 7.0
CRITICAL ICSA-23-306-01 Rockwell 1756-L83E/B v33.011
CVE-2023-3595 CVSS 9.8 [KEV+Ransomware] EPSS 94.2% Risk: 100
HIGH ICSA-24-011-03 Siemens S7-1500 v2.9.4
CVE-2023-44374 CVSS 7.5 EPSS 12.8% Risk: 53Compliance Mapping
Map assessment capabilities to control frameworks. Include compliance context in reports for auditors and stakeholders.
IEC 62443
Industrial automation security. Maps to asset inventory, vulnerability management, and patch management controls.
NIST CSF 2.0
Cybersecurity Framework functions — Identify, Protect, Detect. Maps discovery and matching capabilities to specific controls.
NERC CIP
Critical Infrastructure Protection for electric utilities. Maps to CIP-007 (vulnerability assessment) and CIP-010 (configuration management).
$ deadband -i devices.csv --compliance iec62443,nist-csf --out-format html -o report.html
# Compliance section included in HTML and JSON outputFive Output Formats
CLI-only. From human-readable terminal output to CI/CD-ready SARIF and self-contained HTML reports.
Text
Color-coded terminal output with enrichment data
--out-format textCSV
Spreadsheet-ready with KEV, EPSS, and risk columns
--out-format csvJSON
Structured data for automation and API integration
--out-format jsonHTML
Self-contained report with executive summary and charts
--out-format htmlSARIF
Static Analysis Results for GitHub and GitLab CI/CD
--out-format sarifDevice Baseline & Drift Detection
CLI-only. Save a snapshot of your device inventory and detect changes between scans — new devices, removals, firmware updates, and new vulnerabilities. (The cloud handles drift continuously; baselines are for one-shot CLI runs.)
# Save initial baseline
$ deadband --cidr 10.0.1.0/24 --save-baseline
# Later: compare against baseline
$ deadband --cidr 10.0.1.0/24 --compare-baseline
Baseline drift: 1 new, 0 removed, 1 firmware change, 2 new vulnerabilities
+ 10.0.1.55 Omron CJ2M (fw 2.1)
~ 10.0.1.22 Siemens S7-1500: v2.9.4 -> v3.0.1
! 10.0.1.55 Omron CJ2M: new advisory ICSA-24-100-02 (CVSS 8.1)Air-Gap Capable
CLI-only. Designed for isolated OT networks — no runtime API calls. The advisory database and enrichment data are cached locally after update.
Offline Operation
- Run
deadband --updateon a connected host - Copy
~/.deadband/to the air-gapped host - Run checks offline — advisories, KEV, and EPSS all cached locally
Local CSAF Mirror
For fully isolated environments, point deadband at a local clone of the CISA CSAF repository using --source. All advisory data is TLP:WHITE and freely redistributable.
Embedded Web UI
CLI-only. A full-featured dashboard embedded in the Go binary — no separate web server or database required. (For continuous monitoring as a service, use the deadband cloud.)
Dashboard
Overview of advisories, vendors, enrichment stats, and device counts
Advisory Browser
Search and filter 3,600+ CISA advisories with KEV/EPSS enrichment
Vulnerability Check
Upload inventory files and check for CVEs with risk prioritization
Network Discovery
Scan networks in real-time with streaming progress across 8 protocols
Compliance View
Browse IEC 62443, NIST CSF, and NERC CIP control mappings
Inventory Diff
Compare two device snapshots to track changes and new exposures
$ deadband serve
Listening on :8484CI/CD Integration
CLI-only. Meaningful exit codes, structured output, and SARIF reports make the deadband CLI pipeline-friendly.
| Exit Code | Meaning |
|---|---|
| 0 | No vulnerabilities found |
| 1 | Vulnerabilities found |
| 2 | Error (missing DB, bad input, etc.) |
# Upload SARIF to GitHub Code Scanning
$ deadband -i devices.csv --out-format sarif -o results.sarif
$ gh api repos/$REPO/code-scanning/sarifs -f [email protected]