deadband logodeadband
Single Binary · Zero Dependencies

Features

Everything you need to assess firmware vulnerabilities across your ICS/OT environment — discovery, matching, enrichment, compliance mapping, and reporting in a single, portable binary.

Multi-Protocol Network Discovery

Scan for industrial devices using 8 native ICS protocols simultaneously. Read-only by construction — identity reads and port probes only, never writes.

CIP/EIP

UDP 44818

ListIdentity broadcast + unicast

Rockwell Automation

S7comm

TCP 102

COTP + S7 Setup + SZL 0x001C

Siemens

Modbus TCP

TCP 502

Device ID (FC 43 / MEI 14)

Schneider ElectricABBDeltaMoxaPhoenix ContactWAGO

MELSEC/SLMP

TCP 5007

Read Type Name command

Mitsubishi Electric

BACnet/IP

UDP 47808

Who-Is + ReadProperty

TraneHoneywellJohnson ControlsCarrier

FINS

UDP 9600

Controller Data Read

Omron

GE-SRTP

TCP 18245

INIT handshake + Type Read

Emerson / GE

OPC UA

TCP 4840

GetEndpoints binary protocol

SiemensBeckhoffB&RKepwareCODESYS
discovery examples
$ deadband --cidr 10.0.1.0/24                    # Auto-detect all 8 protocols
$ deadband --cidr 10.0.1.0/24 --mode cip         # CIP/EIP only
$ deadband --cidr 10.0.1.0/24 --mode opcua       # OPC UA only
$ deadband --cidr 10.0.1.0/24 --concurrency 100  # Faster scanning

Passive PCAP Analysis

CLI-only. Extract device identities from packet captures without generating network traffic. Pure Go — no CGO, no libpcap dependency.

Zero Network Impact

Analyze captures from span ports or network taps. No packets sent, no device interaction.

All 8 Protocols

Same protocol parsers as active discovery — CIP, S7, Modbus, MELSEC, BACnet, FINS, GE-SRTP, OPC UA.

Full Pipeline

Extracted devices feed directly into vulnerability matching, enrichment, and reporting.

passive analysis
$ deadband pcap /captures/ot-network.pcap --prioritize -o report.html
Processed 482,391 packets, found 12 devices (0 errors)

Intelligent Matching Engine

Three-tier matching system that normalizes vendor names, matches models with substring and glob patterns, and compares firmware versions using both semver and prose heuristics.

Vendor Normalization

Static alias mapping handles vendor name variations automatically.

Rockwell → Rockwell, Allen-Bradley, A-B, RA

Siemens → Siemens, SIMATIC

Schneider → Schneider Electric, SE, Modicon

Model Matching

Substring and glob pattern matching for flexible model identification.

1756-EN2T/D → matches 1756-EN2T

1756-L83E → matches 1756-L8*

S7-1500 → matches S7-1500, S7-15*

Version Comparison

Two-tier approach: clean semver parsing plus regex extraction from prose ranges.

Tier 1: <=33.011 (clean semver)

Tier 2: "v33 and prior" (prose heuristic)

Confidence Levels

ConfidenceCriteria
HIGHVendor + model exact match, firmware in advisory range (clean semver)
MEDIUMVendor + model match, version comparison ambiguous or prose-based
LOWVendor match only, model is partial/wildcard match

KEV + EPSS Risk Enrichment

Go beyond CVSS — prioritize findings with real-world exploit intelligence from CISA KEV and FIRST EPSS.

CISA KEV

Flag CVEs in CISA's Known Exploited Vulnerabilities catalog, including ransomware indicators. KEV entries get maximum risk priority.

EPSS Scores

Exploit Prediction Scoring System probabilities for every CVE. Percentile rankings contextualize risk relative to all known vulnerabilities.

Composite Risk Score

Weighted scoring: KEV+ransomware=100, KEV=90, then EPSS and CVSS blended. Sort results by what matters most.

risk-prioritized output
$ deadband -i devices.csv --prioritize --min-cvss 7.0

CRITICAL  ICSA-23-306-01  Rockwell 1756-L83E/B v33.011
         CVE-2023-3595  CVSS 9.8  [KEV+Ransomware]  EPSS 94.2%  Risk: 100
HIGH      ICSA-24-011-03  Siemens S7-1500 v2.9.4
         CVE-2023-44374 CVSS 7.5  EPSS 12.8%  Risk: 53

Compliance Mapping

Map assessment capabilities to control frameworks. Include compliance context in reports for auditors and stakeholders.

IEC 62443

Industrial automation security. Maps to asset inventory, vulnerability management, and patch management controls.

NIST CSF 2.0

Cybersecurity Framework functions — Identify, Protect, Detect. Maps discovery and matching capabilities to specific controls.

NERC CIP

Critical Infrastructure Protection for electric utilities. Maps to CIP-007 (vulnerability assessment) and CIP-010 (configuration management).

compliance report
$ deadband -i devices.csv --compliance iec62443,nist-csf --out-format html -o report.html

# Compliance section included in HTML and JSON output

Five Output Formats

CLI-only. From human-readable terminal output to CI/CD-ready SARIF and self-contained HTML reports.

Text

Color-coded terminal output with enrichment data

--out-format text

CSV

Spreadsheet-ready with KEV, EPSS, and risk columns

--out-format csv

JSON

Structured data for automation and API integration

--out-format json

HTML

Self-contained report with executive summary and charts

--out-format html

SARIF

Static Analysis Results for GitHub and GitLab CI/CD

--out-format sarif

Device Baseline & Drift Detection

CLI-only. Save a snapshot of your device inventory and detect changes between scans — new devices, removals, firmware updates, and new vulnerabilities. (The cloud handles drift continuously; baselines are for one-shot CLI runs.)

baseline workflow
# Save initial baseline
$ deadband --cidr 10.0.1.0/24 --save-baseline

# Later: compare against baseline
$ deadband --cidr 10.0.1.0/24 --compare-baseline
Baseline drift: 1 new, 0 removed, 1 firmware change, 2 new vulnerabilities
  + 10.0.1.55 Omron CJ2M (fw 2.1)
  ~ 10.0.1.22 Siemens S7-1500: v2.9.4 -> v3.0.1
  ! 10.0.1.55 Omron CJ2M: new advisory ICSA-24-100-02 (CVSS 8.1)

Air-Gap Capable

CLI-only. Designed for isolated OT networks — no runtime API calls. The advisory database and enrichment data are cached locally after update.

Offline Operation

  1. Run deadband --update on a connected host
  2. Copy ~/.deadband/ to the air-gapped host
  3. Run checks offline — advisories, KEV, and EPSS all cached locally

Local CSAF Mirror

For fully isolated environments, point deadband at a local clone of the CISA CSAF repository using --source. All advisory data is TLP:WHITE and freely redistributable.

Embedded Web UI

CLI-only. A full-featured dashboard embedded in the Go binary — no separate web server or database required. (For continuous monitoring as a service, use the deadband cloud.)

Dashboard

Overview of advisories, vendors, enrichment stats, and device counts

Advisory Browser

Search and filter 3,600+ CISA advisories with KEV/EPSS enrichment

Vulnerability Check

Upload inventory files and check for CVEs with risk prioritization

Network Discovery

Scan networks in real-time with streaming progress across 8 protocols

Compliance View

Browse IEC 62443, NIST CSF, and NERC CIP control mappings

Inventory Diff

Compare two device snapshots to track changes and new exposures

terminal
$ deadband serve
Listening on :8484

CI/CD Integration

CLI-only. Meaningful exit codes, structured output, and SARIF reports make the deadband CLI pipeline-friendly.

Exit CodeMeaning
0No vulnerabilities found
1Vulnerabilities found
2Error (missing DB, bad input, etc.)
github-actions.yml
# Upload SARIF to GitHub Code Scanning
$ deadband -i devices.csv --out-format sarif -o results.sarif
$ gh api repos/$REPO/code-scanning/sarifs -f [email protected]