device type or device version trough the protocol header frame
Is there any way I could know the device type or device version trough the protocol header frame for an OT environment? or any other way?Not nmap
Comments
Depends entirely on the protocols being used and possibly the messages exchanged by the protocol. What protocol do you have in mind?
I am thinking about industrial protocols, for example modbus. I would like to know if for example it is a PLC or HMI
These are commercial products (The ICS Detection Challenge took place at S4x18 and S4x19) with some talk about open source tools in the S4x19 ICS Detection Challenge Results.
There are a few "community tools" available from Dragos.
Presumably "OT" means "operational technology".
In this case yes, the part of the network involved in the (usually) industrial process that is unfortunately sometimes connected to the IT network and occasionally even worse, part of the same. In an ideal world there would be an airgap.