Saturday, October 3, 2020

Passive scanning, possible to get firmware and OS details from endpoints?

Hello In the world of OT, actively scanning endpoints is not possible because they will more than likely crash them. Crashing the OT devices could cause big issues.

I've setup a rspan which is working and dumping everything, I'm wondering is there a way at all to collect firmware versions etc from this data?

I've gone through the pcap using wireshark and can't see anything relating too the firmware, doing a active scan obviously you can get this info.

Any advice is appreciated

Thanks



No comments:

Post a Comment