Skip to the content.

ICSForge™ is an open-source OT/ICS security coverage validation framework designed to help defenders, SOC teams, and OT security engineers validate detection, visibility, and readiness against real-world industrial attack techniques.

ICSForge™ focuses on what can actually be observed on the network and generates realistic OT traffic and PCAPs aligned with MITRE ATT&CK for ICS (v18) - without exploiting real systems or causing unsafe process impact.


Why ICSForge™?

Most ICS security tools promise coverage - very few let you prove it.

ICSForge™ helps you answer questions like:

ICSForge™ is defender-first, safe by design, and honest about limitations.


Key Capabilities

MITRE ATT&CK for ICS–Aligned Scenarios

Live OT Traffic Generation

PCAP Generation

Sender & Receiver Architecture

SOC Mode


What ICSForge™ Is Not


Quick Start & Installation

git clone https://github.com/ICSforge/ICSforge.git
cd ICSforge
chmod +x icsforge.sh
./icsforge.sh install

Running

sudo ./icsforge.sh web
sudo ./icsforge.sh receiver

Root privileges are required for real protocol ports.


Scenarios


Screenshots

Sender Dashboard

Sender Dashboard

ATT&CK for ICS Matrix

ATT&CK Matrix

SOC Mode – Coverage Validation

SOC Mode

Sender – Tools View

Receiver Live View

Receiver – Live Traffic View

Receiver Live View

Receiver’s ATT&CK for ICS Matrix

ATT&CK Matrix

Receiver – Tools View

Receiver Live View


License

GPLv3


ICSForge™ • OT/ICS security coverage validation • GPLv3