Why it matters in practice
Industrial Protocols: Modbus and DNP3 matters because it shapes how an operator scopes the work, chooses validation steps, prioritizes evidence and explains risk. The point is not to accumulate trivia; it is to understand which control boundary is in play and how that boundary can fail under realistic pressure.
Primary coverage
- Understand read/write functions, addressing, broadcast behaviour and expected polling patterns.
- Separate protocol visibility from protocol manipulation; both matter, but they answer different questions.
- Test assumptions around unauthenticated commands, stale devices and permissive routing.
- Correlate packet behaviour with process context whenever possible.
Selected public references
Write findings in terms of trust crossed, scope enlarged and business or operational effect reached. That keeps the note useful whether you are validating a lab, an internal research target or a live customer environment.
Selected public references
- Wireshark ModbusPacket visibility and protocol basics.
- Wireshark DNP3DNP3 packet and field visibility.
- MITRE ATT&CK for ICSIndustrial-technique framing.
