OT and network forensics is where BulletproofSoft’s security engineering meets the operational-technology world our sister practice works in every day. Most security firms can read a packet capture. Far fewer can tell you what a malformed BACnet broadcast storm is doing to a building, or read Modbus, S7comm, and DNP3 alongside TLS and DNS in the same investigation. That overlap is the point of this practice.
Authorized Engagements Only
Everything described on this page is for authorized security assessment, incident response, and network diagnostics on systems you own or are contracted to examine. Capture analysis surfaces credentials, authentication material, and transferred files — which is precisely why it is engagement-scoped work with defined authorization, handling rules, and evidence controls. We do not perform, support, or advise on unauthorized interception.
Passive OT and ICS Analysis
Industrial and building networks are the one environment where the usual security toolkit can cause the incident. Active scanning and packet injection can disrupt controllers that were never designed to tolerate it. So our OT analysis workstation, LUVA Studio, is deliberately passive and offline: it reads stored captures. It does not sniff live traffic, inject packets, actively scan devices, or interact with the plant network in any way.
From a stored capture it produces asset inventories, protocol participation, communication flows, topology maps, findings, and report-ready output — across the protocols that actually run plants and buildings:
- Building automation — BACnet/IP, MQTT, SNMP
- Industrial control — Modbus/TCP, S7comm, DNP3, EtherNet/IP, IEC 60870-5-104
- Vendor protocols — Omron FINS, GE SRTP
- Process and telemetry — OPC UA
For a plant or facilities team, “we will never touch your control network” is not a limitation — it is the reason the assessment can happen at all.
BACnet and Network Integrity Diagnostics
A building network rarely fails loudly. It degrades — a duplicate device ID here, a misconfigured BBMD there, retries climbing until operators start describing the system as “slow.” Our BACnet and network integrity analysis targets exactly those conditions:
- Duplicate BACnet device IDs and address conflicts
- Excessive broadcast traffic and broadcast storms
- Timeouts, retries, and slow response times
- Router and BBMD misconfiguration
- Device instability and intermittent dropouts
- Segmentation and packet errors
- Communication loops
Status: working prototype, actively refined. We use it in engagements and continue to develop it; we are not selling it as a finished product.
This is also where the family connection earns its keep. When a diagnosis points at station configuration rather than the network itself, SoftwarePile’s Niagara engineers can act on it — and the protocol integration work that produced the network is the same discipline used to read it.
Packet Forensics and Incident Response Tooling
For IT-side investigation we maintain a set of analyst workspaces built on established open-source forensic engines — BruteShark, PCredz, Scapy, PcapXray, and Wireshark. The engines do the parsing; our contribution is the working environment around them: case persistence, project files, structured reporting, evidence export, and the workflow an analyst actually needs during an investigation.
- Session and protocol reconstruction — rebuild conversations, carve transferred files, map endpoints.
- Authentication evidence — credential and hash extraction for authorized review, with sensitive values masked in reporting.
- Threat indicators — DNS analysis and exfiltration patterns, TLS and SSH fingerprinting (JA3/JA3S), suspicious traffic and potential command-and-control behaviour.
- Topology and asset mapping — device inventories, communication summaries, and interactive network diagrams from offline captures.
- Case handling — project workspaces, analyst notes, timelines, statistics, audit logs, and HTML/CSV/JSON evidence export.
One workspace — our Windows forensics suite — also carries BACnet analysis alongside the conventional IT protocols, which is unusual and genuinely useful when an investigation crosses from the corporate network into the building systems attached to it.
Unified Building-Automation Diagnostics
We are consolidating this work into a single diagnostics workstation that combines packet inspection with guided analysis for BACnet, Fox, Modbus, MQTT, and general IP networking — capture import, asset discovery, network-health analysis, duplicate-address and broadcast detection, traffic baselining, conversation maps, protocol-specific issue detection, and case reporting, with AI-assisted interpretation of what the capture is showing.
Status: working prototype. It is an active build that will absorb parts of the separate tools above. We would rather describe it accurately now than imply a finished platform.
Who This Is For
Facilities and plant teams who need a security or performance assessment of a control network without anything being probed or disturbed. Systems integrators diagnosing a building network that has become unreliable. Security teams whose incident crosses into OT and who need someone fluent in both BACnet and TLS. And organisations that need the findings written up as evidence, not as a screenshot.
If AI is part of the environment being assessed, our AI and MCP security practice covers that boundary, and prompt injection is the failure mode we test for most often.
Tell us what you need examined — and what must not be touched while we do it. We will scope the engagement, confirm authorization, and tell you honestly what a passive analysis can and cannot determine.
Related services
- OT and ICS Security Assessment — Assessing the control network before an incident: OT and ICS security assessment.
- Incident Response and Digital Forensics — When something has already happened: incident response and digital forensics.