Analysis of malware families built to disrupt, manipulate, or destroy industrial control systems and OT environments.
Industroyer
The first malware framework built to speak grid-control protocols directly — used against a Kyiv transmission substation in 2016.
Read profile →TRISIS (TRITON)
The first malware to target a safety instrumented system directly — deployed against Triconex controllers at a Saudi petrochemical plant in 2017.
Read profile →PIPEDREAM
A modular toolkit built to scan, access, and disable PLCs across multiple vendors — discovered and disclosed before it was ever used.
Read profile →