icsFuzzer is a security research and assessment tool designed for use by authorized security professionals. Unauthorized use against systems you do not have explicit written permission to test is illegal and may result in criminal prosecution under the Computer Fraud and Abuse Act (CFAA), the UK Computer Misuse Act, and equivalent laws in other jurisdictions.
Before running icsFuzzer in any environment:
- Obtain written authorization from the system/facility owner
- Coordinate with plant operators — inform them of the test window and which systems will be targeted
- Use a test/lab environment whenever possible rather than production
- Start with a single non-critical device before expanding scope
- Have a rollback plan — know how to restore affected devices
- Use
--delayto throttle packet rates on sensitive network segments - Monitor target devices for unexpected behavior during testing
If icsFuzzer identifies a vulnerability in a vendor's ICS product:
- Do not publish vulnerability details before coordinating with the vendor
- Contact the vendor's security disclosure team directly, or use:
- ICS-CERT: https://www.cisa.gov/report
- CERT/CC: https://kb.cert.org/vuls/report/
- Provide a 90-day remediation window before public disclosure
For vulnerability reports related to icsFuzzer itself or findings made with this tool, contact: alosafuzz@proton.me
This tool is released in good faith for the purpose of improving the security of industrial control systems. Users are expected to act responsibly and in accordance with applicable laws and their organization's policies.