SpinfoSecurity

Open to cybersecurity roles

Defensive OT/ICS tooling you can actually run.

I build free PowerShell and Bash scanners that help authorized teams find exposed industrial control systems before attackers do. The work is defensive, evidence-based, and mapped to public CISA guidance.

Featured projects

Four sector-specific scanners. Same idea: authorized subnet review, protocol exposure, severity-ranked reports. No exploit payloads.

Water / wastewater · PowerShell + Bash

Water Utility Protector

OT/SCADA exposure discovery for water and wastewater utilities, aligned with CISA Alert AA26-097A. Looks for exposed PLCs, HMIs, and remote access on authorized networks.

Building automation · BACnet / BMS

BAS-Guardian

Building automation and HVAC security scanner for BACnet, BMS controllers, and vendor-specific exposure, including high-severity ICS advisories.

Power grid · NERC CIP-aware

Energy-Grid-Protector

Substation and transmission OT/SCADA review for DNP3, IEC 61850, Modbus, and vendor platforms used in electric utilities.

Rail / transit · CVE-2025-1727

Rail-OT-Protector

Rail and transit OT scanner for remote access, ICS protocols, legacy RailSafe APIs, and EOT/HOT linking exposure.

Skills this work demonstrates

How I work

Authorized defensive use only. These projects check reachability and help owners triage exposure. They are not exploit frameworks and must not be used on systems without explicit permission.