DNP3 Protocol Anomaly Detection — IDS for SCADA/ICS energy-sector traffic
Defensive security: detect anomalies in DNP3 communications used in SCADA/ICS systems — monitor unauthorized control commands, firmware update attempts, and protocol violations on TCP port 20000 or serial links, using deep packet inspection and machine learning
- What
- Defensive security: detect anomalies in DNP3 communications used in SCADA/ICS systems — monitor unauthorized control commands, firmware update attempts, and protocol violations on TCP port 20000 or serial links, using deep packet inspection and machine learning
- Cost
- Free
- Needs
- network TAP/SPAN on DNP3 communication segments (TCP port 20000 or serial); a baseline of normal DNP3 traffic (masters, outstations, poll intervals, function codes); Suricata or Zeek with DNP3 protocol parser enabled; a DNP3 communication topology map
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — @mukul975's detecting-dnp3-protocol-anomalies skill, listed here with credit to its creator (authored by mahipal, purely defensive OT/ICS security): detect anomalies in DNP3 communications used in SCADA/ICS systems by monitoring unauthorized control commands, firmware update attempts, protocol violations, and deviations from baseline traffic. It walks the agent through building a DNP3 anomaly detector with deep packet inspection and ML approaches — analyzing DNP3 traffic on TCP port 20000 or serial links, mapping masters to outstations, tracking poll intervals and function codes, and flagging suspicious master/outstation activity — for use cases like securing energy-sector networks, investigating suspected unauthorized control commands to RTUs and substations, or deploying anomaly-based IDS with DNP3 parsing at utility substations. Mapped to MITRE ATT&CK, MITRE ATLAS, and NIST frameworks. Honest caveats: a SPECIALIZED skill — it assumes network TAP/SPAN on DNP3 segments, a baseline of normal DNP3 traffic, and a DNP3-aware sensor (Suricata or Zeek with DNP3 parser); it explicitly separates DNP3 Secure Authentication configuration into a different task; deep packet inspection on OT networks must never disrupt live traffic — passive capture only. Apache-2.0 licensed. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: network TAP/SPAN on DNP3 communication segments (TCP port 20000 or serial); a baseline of normal DNP3 traffic (masters, outstations, poll intervals, function codes); Suricata or Zeek with DNP3 protocol parser enabled; a DNP3 communication topology map Install "DNP3 Protocol Anomaly Detection — IDS for SCADA/ICS energy-sector traffic" for me. It gives my agent @mukul975's defensive DNP3 anomaly-detection workflow: analyze DNP3 traffic with deep packet inspection and ML approaches, map master-to-outstation relationships, monitor for unauthorized control commands, firmware update attempts, and protocol violations, and flag deviations from established baselines — mapped to MITRE ATT&CK, ATLAS, and NIST frameworks. Apache-2.0 licensed. IMPORTANT: passive capture only — never disrupt live OT traffic. Repository: https://github.com/mukul975/anthropic-cybersecurity-skills/blob/main/skills/detecting-dnp3-protocol-anomalies/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "detecting-dnp3-protocol-anomalies". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. confirm TAP/SPAN coverage of DNP3 segments; capture a normal-traffic baseline; enable the DNP3 parser in Suricata/Zeek; map my master-to-outstation topology). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.