Hi all, I just thought it would be cool if we could start building some testsuite, that fetches known sources of pcap files and then simply replays them against our drivers. This way we should be able to harden our drivers against the stuff that’s out there in the wild.
Here’s a list of some sources: http://kargs.net/captures/ (Mostly BACnet/IP stuff) https://github.com/automayt/ICS-pcap https://www.netresec.com/?page=PcapFiles (Probably we shouldn’t implement drivers for trojans … but contains further lists of repos with captures ;-) ) What do you think? Chris
