300+ SCADA Protocol Articles & Guides
Deep dives on Modbus, DNP3, IEC 60870-5-101/104, IEC 61850, OPC UA, Profinet, MQTT, IEC 62443, and substation automation — written for practicing engineers.
Wireshark ICCP: How to Decode TASE.2 Traffic
Wireshark ICCP analysis: capture ports 102 and 3782, fix MMS decoding, tell ICCP from IEC 61850, and read associations, transfer reports, and device controls.
Wireshark EtherNet/IP: Decode CIP Traffic
Wireshark EtherNet/IP capture and decode: CIP services, Forward_Open on TCP 44818, implicit I/O on UDP 2222, status codes, and connection troubleshooting.
Wireshark Modbus RTU: Decode Serial RS-485 Traffic
Wireshark Modbus RTU over RS-485: COM port setup with a serial adapter, DLT 147 configuration, display filters, and how to read framing and CRC errors.
Decrypt Industrial Protocol Traffic in Wireshark
Decrypt industrial protocol traffic in Wireshark using SSLKEYLOGFILE: TLS-secured Modbus TCP on 802, IEC 104 on 19998, IEC 61850 MMS, and OPC UA sessions.
Wireshark DNP3: Capture, Filter, Troubleshoot
Wireshark DNP3 analysis end to end: display filters, function codes, IIN bits, quality flags, CRC errors, and how to trace an unsolicited response.
Wireshark Modbus TCP: Capture, Filter, Troubleshoot
Wireshark Modbus TCP analysis end to end: display filters, MBAP header decoding, exception responses, timeouts, and what each failure looks like on the wire.
Wireshark MQTT: Decode Industrial IoT Traffic
Wireshark MQTT capture and decode: display filters, CONNECT and PUBLISH packets, QoS levels, Sparkplug B payloads, TLS on 8883, and broker troubleshooting.
Wireshark OPC UA: Decode Client/Server Traffic
Wireshark OPC UA capture and decode: display filters, service node IDs, session and channel setup, decrypting secured traffic, and certificate failures.
Wireshark PROFINET: Decode RT, DCP, and IO Traffic
Wireshark PROFINET capture and decode: RT cyclic frames, DCP discovery, connection setup, alarm frames, LLDP topology checks, and cycle-time troubleshooting.
Wireshark IEC 61850 MMS: Decode Client/Server
Wireshark IEC 61850 MMS capture and decode: the PRES user context fix for port 102, association setup, Read and Write services, reports, and control sequences.
Wireshark GOOSE: Decode IEC 61850 Messages
Wireshark GOOSE decoding step by step: filter EtherType 0x88B8, read gocbRef and datSet, and use stNum and sqNum to spot the exact moment an event fires.
Wireshark IEC 104: Decode IEC 60870-5-104 Traffic
Wireshark IEC 104 decoding on TCP 2404: I, S, and U frame types, ASDU type IDs, cause of transmission values, CP56Time2a timestamps, and SPAN capture setup.