[{"categories":null,"collections":null,"content":"Learn how OTserver reads DNP3 Group 0 device attributes over TCP 20000 to identify outstation manufacturers, models, firmware, and serial numbers.","date":"2026-09-10","objectID":"/protocols/dnp3/","tags":null,"title":"DNP3 Outstation Discovery with OTserver","uri":"/protocols/dnp3/"},{"categories":null,"collections":null,"content":"Overview DNP3 (IEEE 1815) is used by utility outstations, remote terminal units, and other telemetry devices. OTserver Otter reads device attributes and attaches the resulting identity evidence to an asset with a discovered MAC address. ","date":"2026-09-10","objectID":"/protocols/dnp3/:1:0","tags":null,"title":"DNP3 Outstation Discovery with OTserver","uri":"/protocols/dnp3/#overview"},{"categories":null,"collections":null,"content":"How OTserver discovers DNP3 devices Otter connects to TCP port 20000 and sends a link-layer Reset Link States followed by a confirmed application Read of Group 0 Variation 0 with the all-objects qualifier (0x06). The link reset initializes ","date":"2026-09-10","objectID":"/protocols/dnp3/:2:0","tags":null,"title":"DNP3 Outstation Discovery with OTserver","uri":"/protocols/dnp3/#how-otserver-discovers-dnp3-devices"},{"categories":null,"collections":null,"content":"Evidence extracted OTserver evidence DNP3 Group 0 attribute Vendor Manufacturer, variation 252 Model Product name, variation 250 Name User-assigned device name, variation 247; product name is the fallback Firmware Software version, variatio","date":"2026-09-10","objectID":"/protocols/dnp3/:2:1","tags":null,"title":"DNP3 Outstation Discovery with OTserver","uri":"/protocols/dnp3/#evidence-extracted"},{"categories":null,"collections":null,"content":"Security and read-only safety Otter sends the fixed link reset and attribute read. It does not write or operate points, assign classes, freeze counters, restart devices, or use DNP3 Secure Authentication. Discovery currently covers plain DN","date":"2026-09-10","objectID":"/protocols/dnp3/:3:0","tags":null,"title":"DNP3 Outstation Discovery with OTserver","uri":"/protocols/dnp3/#security-and-read-only-safety"},{"categories":null,"collections":null,"content":"Frequently asked questions ","date":"2026-09-10","objectID":"/protocols/dnp3/:4:0","tags":null,"title":"DNP3 Outstation Discovery with OTserver","uri":"/protocols/dnp3/#frequently-asked-questions"},{"categories":null,"collections":null,"content":"Why is DNP3 detected without a vendor or model? An outstation can answer at the link layer while rejecting or not implementing Group 0 device attributes. Otter preserves that protocol evidence and reports the missing application response or","date":"2026-09-10","objectID":"/protocols/dnp3/:4:1","tags":null,"title":"DNP3 Outstation Discovery with OTserver","uri":"/protocols/dnp3/#why-is-dnp3-detected-without-a-vendor-or-model"},{"categories":null,"collections":null,"content":"Does the link reset restart the outstation? No. Reset Link States is a link-layer communication operation. Otter does not send the DNP3 application cold-restart or warm-restart functions. Compare all supported discovery protocols or configu","date":"2026-09-10","objectID":"/protocols/dnp3/:4:2","tags":null,"title":"DNP3 Outstation Discovery with OTserver","uri":"/protocols/dnp3/#does-the-link-reset-restart-the-outstation"},{"categories":null,"collections":null,"content":"See how OTserver uses IEC 61850 MMS over TCP 102 to discover IED identity, logical devices, health, breaker position, and operation counts.","date":"2026-09-10","objectID":"/protocols/iec61850/","tags":null,"title":"IEC 61850 IED Discovery with OTserver","uri":"/protocols/iec61850/"},{"categories":null,"collections":null,"content":"Overview IEC 61850 models substation equipment as intelligent electronic devices (IEDs), logical devices, logical nodes, and data objects. OTserver Otter browses the MMS model and reads a fixed set of advertised identity and status attribut","date":"2026-09-10","objectID":"/protocols/iec61850/:1:0","tags":null,"title":"IEC 61850 IED Discovery with OTserver","uri":"/protocols/iec61850/#overview"},{"categories":null,"collections":null,"content":"How OTserver discovers IEC 61850 devices Otter connects to MMS on TCP port 102, retrieves the server\u0026rsquo;s logical-device directory, and browses the logical nodes and their advertised variables. It reads only matching attributes from its ","date":"2026-09-10","objectID":"/protocols/iec61850/:2:0","tags":null,"title":"IEC 61850 IED Discovery with OTserver","uri":"/protocols/iec61850/#how-otserver-discovers-iec-61850-devices"},{"categories":null,"collections":null,"content":"Evidence extracted OTserver evidence IEC 61850 source Vendor, model, serial number LPHD1.PhyNam.vendor, .model, .serNum, with LLN0.NamPlt alternatives Hardware version LPHD1.PhyNam.hwRev Firmware and location LPHD1.PhyNam.swRev and .locatio","date":"2026-09-10","objectID":"/protocols/iec61850/:2:1","tags":null,"title":"IEC 61850 IED Discovery with OTserver","uri":"/protocols/iec61850/#evidence-extracted"},{"categories":null,"collections":null,"content":"Security and read-only safety Otter browses directories and reads the listed attributes. It does not access control, report, setting-group, file, or write services and does not issue breaker commands. This is MMS discovery, not GOOSE or Sam","date":"2026-09-10","objectID":"/protocols/iec61850/:3:0","tags":null,"title":"IEC 61850 IED Discovery with OTserver","uri":"/protocols/iec61850/#security-and-read-only-safety"},{"categories":null,"collections":null,"content":"Frequently asked questions ","date":"2026-09-10","objectID":"/protocols/iec61850/:4:0","tags":null,"title":"IEC 61850 IED Discovery with OTserver","uri":"/protocols/iec61850/#frequently-asked-questions"},{"categories":null,"collections":null,"content":"How is this different from S7 discovery on port 102? Both protocols use ISO-on-TCP, but they have different application exchanges. S7 discovery reads Siemens system-status lists; IEC 61850 discovery establishes an MMS association and browse","date":"2026-09-10","objectID":"/protocols/iec61850/:4:1","tags":null,"title":"IEC 61850 IED Discovery with OTserver","uri":"/protocols/iec61850/#how-is-this-different-from-s7-discovery-on-port-102"},{"categories":null,"collections":null,"content":"Does a position reading mean Otter can operate the breaker? No. Otter reads the advertised status value only. Control services and state-changing commands are outside this discovery implementation. Compare all supported discovery protocols ","date":"2026-09-10","objectID":"/protocols/iec61850/:4:2","tags":null,"title":"IEC 61850 IED Discovery with OTserver","uri":"/protocols/iec61850/#does-a-position-reading-mean-otter-can-operate-the-breaker"},{"categories":null,"collections":null,"content":"Learn how OTserver uses read-only OPC UA sessions to collect asset identity, health, location, and documentation evidence from industrial servers.","date":"2026-08-16","objectID":"/protocols/opc-ua/","tags":null,"title":"OPC UA Asset Discovery for Industrial Inventory","uri":"/protocols/opc-ua/"},{"categories":null,"collections":null,"content":"Overview OPC UA connects industrial controllers, supervisory systems, and other automation equipment over IP networks. OTserver opens an unsecured channel and reads standardized asset-identification variables without writing values or calli","date":"2026-08-16","objectID":"/protocols/opc-ua/:1:0","tags":null,"title":"OPC UA Asset Discovery for Industrial Inventory","uri":"/protocols/opc-ua/#overview"},{"categories":null,"collections":null,"content":"How OTserver discovers OPC UA assets For each ARP-discovered target, OTserver probes TCP ports 4840, 4841, and 48400 (configurable). It performs the OPC UA HEL/ACK handshake, calls GetEndpoints to learn the server\u0026rsquo;s endpoint and user-","date":"2026-08-16","objectID":"/protocols/opc-ua/:2:0","tags":null,"title":"OPC UA Asset Discovery for Industrial Inventory","uri":"/protocols/opc-ua/#how-otserver-discovers-opc-ua-assets"},{"categories":null,"collections":null,"content":"Evidence extracted OTserver evidence OPC UA variable Name AssetId, or DeviceSet display name, or ProductInstanceUri Vendor Manufacturer Model Model Serial number SerialNumber Firmware SoftwareRevision Description DeviceClass Location Hierar","date":"2026-08-16","objectID":"/protocols/opc-ua/:2:1","tags":null,"title":"OPC UA Asset Discovery for Industrial Inventory","uri":"/protocols/opc-ua/#evidence-extracted"},{"categories":null,"collections":null,"content":"Security and read-only safety OTserver opens only unsecured (SecurityPolicy None) channels and never writes values or calls methods that modify server state. It does not follow continuation points, does not walk the full node tree, and limi","date":"2026-08-16","objectID":"/protocols/opc-ua/:3:0","tags":null,"title":"OPC UA Asset Discovery for Industrial Inventory","uri":"/protocols/opc-ua/#security-and-read-only-safety"},{"categories":null,"collections":null,"content":"Frequently asked questions ","date":"2026-08-16","objectID":"/protocols/opc-ua/:4:0","tags":null,"title":"OPC UA Asset Discovery for Industrial Inventory","uri":"/protocols/opc-ua/#frequently-asked-questions"},{"categories":null,"collections":null,"content":"Does OTserver support encrypted OPC UA endpoints? No. The scanner opens only SecurityPolicy None channels. When a server offers no unsecured endpoint, the scanner records the endpoint evidence it already collected and warns that asset detai","date":"2026-08-16","objectID":"/protocols/opc-ua/:4:1","tags":null,"title":"OPC UA Asset Discovery for Industrial Inventory","uri":"/protocols/opc-ua/#does-otserver-support-encrypted-opc-ua-endpoints"},{"categories":null,"collections":null,"content":"What happens when the OPC UA server has no aliases? OTserver falls back to the OPC UA DI DeviceSet and reads the same identification, location, health, and counter variables from each device object found there. Compare all supported discove","date":"2026-08-16","objectID":"/protocols/opc-ua/:4:2","tags":null,"title":"OPC UA Asset Discovery for Industrial Inventory","uri":"/protocols/opc-ua/#what-happens-when-the-opc-ua-server-has-no-aliases"},{"categories":null,"collections":null,"content":"Learn how OTserver uses BACnet ReadProperty requests on UDP 47808 to collect controller identity, firmware, model, location, and vendor evidence.","date":"2026-08-14","objectID":"/protocols/bacnet/","tags":null,"title":"BACnet/IP Asset Discovery with ReadProperty","uri":"/protocols/bacnet/"},{"categories":null,"collections":null,"content":"Overview BACnet/IP connects building controllers, supervisory systems, and other automation equipment over IP networks. OTserver uses standard property reads to identify BACnet devices without changing their objects. ","date":"2026-08-14","objectID":"/protocols/bacnet/:1:0","tags":null,"title":"BACnet/IP Asset Discovery with ReadProperty","uri":"/protocols/bacnet/#overview"},{"categories":null,"collections":null,"content":"How OTserver discovers BACnet devices OTserver sends unicast BACnet ReadProperty requests to UDP port 47808 on each ARP-discovered target. It first reads the Device object\u0026rsquo;s Object Identifier to learn the instance number. A valid resp","date":"2026-08-14","objectID":"/protocols/bacnet/:2:0","tags":null,"title":"BACnet/IP Asset Discovery with ReadProperty","uri":"/protocols/bacnet/#how-otserver-discovers-bacnet-devices"},{"categories":null,"collections":null,"content":"Evidence extracted OTserver evidence BACnet property Device instance Object Identifier (75) Firmware Firmware Revision (44) Application version Application Software Version (12) Model Model Name (70) Name Object Name (77) Description Descri","date":"2026-08-14","objectID":"/protocols/bacnet/:2:1","tags":null,"title":"BACnet/IP Asset Discovery with ReadProperty","uri":"/protocols/bacnet/#evidence-extracted"},{"categories":null,"collections":null,"content":"Security and read-only safety The scanner only invokes ReadProperty. It does not use WriteProperty, reinitialize devices, manage alarms, or modify schedules and setpoints. The requests are unicast rather than a BACnet/IP Who-Is broadcast, b","date":"2026-08-14","objectID":"/protocols/bacnet/:3:0","tags":null,"title":"BACnet/IP Asset Discovery with ReadProperty","uri":"/protocols/bacnet/#security-and-read-only-safety"},{"categories":null,"collections":null,"content":"Frequently asked questions ","date":"2026-08-14","objectID":"/protocols/bacnet/:4:0","tags":null,"title":"BACnet/IP Asset Discovery with ReadProperty","uri":"/protocols/bacnet/#frequently-asked-questions"},{"categories":null,"collections":null,"content":"Does OTserver use BACnet Who-Is and I-Am broadcasts? No. The current implementation starts from ARP-discovered IPv4 targets and sends ReadProperty directly to each target on UDP 47808. ","date":"2026-08-14","objectID":"/protocols/bacnet/:4:1","tags":null,"title":"BACnet/IP Asset Discovery with ReadProperty","uri":"/protocols/bacnet/#does-otserver-use-bacnet-who-is-and-i-am-broadcasts"},{"categories":null,"collections":null,"content":"What happens when a BACnet property is unavailable? OTserver keeps the valid properties returned by the device. A missing optional property does not erase other identity evidence. Compare all supported discovery protocols or configure per-p","date":"2026-08-14","objectID":"/protocols/bacnet/:4:2","tags":null,"title":"BACnet/IP Asset Discovery with ReadProperty","uri":"/protocols/bacnet/#what-happens-when-a-bacnet-property-is-unavailable"},{"categories":null,"collections":null,"content":"Design a plant discovery rollout with one scanner per line or cell, weekly authorized scans, and automatic transport to a central OTserver site.","date":"2026-08-14","objectID":"/docs/network-scanning/plant-deployment/","tags":null,"title":"Deploy One OTserver Otter per Production Line","uri":"/docs/network-scanning/plant-deployment/"},{"categories":null,"collections":null,"content":"Placement and scope Place a scanner host at each approved production line or cell boundary. Set each configuration\u0026rsquo;s interface and target list to one boundary, and map its output to the matching OTserver site. A host connected to mult","date":"2026-08-14","objectID":"/docs/network-scanning/plant-deployment/:1:0","tags":null,"title":"Deploy One OTserver Otter per Production Line","uri":"/docs/network-scanning/plant-deployment/#placement-and-scope"},{"categories":null,"collections":null,"content":"Scanner configuration Create otter.json beside each scanner binary. A single object still handles one line; an ordered array handles several lines sequentially: Every array entry needs a unique non-empty name and unique resolved output path","date":"2026-08-14","objectID":"/docs/network-scanning/plant-deployment/:2:0","tags":null,"title":"Deploy One OTserver Otter per Production Line","uri":"/docs/network-scanning/plant-deployment/#scanner-configuration"},{"categories":null,"collections":null,"content":"Windows Task Scheduler Run PowerShell as Administrator on the scanner host: $otterDir = \u0026#39;C:\\OTserver Otter\u0026#39; $action = New-ScheduledTaskAction ` -Execute \u0026#34;$otterDir\\otserver-otter.exe\u0026#34; ` -Argument \u0026#39;scan --ack-authorized\u0026#","date":"2026-08-14","objectID":"/docs/network-scanning/plant-deployment/:2:1","tags":null,"title":"Deploy One OTserver Otter per Production Line","uri":"/docs/network-scanning/plant-deployment/#windows-task-scheduler"},{"categories":null,"collections":null,"content":"Verify the result Confirm that each configuration writes a different file, each line\u0026rsquo;s site receives only its own assets, the import warning count is reviewed, and the scanner host\u0026rsquo;s API key has read/write access only to the int","date":"2026-08-14","objectID":"/docs/network-scanning/plant-deployment/:3:0","tags":null,"title":"Deploy One OTserver Otter per Production Line","uri":"/docs/network-scanning/plant-deployment/#verify-the-result"},{"categories":null,"collections":null,"content":"See how OTserver sends EtherNet/IP List Identity requests over TCP and UDP to inventory industrial devices without opening a control session.","date":"2026-08-14","objectID":"/protocols/ethernet-ip/","tags":null,"title":"How OTserver Discovers EtherNet/IP Devices","uri":"/protocols/ethernet-ip/"},{"categories":null,"collections":null,"content":"Overview EtherNet/IP carries the Common Industrial Protocol (CIP) over standard Ethernet transports. OTserver queries the encapsulation identity service to enrich ARP-discovered assets with product and firmware evidence. ","date":"2026-08-14","objectID":"/protocols/ethernet-ip/:1:0","tags":null,"title":"How OTserver Discovers EtherNet/IP Devices","uri":"/protocols/ethernet-ip/#overview"},{"categories":null,"collections":null,"content":"How OTserver discovers EtherNet/IP devices For each discovered IPv4 target, OTserver sends the encapsulation List Identity command (0x0063) concurrently over TCP and UDP port 44818. It records each transport that returns a valid response an","date":"2026-08-14","objectID":"/protocols/ethernet-ip/:2:0","tags":null,"title":"How OTserver Discovers EtherNet/IP Devices","uri":"/protocols/ethernet-ip/#how-otserver-discovers-ethernetip-devices"},{"categories":null,"collections":null,"content":"Evidence extracted OTserver evidence List Identity attribute Vendor Vendor ID, when present in OTserver\u0026rsquo;s vendor mapping Model and name Product name Firmware Major and minor revision Serial number Device serial number Network evidence","date":"2026-08-14","objectID":"/protocols/ethernet-ip/:2:1","tags":null,"title":"How OTserver Discovers EtherNet/IP Devices","uri":"/protocols/ethernet-ip/#evidence-extracted"},{"categories":null,"collections":null,"content":"Security and read-only safety List Identity is an identification request. OTserver does not create a control connection, write CIP objects, download logic, or change device state. Devices still receive network traffic on both supported tran","date":"2026-08-14","objectID":"/protocols/ethernet-ip/:3:0","tags":null,"title":"How OTserver Discovers EtherNet/IP Devices","uri":"/protocols/ethernet-ip/#security-and-read-only-safety"},{"categories":null,"collections":null,"content":"Frequently asked questions ","date":"2026-08-14","objectID":"/protocols/ethernet-ip/:4:0","tags":null,"title":"How OTserver Discovers EtherNet/IP Devices","uri":"/protocols/ethernet-ip/#frequently-asked-questions"},{"categories":null,"collections":null,"content":"Does OTserver broadcast EtherNet/IP discovery? No. The current scanner sends List Identity directly to IPv4 targets already found by ARP. It tries both TCP and UDP 44818 rather than sending a subnet-wide EtherNet/IP broadcast. ","date":"2026-08-14","objectID":"/protocols/ethernet-ip/:4:1","tags":null,"title":"How OTserver Discovers EtherNet/IP Devices","uri":"/protocols/ethernet-ip/#does-otserver-broadcast-ethernetip-discovery"},{"categories":null,"collections":null,"content":"Can OTserver discover a device that supports only one transport? Yes. A valid response from either TCP or UDP is enough to create the EtherNet/IP observation. Compare all supported discovery protocols or read about ARP and scanner setup. ","date":"2026-08-14","objectID":"/protocols/ethernet-ip/:4:2","tags":null,"title":"How OTserver Discovers EtherNet/IP Devices","uri":"/protocols/ethernet-ip/#can-otserver-discover-a-device-that-supports-only-one-transport"},{"categories":null,"collections":null,"content":"Deploy the OTserver industrial asset manager with Docker Compose, initialize the first administrator, and prepare a site for scanner imports.","date":"2026-08-14","objectID":"/docs/configuration/docker-deployment/","tags":null,"title":"How to Deploy OTserver with Docker Compose","uri":"/docs/configuration/docker-deployment/"},{"categories":null,"collections":null,"content":"Prerequisites Install Docker Engine with Compose. Use long random, URL-safe database credentials and a separate long random OTSERVER_SECRET; keep the environment file out of source control. Put TLS in a reverse proxy in front of OTserver an","date":"2026-08-14","objectID":"/docs/configuration/docker-deployment/:1:0","tags":null,"title":"How to Deploy OTserver with Docker Compose","uri":"/docs/configuration/docker-deployment/#prerequisites"},{"categories":null,"collections":null,"content":"Local development Clone the OTserver manager repository, including the pinned Otter contract submodule, and run the following commands from its root: git clone --recurse-submodules https://github.com/ruveydac/OTserver.git cd OTserver For an","date":"2026-08-14","objectID":"/docs/configuration/docker-deployment/:2:0","tags":null,"title":"How to Deploy OTserver with Docker Compose","uri":"/docs/configuration/docker-deployment/#local-development"},{"categories":null,"collections":null,"content":"Production example with MongoDB The repository\u0026rsquo;s multi-stage Dockerfile builds the standalone application and runs it as an unprivileged user. From the repository root, save this as compose.production.yml: services: mongo: image: mong","date":"2026-08-14","objectID":"/docs/configuration/docker-deployment/:3:0","tags":null,"title":"How to Deploy OTserver with Docker Compose","uri":"/docs/configuration/docker-deployment/#production-example-with-mongodb"},{"categories":null,"collections":null,"content":"Update an existing production deployment Back up MongoDB and the uploaded import files, then check out the OTserver release tag or commit you have tested. From the same repository directory, update its pinned submodule and rebuild only the ","date":"2026-08-14","objectID":"/docs/configuration/docker-deployment/:4:0","tags":null,"title":"How to Deploy OTserver with Docker Compose","uri":"/docs/configuration/docker-deployment/#update-an-existing-production-deployment"},{"categories":null,"collections":null,"content":"Import configuration Import an authorized scanner export through Imports → Create New, or configure the scanner\u0026rsquo;s direct upload with the destination URL, site document ID, and a user API key with read/write access to that site. ","date":"2026-08-14","objectID":"/docs/configuration/docker-deployment/:5:0","tags":null,"title":"How to Deploy OTserver with Docker Compose","uri":"/docs/configuration/docker-deployment/#import-configuration"},{"categories":null,"collections":null,"content":"Verify the result Sign in at /admin, confirm that the expected site exists, and create a small authorized import before planning a plant-wide rollout. The import result shows created, updated, skipped, unresolved, and warning counts. Deploy","date":"2026-08-14","objectID":"/docs/configuration/docker-deployment/:6:0","tags":null,"title":"How to Deploy OTserver with Docker Compose","uri":"/docs/configuration/docker-deployment/#verify-the-result"},{"categories":null,"collections":null,"content":"Run bounded, read-only OT discovery with native identity requests, explicit authorization, and validated evidence.","date":"2026-08-14","objectID":"/docs/network-scanning/secure-industrial-scanning/","tags":null,"title":"How to Safely Scan Industrial Control Systems Without Disrupting PLCs","uri":"/docs/network-scanning/secure-industrial-scanning/"},{"categories":null,"collections":null,"content":"Scope and safety Define the exact IPv4 targets and interface first. Prefer native read-only discovery operations such as PROFINET DCP Identify, EtherNet/IP List Identity, S7 identity lists, BACnet ReadProperty, FINS controller data, Niagara","date":"2026-08-14","objectID":"/docs/network-scanning/secure-industrial-scanning/:1:0","tags":null,"title":"How to Safely Scan Industrial Control Systems Without Disrupting PLCs","uri":"/docs/network-scanning/secure-industrial-scanning/#scope-and-safety"},{"categories":null,"collections":null,"content":"Linux scan otserver-otter scan \\ --target 192.168.1.0/24 \\ --interface eth0 \\ --source-mac 00:11:22:33:44:55 \\ --no-snmp \\ --output ./scan.otserver.json \\ --ack-authorized The scanner enables supported protocols by default. Use --no-* flags","date":"2026-08-14","objectID":"/docs/network-scanning/secure-industrial-scanning/:2:0","tags":null,"title":"How to Safely Scan Industrial Control Systems Without Disrupting PLCs","uri":"/docs/network-scanning/secure-industrial-scanning/#linux-scan"},{"categories":null,"collections":null,"content":"Windows scan .\\otserver-otter.exe scan ` --target 192.168.1.0/24 ` --interface \u0026#39;\u0026lt;interface name or GUID\u0026gt;\u0026#39; ` --source-mac 00:11:22:33:44:55 ` --no-snmp ` --output .\\scan.otserver.json ` --ack-authorized The Windows GUI exposes ","date":"2026-08-14","objectID":"/docs/network-scanning/secure-industrial-scanning/:3:0","tags":null,"title":"How to Safely Scan Industrial Control Systems Without Disrupting PLCs","uri":"/docs/network-scanning/secure-industrial-scanning/#windows-scan"},{"categories":null,"collections":null,"content":"Verify the result Run validate, review partial-failure warnings, and import only the export belonging to the intended site. Compare the first run against the plant\u0026rsquo;s change window and device owner feedback before scheduling repeats. S","date":"2026-08-14","objectID":"/docs/network-scanning/secure-industrial-scanning/:4:0","tags":null,"title":"How to Safely Scan Industrial Control Systems Without Disrupting PLCs","uri":"/docs/network-scanning/secure-industrial-scanning/#verify-the-result"},{"categories":null,"collections":null,"content":"Build a tree-like OTserver site hierarchy from enterprise and plant to production line or cell so scanners and permissions remain scoped.","date":"2026-08-14","objectID":"/docs/inventory-structure/site-hierarchy/","tags":null,"title":"How to Structure OTserver Sites for Plants and Production Lines","uri":"/docs/inventory-structure/site-hierarchy/"},{"categories":null,"collections":null,"content":"Site model Use the smallest site that has a clear operational owner and network boundary. A practical tree is organization → plant → area → production line → cell, but OTserver does not hard-code those names or depth. Stop at the production","date":"2026-08-14","objectID":"/docs/inventory-structure/site-hierarchy/:1:0","tags":null,"title":"How to Structure OTserver Sites for Plants and Production Lines","uri":"/docs/inventory-structure/site-hierarchy/#site-model"},{"categories":null,"collections":null,"content":"Procedure Create the plant and its child areas under Sites. Add production lines or cells where ownership, network scope, or risk changes. Give each scanner configuration only the target networks for its assigned site. Import a baseline and","date":"2026-08-14","objectID":"/docs/inventory-structure/site-hierarchy/:2:0","tags":null,"title":"How to Structure OTserver Sites for Plants and Production Lines","uri":"/docs/inventory-structure/site-hierarchy/#procedure"},{"categories":null,"collections":null,"content":"Verify the result Open a representative asset and confirm its site, observations, topology, and audit history. Move a test user through the hierarchy and verify that descendant access follows the intended boundary. Configure site-based role","date":"2026-08-14","objectID":"/docs/inventory-structure/site-hierarchy/:3:0","tags":null,"title":"How to Structure OTserver Sites for Plants and Production Lines","uri":"/docs/inventory-structure/site-hierarchy/#verify-the-result"},{"categories":null,"collections":null,"content":"Build OTserver Otter on Linux, grant only the raw-network capability it needs, and run an authorized discovery export.","date":"2026-08-14","objectID":"/docs/configuration/linux-deployment/","tags":null,"title":"Linux Deployment for OTserver and OTserver Otter","uri":"/docs/configuration/linux-deployment/"},{"categories":null,"collections":null,"content":"Linux prerequisites Use a dedicated scanner account, a selected physical interface, and either root or CAP_NET_RAW for Linux AF_PACKET discovery. Keep scan output and executable-adjacent otter.json in a restricted directory because the conf","date":"2026-08-14","objectID":"/docs/configuration/linux-deployment/:1:0","tags":null,"title":"Linux Deployment for OTserver and OTserver Otter","uri":"/docs/configuration/linux-deployment/#linux-prerequisites"},{"categories":null,"collections":null,"content":"Install or build the scanner Download the archive for your architecture from a tested Otter release: otserver-otter-linux-x86_64.tar.gz for x86-64 Linux or otserver-otter-linux-aarch64.tar.gz for supported 64-bit Raspberry Pi systems. Extra","date":"2026-08-14","objectID":"/docs/configuration/linux-deployment/:2:0","tags":null,"title":"Linux Deployment for OTserver and OTserver Otter","uri":"/docs/configuration/linux-deployment/#install-or-build-the-scanner"},{"categories":null,"collections":null,"content":"Linux scan Replace the example target, interface, and source MAC with the authorized network and the actual values reported by interfaces. For a downloaded release, replace ./target/release/otserver-otter with ./otserver-otter. sudo ./targe","date":"2026-08-14","objectID":"/docs/configuration/linux-deployment/:3:0","tags":null,"title":"Linux Deployment for OTserver and OTserver Otter","uri":"/docs/configuration/linux-deployment/#linux-scan"},{"categories":null,"collections":null,"content":"Verify the result Validate the export before importing it: ./target/release/otserver-otter validate ./scan.otserver.json Exit code 0 means every configured scan completed, 2 means at least one valid output is partial, and 1 means a configur","date":"2026-08-14","objectID":"/docs/configuration/linux-deployment/:4:0","tags":null,"title":"Linux Deployment for OTserver and OTserver Otter","uri":"/docs/configuration/linux-deployment/#verify-the-result"},{"categories":null,"collections":null,"content":"See how OTserver reads LLDP MIB neighbor tables through SNMP to create MAC-correlated industrial network topology links.","date":"2026-08-14","objectID":"/protocols/lldp/","tags":null,"title":"LLDP Topology Discovery with OTserver","uri":"/protocols/lldp/"},{"categories":null,"collections":null,"content":"Overview Link Layer Discovery Protocol (LLDP) lets neighboring network devices advertise chassis and port identity. OTserver reads the LLDP data already held by an SNMP agent and turns usable neighbor records into topology links between MAC","date":"2026-08-14","objectID":"/protocols/lldp/:1:0","tags":null,"title":"LLDP Topology Discovery with OTserver","uri":"/protocols/lldp/#overview"},{"categories":null,"collections":null,"content":"How OTserver discovers LLDP topology The scanner uses the SNMP settings in executable-adjacent otter.json to walk the standard LLDP remote-systems table under 1.0.8802.1.1.2.1.4.1.1. It also collects LLDP local and extension trees under 1.0","date":"2026-08-14","objectID":"/protocols/lldp/:2:0","tags":null,"title":"LLDP Topology Discovery with OTserver","uri":"/protocols/lldp/#how-otserver-discovers-lldp-topology"},{"categories":null,"collections":null,"content":"Evidence extracted OTserver topology evidence LLDP remote-table field Local endpoint Local MAC from ARP or SNMP interface, bridge, or chassis evidence, plus the LLDP local port number Remote endpoint Chassis MAC address Remote device name R","date":"2026-08-14","objectID":"/protocols/lldp/:2:1","tags":null,"title":"LLDP Topology Discovery with OTserver","uri":"/protocols/lldp/#evidence-extracted"},{"categories":null,"collections":null,"content":"Security and read-only safety OTserver does not transmit LLDP advertisements or change switch neighbor tables. It reads LLDP MIB data with SNMP WALK operations and never sends SNMP SET. Use a read-only SNMPv3 account where possible and keep","date":"2026-08-14","objectID":"/protocols/lldp/:3:0","tags":null,"title":"LLDP Topology Discovery with OTserver","uri":"/protocols/lldp/#security-and-read-only-safety"},{"categories":null,"collections":null,"content":"Frequently asked questions ","date":"2026-08-14","objectID":"/protocols/lldp/:4:0","tags":null,"title":"LLDP Topology Discovery with OTserver","uri":"/protocols/lldp/#frequently-asked-questions"},{"categories":null,"collections":null,"content":"Does OTserver capture raw LLDP Ethernet frames? No. The current scanner reads LLDP neighbor tables through SNMP on UDP 161; it therefore needs working SNMP settings for the target device. ","date":"2026-08-14","objectID":"/protocols/lldp/:4:1","tags":null,"title":"LLDP Topology Discovery with OTserver","uri":"/protocols/lldp/#does-otserver-capture-raw-lldp-ethernet-frames"},{"categories":null,"collections":null,"content":"Why are some LLDP neighbors not turned into links? OTserver only creates a link when the remote chassis subtype says the chassis ID is a MAC address. This avoids inventing asset identity from names, arbitrary strings, or IP addresses. Compa","date":"2026-08-14","objectID":"/protocols/lldp/:4:2","tags":null,"title":"LLDP Topology Discovery with OTserver","uri":"/protocols/lldp/#why-are-some-lldp-neighbors-not-turned-into-links"},{"categories":null,"collections":null,"content":"See how OTserver sends a Niagara Fox hello on TCP 1911 and 4911 to inventory station names, platforms, application versions, and vendor IDs.","date":"2026-08-14","objectID":"/protocols/niagara-fox/","tags":null,"title":"Niagara Fox Station Discovery with OTserver","uri":"/protocols/niagara-fox/"},{"categories":null,"collections":null,"content":"Overview Niagara Fox is used by Niagara Framework stations in building and industrial automation. OTserver uses the protocol\u0026rsquo;s hello exchange to identify a station and its software platform without attempting an authenticated session.","date":"2026-08-14","objectID":"/protocols/niagara-fox/:1:0","tags":null,"title":"Niagara Fox Station Discovery with OTserver","uri":"/protocols/niagara-fox/#overview"},{"categories":null,"collections":null,"content":"How OTserver discovers Niagara Fox stations OTserver connects to TCP ports 1911 and 4911 on each discovered target and sends a fixed Fox version 1.0 hello. It first tries plain Fox. If that response is not valid, it reconnects and tries the","date":"2026-08-14","objectID":"/protocols/niagara-fox/:2:0","tags":null,"title":"Niagara Fox Station Discovery with OTserver","uri":"/protocols/niagara-fox/#how-otserver-discovers-niagara-fox-stations"},{"categories":null,"collections":null,"content":"Evidence extracted OTserver evidence Fox hello field Name hostName Operating system os.name Vendor brandId Software evidence Fox, application, and VM names and versions Host evidence Host address, time zone, host ID, and VM UUID Transport e","date":"2026-08-14","objectID":"/protocols/niagara-fox/:2:1","tags":null,"title":"Niagara Fox Station Discovery with OTserver","uri":"/protocols/niagara-fox/#evidence-extracted"},{"categories":null,"collections":null,"content":"Security and read-only safety The scanner sends only the unauthenticated Fox hello. It does not log in, read station configuration, invoke actions, or write points. For discovery compatibility, the TLS attempt does not use certificate trust","date":"2026-08-14","objectID":"/protocols/niagara-fox/:3:0","tags":null,"title":"Niagara Fox Station Discovery with OTserver","uri":"/protocols/niagara-fox/#security-and-read-only-safety"},{"categories":null,"collections":null,"content":"Frequently asked questions ","date":"2026-08-14","objectID":"/protocols/niagara-fox/:4:0","tags":null,"title":"Niagara Fox Station Discovery with OTserver","uri":"/protocols/niagara-fox/#frequently-asked-questions"},{"categories":null,"collections":null,"content":"Why does OTserver try both plain Fox and TLS? Niagara deployments expose different transports and ports. OTserver tries the same small identity exchange over each supported form and records which one responds. ","date":"2026-08-14","objectID":"/protocols/niagara-fox/:4:1","tags":null,"title":"Niagara Fox Station Discovery with OTserver","uri":"/protocols/niagara-fox/#why-does-otserver-try-both-plain-fox-and-tls"},{"categories":null,"collections":null,"content":"Does OTserver need Niagara credentials? No. The hello exchange used for discovery does not authenticate to the station or access protected configuration. Compare all supported discovery protocols or configure the scanner. ","date":"2026-08-14","objectID":"/protocols/niagara-fox/:4:2","tags":null,"title":"Niagara Fox Station Discovery with OTserver","uri":"/protocols/niagara-fox/#does-otserver-need-niagara-credentials"},{"categories":null,"collections":null,"content":"Learn how OTserver uses the read-only Omron FINS Controller Data Read command over TCP and UDP 9600 to identify PLC models and versions.","date":"2026-08-14","objectID":"/protocols/omron-fins/","tags":null,"title":"Omron FINS Controller Discovery with OTserver","uri":"/protocols/omron-fins/"},{"categories":null,"collections":null,"content":"Overview Factory Interface Network Service (FINS) is used by Omron controllers and related automation products. OTserver sends a fixed controller-information request to identify supported devices without reading or changing process memory. ","date":"2026-08-14","objectID":"/protocols/omron-fins/:1:0","tags":null,"title":"Omron FINS Controller Discovery with OTserver","uri":"/protocols/omron-fins/#overview"},{"categories":null,"collections":null,"content":"How OTserver discovers Omron FINS devices For each ARP-discovered IPv4 address, OTserver queries TCP and UDP port 9600 concurrently. UDP uses the fixed FINS Controller Data Read command (05 01). TCP first completes the FINS node-address han","date":"2026-08-14","objectID":"/protocols/omron-fins/:2:0","tags":null,"title":"Omron FINS Controller Discovery with OTserver","uri":"/protocols/omron-fins/#how-otserver-discovers-omron-fins-devices"},{"categories":null,"collections":null,"content":"Evidence extracted OTserver evidence FINS response field Vendor Omron for a valid controller response Model and name Controller model Firmware Controller version Capacity evidence Program area, I/O memory, DM words, timers/counters, steps, ","date":"2026-08-14","objectID":"/protocols/omron-fins/:2:1","tags":null,"title":"Omron FINS Controller Discovery with OTserver","uri":"/protocols/omron-fins/#evidence-extracted"},{"categories":null,"collections":null,"content":"Security and read-only safety Controller Data Read requests controller metadata. OTserver does not send FINS Memory Area Write, force operations, mode changes, program transfers, or other state-changing commands. It sends at most the fixed ","date":"2026-08-14","objectID":"/protocols/omron-fins/:3:0","tags":null,"title":"Omron FINS Controller Discovery with OTserver","uri":"/protocols/omron-fins/#security-and-read-only-safety"},{"categories":null,"collections":null,"content":"Frequently asked questions ","date":"2026-08-14","objectID":"/protocols/omron-fins/:4:0","tags":null,"title":"Omron FINS Controller Discovery with OTserver","uri":"/protocols/omron-fins/#frequently-asked-questions"},{"categories":null,"collections":null,"content":"Must an Omron controller support both TCP and UDP? No. A valid response from either transport is sufficient. OTserver records which of TCP and UDP port 9600 responded. ","date":"2026-08-14","objectID":"/protocols/omron-fins/:4:1","tags":null,"title":"Omron FINS Controller Discovery with OTserver","uri":"/protocols/omron-fins/#must-an-omron-controller-support-both-tcp-and-udp"},{"categories":null,"collections":null,"content":"Does the scan read PLC process memory? No. The implementation uses Controller Data Read for controller identity and capacity metadata, not Memory Area Read or Write. Compare all supported discovery protocols or configure the scanner. ","date":"2026-08-14","objectID":"/protocols/omron-fins/:4:2","tags":null,"title":"Omron FINS Controller Discovery with OTserver","uri":"/protocols/omron-fins/#does-the-scan-read-plc-process-memory"},{"categories":null,"collections":null,"content":"Collect OTserver evidence across critical or disconnected environments using scheduled files, controlled shares, and quarterly offline transfer.","date":"2026-08-14","objectID":"/docs/network-scanning/isolated-environments/","tags":null,"title":"OTserver Discovery in Isolated and Critical Infrastructure","uri":"/docs/network-scanning/isolated-environments/"},{"categories":null,"collections":null,"content":"Collection and transfer procedure Keep the scanner inside the isolated environment and write validated scan.otserver.json files locally. Use a controlled gateway or approved file share when policy allows. For a disconnected site, transfer t","date":"2026-08-14","objectID":"/docs/network-scanning/isolated-environments/:1:0","tags":null,"title":"OTserver Discovery in Isolated and Critical Infrastructure","uri":"/docs/network-scanning/isolated-environments/#collection-and-transfer-procedure"},{"categories":null,"collections":null,"content":"Linux collection Run without direct upload: otserver-otter scan \\ --target 10.20.0.0/24 \\ --interface eth0 \\ --source-mac 00:11:22:33:44:55 \\ --output /var/lib/otserver-otter/quarterly-line-20.otserver.json \\ --ack-authorized Validate at th","date":"2026-08-14","objectID":"/docs/network-scanning/isolated-environments/:2:0","tags":null,"title":"OTserver Discovery in Isolated and Critical Infrastructure","uri":"/docs/network-scanning/isolated-environments/#linux-collection"},{"categories":null,"collections":null,"content":"Windows collection .\\otserver-otter.exe scan ` --target 10.20.0.0/24 ` --interface \u0026#39;\u0026lt;interface name or GUID\u0026gt;\u0026#39; ` --source-mac 00:11:22:33:44:55 ` --output .\\quarterly-line-20.otserver.json ` --ack-authorized The Windows GUI can","date":"2026-08-14","objectID":"/docs/network-scanning/isolated-environments/:3:0","tags":null,"title":"OTserver Discovery in Isolated and Critical Infrastructure","uri":"/docs/network-scanning/isolated-environments/#windows-collection"},{"categories":null,"collections":null,"content":"Verify the result Record collection time, scanner identity, target scope, validation result, transfer owner, and destination site. Compare warnings and asset counts with the previous quarterly collection before accepting the import. Deploy ","date":"2026-08-14","objectID":"/docs/network-scanning/isolated-environments/:4:0","tags":null,"title":"OTserver Discovery in Isolated and Critical Infrastructure","uri":"/docs/network-scanning/isolated-environments/#verify-the-result"},{"categories":null,"collections":null,"content":"Learn how OTserver uses read-only PROFINET DCP Identify requests to discover device names, models, MAC addresses, IP settings, and device roles.","date":"2026-08-14","objectID":"/protocols/profinet/","tags":null,"title":"PROFINET Network Discovery with OTserver","uri":"/protocols/profinet/"},{"categories":null,"collections":null,"content":"Overview PROFINET Discovery and Configuration Protocol (DCP) exposes identity and network attributes on the local Ethernet segment. OTserver uses DCP because it can find PROFINET devices by MAC address even before their IP configuration is ","date":"2026-08-14","objectID":"/protocols/profinet/:1:0","tags":null,"title":"PROFINET Network Discovery with OTserver","uri":"/protocols/profinet/#overview"},{"categories":null,"collections":null,"content":"How OTserver discovers PROFINET devices The scanner sends a DCP Identify All Ethernet frame to multicast MAC address 01:0E:CF:00:00:00 with EtherType 0x8892. It matches replies to the request transaction ID and rejects malformed, truncated,","date":"2026-08-14","objectID":"/protocols/profinet/:2:0","tags":null,"title":"PROFINET Network Discovery with OTserver","uri":"/protocols/profinet/#how-otserver-discovers-profinet-devices"},{"categories":null,"collections":null,"content":"Evidence extracted OTserver evidence DCP source MAC address Ethernet source and DCP MAC block IP address, network mask, gateway IP parameter block DNS servers Full IP parameter block Device name Name of Station Model Device Vendor Value Ven","date":"2026-08-14","objectID":"/protocols/profinet/:2:1","tags":null,"title":"PROFINET Network Discovery with OTserver","uri":"/protocols/profinet/#evidence-extracted"},{"categories":null,"collections":null,"content":"Security and read-only safety OTserver sends DCP Identify only. It does not send DCP Set or change a station name, IP address, or other device configuration. Layer 2 discovery still reaches every responding PROFINET device on the local segm","date":"2026-08-14","objectID":"/protocols/profinet/:3:0","tags":null,"title":"PROFINET Network Discovery with OTserver","uri":"/protocols/profinet/#security-and-read-only-safety"},{"categories":null,"collections":null,"content":"Frequently asked questions ","date":"2026-08-14","objectID":"/protocols/profinet/:4:0","tags":null,"title":"PROFINET Network Discovery with OTserver","uri":"/protocols/profinet/#frequently-asked-questions"},{"categories":null,"collections":null,"content":"Does PROFINET discovery require an IP address? No. DCP Identify operates directly at Ethernet Layer 2. The selected scanner interface must share the device\u0026rsquo;s broadcast domain; routers do not normally forward these frames. ","date":"2026-08-14","objectID":"/protocols/profinet/:4:1","tags":null,"title":"PROFINET Network Discovery with OTserver","uri":"/protocols/profinet/#does-profinet-discovery-require-an-ip-address"},{"categories":null,"collections":null,"content":"Does OTserver need a special Windows network bridge? No. Active Windows discovery binds Npcap to the selected physical adapter. The scanner does not create a TAP adapter or Windows Network Bridge. Compare all supported discovery protocols o","date":"2026-08-14","objectID":"/protocols/profinet/:4:2","tags":null,"title":"PROFINET Network Discovery with OTserver","uri":"/protocols/profinet/#does-otserver-need-a-special-windows-network-bridge"},{"categories":null,"collections":null,"content":"See how OTserver reads Siemens S7 system-status lists over TCP 102 to identify PLC hardware, firmware, names, and serial numbers.","date":"2026-08-14","objectID":"/protocols/s7/","tags":null,"title":"Siemens S7 Device Discovery with OTserver","uri":"/protocols/s7/"},{"categories":null,"collections":null,"content":"Overview Siemens S7 communication exposes controller identity through System Status Lists (SZLs). OTserver reads the identity lists needed for inventory and associates the result with the MAC address found during ARP discovery. ","date":"2026-08-14","objectID":"/protocols/s7/:1:0","tags":null,"title":"Siemens S7 Device Discovery with OTserver","uri":"/protocols/s7/#overview"},{"categories":null,"collections":null,"content":"How OTserver discovers S7 devices OTserver connects to TCP port 102, negotiates an ISO-on-TCP COTP connection, and performs S7 Setup Communication. It first tries destination TSAP 01:02 and retries with 02:00 when the first negotiation is n","date":"2026-08-14","objectID":"/protocols/s7/:2:0","tags":null,"title":"Siemens S7 Device Discovery with OTserver","uri":"/protocols/s7/#how-otserver-discovers-s7-devices"},{"categories":null,"collections":null,"content":"Evidence extracted OTserver evidence S7 source Vendor Identified as Siemens for a valid S7 response Model Module type, module, or basic hardware record Firmware Version bytes from SZL 0x0011 Name System name from SZL 0x001C Serial number Se","date":"2026-08-14","objectID":"/protocols/s7/:2:1","tags":null,"title":"Siemens S7 Device Discovery with OTserver","uri":"/protocols/s7/#evidence-extracted"},{"categories":null,"collections":null,"content":"Security and read-only safety OTserver requests two diagnostic identity lists. It does not read or write process variables, start or stop the CPU, upload or download blocks, or change controller configuration. Even diagnostic requests consu","date":"2026-08-14","objectID":"/protocols/s7/:3:0","tags":null,"title":"Siemens S7 Device Discovery with OTserver","uri":"/protocols/s7/#security-and-read-only-safety"},{"categories":null,"collections":null,"content":"Frequently asked questions ","date":"2026-08-14","objectID":"/protocols/s7/:4:0","tags":null,"title":"Siemens S7 Device Discovery with OTserver","uri":"/protocols/s7/#frequently-asked-questions"},{"categories":null,"collections":null,"content":"Does S7 discovery require PROFINET DCP? No. S7 identity is queried over TCP/IP after ARP finds a target. PROFINET DCP discovery is separate and can add Layer 2 names, addressing, and device-role evidence. ","date":"2026-08-14","objectID":"/protocols/s7/:4:1","tags":null,"title":"Siemens S7 Device Discovery with OTserver","uri":"/protocols/s7/#does-s7-discovery-require-profinet-dcp"},{"categories":null,"collections":null,"content":"Why does OTserver try two TSAP values? Different S7 endpoints accept different rack/slot conventions. OTserver tries two fixed connection requests and stops if neither produces a valid COTP response. Compare all supported discovery protocol","date":"2026-08-14","objectID":"/protocols/s7/:4:2","tags":null,"title":"Siemens S7 Device Discovery with OTserver","uri":"/protocols/s7/#why-does-otserver-try-two-tsap-values"},{"categories":null,"collections":null,"content":"Learn how OTserver uses read-only SNMPv2c or SNMPv3 GET and WALK operations to collect system, interface, entity, IP, and bridge evidence.","date":"2026-08-14","objectID":"/protocols/snmp/","tags":null,"title":"SNMP Discovery for Industrial Asset Inventory","uri":"/protocols/snmp/"},{"categories":null,"collections":null,"content":"Overview SNMP supplies identity, interface, physical-component, VLAN, and topology data across managed switches, controllers, servers, and other networked equipment. It is enabled by default and uses SNMPv2c with community public when no se","date":"2026-08-14","objectID":"/protocols/snmp/:1:0","tags":null,"title":"SNMP Discovery for Industrial Asset Inventory","uri":"/protocols/snmp/#overview"},{"categories":null,"collections":null,"content":"How OTserver discovers assets with SNMP OTserver connects to UDP port 161 with SNMPv1, v2c, or v3 settings from the snmp block of executable-adjacent otter.json. It starts with a multi-value GET for system description, object ID, name, and ","date":"2026-08-14","objectID":"/protocols/snmp/:2:0","tags":null,"title":"SNMP Discovery for Industrial Asset Inventory","uri":"/protocols/snmp/#how-otserver-discovers-assets-with-snmp"},{"categories":null,"collections":null,"content":"Evidence extracted OTserver evidence MIB source Description and operating-system hint sysDescr.0 Name sysName.0 Location sysLocation.0 Interfaces IF-MIB description, MTU, speed, MAC, admin state, and operational state High-speed interfaces ","date":"2026-08-14","objectID":"/protocols/snmp/:2:1","tags":null,"title":"SNMP Discovery for Industrial Asset Inventory","uri":"/protocols/snmp/#evidence-extracted"},{"categories":null,"collections":null,"content":"Security and read-only safety OTserver uses SNMP GET and WALK only; it never sends SNMP SET. Prefer SNMPv3 authentication and privacy where devices support it, give the scanner a read-only account, and restrict access with device ACLs. SNMP","date":"2026-08-14","objectID":"/protocols/snmp/:3:0","tags":null,"title":"SNMP Discovery for Industrial Asset Inventory","uri":"/protocols/snmp/#security-and-read-only-safety"},{"categories":null,"collections":null,"content":"Frequently asked questions ","date":"2026-08-14","objectID":"/protocols/snmp/:4:0","tags":null,"title":"SNMP Discovery for Industrial Asset Inventory","uri":"/protocols/snmp/#frequently-asked-questions"},{"categories":null,"collections":null,"content":"Can OTserver scan SNMP without configuring credentials? Yes. Without SNMP settings, the scanner uses SNMPv2c with community public, so SNMP does not block a scan. Keep otter.json out of source control and restrict its permissions when it co","date":"2026-08-14","objectID":"/protocols/snmp/:4:1","tags":null,"title":"SNMP Discovery for Industrial Asset Inventory","uri":"/protocols/snmp/#can-otserver-scan-snmp-without-configuring-credentials"},{"categories":null,"collections":null,"content":"Does OTserver use vendor-specific MIBs? The scanner uses standard system, IF-MIB, IP-MIB, BRIDGE-MIB, Q-BRIDGE-MIB, ENTITY-MIB, and LLDP trees, plus generic Siemens AUTOMATION-SYSTEM-MIB identity scalars. It preserves returned OIDs as raw e","date":"2026-08-14","objectID":"/protocols/snmp/:4:2","tags":null,"title":"SNMP Discovery for Industrial Asset Inventory","uri":"/protocols/snmp/#does-otserver-use-vendor-specific-mibs"},{"categories":null,"collections":null,"content":"Give OTserver users read-only or read/write access to a site and its descendants while preserving auditability and least privilege.","date":"2026-08-14","objectID":"/docs/inventory-structure/users-and-roles/","tags":null,"title":"Users and Site-Based Roles in OTserver","uri":"/docs/inventory-structure/users-and-roles/"},{"categories":null,"collections":null,"content":"Access model Create roles around a site permission and choose read-only or read/write access. A permission applies to the selected site and every descendant, so model the hierarchy before assigning roles. Keep the protected Admin role for a","date":"2026-08-14","objectID":"/docs/inventory-structure/users-and-roles/:1:0","tags":null,"title":"Users and Site-Based Roles in OTserver","uri":"/docs/inventory-structure/users-and-roles/#access-model"},{"categories":null,"collections":null,"content":"Procedure Build the site tree under Sites. Open User Roles and create a role for the responsible team. Add one or more site permissions with the smallest required access level. Create or edit a user and assign the role. Test the account at ","date":"2026-08-14","objectID":"/docs/inventory-structure/users-and-roles/:2:0","tags":null,"title":"Users and Site-Based Roles in OTserver","uri":"/docs/inventory-structure/users-and-roles/#procedure"},{"categories":null,"collections":null,"content":"Verify the result Sign in as the test user and confirm that collections outside the permitted site are neither visible nor accessible. Review the immutable audit log after role, user, or inventory changes. Structure the site tree or deploy ","date":"2026-08-14","objectID":"/docs/inventory-structure/users-and-roles/:3:0","tags":null,"title":"Users and Site-Based Roles in OTserver","uri":"/docs/inventory-structure/users-and-roles/#verify-the-result"},{"categories":null,"collections":null,"content":"Install and run OTserver Otter on Windows with a physical adapter, separately installed Npcap, and explicit scan authorization.","date":"2026-08-14","objectID":"/docs/configuration/windows-deployment/","tags":null,"title":"Windows Deployment for OTserver Otter","uri":"/docs/configuration/windows-deployment/"},{"categories":null,"collections":null,"content":"Prerequisites Use Windows 10 or newer. Download otserver-otter.exe from a tested Otter release into a dedicated directory. Keep otter.json beside the executable and restrict access to it because it can contain scan and upload credentials. W","date":"2026-08-14","objectID":"/docs/configuration/windows-deployment/:1:0","tags":null,"title":"Windows Deployment for OTserver Otter","uri":"/docs/configuration/windows-deployment/#prerequisites"},{"categories":null,"collections":null,"content":"Inspect the scanner From the directory containing the downloaded executable, run: .\\otserver-otter.exe --version .\\otserver-otter.exe doctor .\\otserver-otter.exe interfaces Confirm that doctor reports the Npcap active PROFINET backend as av","date":"2026-08-14","objectID":"/docs/configuration/windows-deployment/:2:0","tags":null,"title":"Windows Deployment for OTserver Otter","uri":"/docs/configuration/windows-deployment/#inspect-the-scanner"},{"categories":null,"collections":null,"content":"Windows scan .\\otserver-otter.exe scan ` --target 192.168.1.0/24 ` --interface \u0026#39;\u0026lt;interface name or GUID\u0026gt;\u0026#39; ` --source-mac 00:11:22:33:44:55 ` --output .\\scan.otserver.json ` --ack-authorized Replace the example target, interfac","date":"2026-08-14","objectID":"/docs/configuration/windows-deployment/:3:0","tags":null,"title":"Windows Deployment for OTserver Otter","uri":"/docs/configuration/windows-deployment/#windows-scan"},{"categories":null,"collections":null,"content":"Verify the result .\\otserver-otter.exe validate .\\scan.otserver.json Inspect the export warnings before importing. Scan exit code 0 means all configured scans completed, 2 means at least one valid output is partial, and 1 means a configurat","date":"2026-08-14","objectID":"/docs/configuration/windows-deployment/:4:0","tags":null,"title":"Windows Deployment for OTserver Otter","uri":"/docs/configuration/windows-deployment/#verify-the-result"},{"categories":null,"collections":null,"content":"Impressum und Datenschutzerklärung von OTserver.","date":"0001-01-01","objectID":"/legal/","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/"},{"categories":null,"collections":null,"content":"Impressum ","date":"0001-01-01","objectID":"/legal/:0:0","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#impressum"},{"categories":null,"collections":null,"content":"Angaben gemäß § 5 DDG Rüveyda Celebi Auf der Toeterloeh 23 33100 Paderborn ","date":"0001-01-01","objectID":"/legal/:1:0","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#angaben-gemäß--5-ddg"},{"categories":null,"collections":null,"content":"Kontakt E-Mail: contact@otserver.org ","date":"0001-01-01","objectID":"/legal/:2:0","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#kontakt"},{"categories":null,"collections":null,"content":"Verantwortlich für den Inhalt nach § 18 Abs. 2 MStV Rüveyda Celebi Auf der Toeterloeh 23 33100 Paderborn ","date":"0001-01-01","objectID":"/legal/:3:0","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#verantwortlich-für-den-inhalt-nach--18-abs-2-mstv"},{"categories":null,"collections":null,"content":"Datenschutzerklärung ","date":"0001-01-01","objectID":"/legal/:0:0","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#datenschutzerklärung"},{"categories":null,"collections":null,"content":"1. Datenschutz auf einen Blick ","date":"0001-01-01","objectID":"/legal/:1:0","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#1-datenschutz-auf-einen-blick"},{"categories":null,"collections":null,"content":"Allgemeine Hinweise Die folgenden Hinweise geben einen einfachen Überblick darüber, was mit Ihren personenbezogenen Daten passiert, wenn Sie diese Website besuchen. Personenbezogene Daten sind alle Daten, mit denen Sie persönlich identifizi","date":"0001-01-01","objectID":"/legal/:1:1","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#allgemeine-hinweise"},{"categories":null,"collections":null,"content":"Datenerfassung auf dieser Website Wer ist verantwortlich für die Datenerfassung auf dieser Website? Die Datenverarbeitung auf dieser Website erfolgt durch die Websitebetreiberin. Deren Kontaktdaten können Sie dem Abschnitt „Hinweis zur vera","date":"0001-01-01","objectID":"/legal/:1:2","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#datenerfassung-auf-dieser-website"},{"categories":null,"collections":null,"content":"2. Hosting ","date":"0001-01-01","objectID":"/legal/:2:0","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#2-hosting"},{"categories":null,"collections":null,"content":"Externes Hosting Diese Website wird bei einem externen Dienstleister gehostet (Hoster). Die personenbezogenen Daten, die auf dieser Website erfasst werden, werden auf den Servern des Hosters gespeichert. Hierbei kann es sich v. a. um IP-Adr","date":"0001-01-01","objectID":"/legal/:2:1","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#externes-hosting"},{"categories":null,"collections":null,"content":"3. Allgemeine Hinweise und Pflichtinformationen ","date":"0001-01-01","objectID":"/legal/:3:0","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#3-allgemeine-hinweise-und-pflichtinformationen"},{"categories":null,"collections":null,"content":"Datenschutz Die Betreiberin dieser Seiten nimmt den Schutz Ihrer persönlichen Daten sehr ernst. Wir behandeln Ihre personenbezogenen Daten vertraulich und entsprechend den gesetzlichen Datenschutzvorschriften sowie dieser Datenschutzerkläru","date":"0001-01-01","objectID":"/legal/:3:1","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#datenschutz"},{"categories":null,"collections":null,"content":"Hinweis zur verantwortlichen Stelle Die verantwortliche Stelle für die Datenverarbeitung auf dieser Website ist: Rüveyda Celebi Auf der Toeterloeh 23 33100 Paderborn E-Mail: contact@otserver.org Verantwortliche Stelle ist die natürliche ode","date":"0001-01-01","objectID":"/legal/:3:2","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#hinweis-zur-verantwortlichen-stelle"},{"categories":null,"collections":null,"content":"SSL- bzw. TLS-Verschlüsselung Diese Seite nutzt aus Sicherheitsgründen und zum Schutz der Übertragung vertraulicher Inhalte eine SSL- bzw. TLS-Verschlüsselung. Eine verschlüsselte Verbindung erkennen Sie daran, dass die Adresszeile des Brow","date":"0001-01-01","objectID":"/legal/:3:3","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#ssl--bzw-tls-verschlüsselung"},{"categories":null,"collections":null,"content":"4. Datenerfassung auf dieser Website ","date":"0001-01-01","objectID":"/legal/:4:0","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#4-datenerfassung-auf-dieser-website"},{"categories":null,"collections":null,"content":"Server-Log-Dateien Der Provider der Seiten erhebt und speichert automatisch Informationen in so genannten Server-Log-Dateien, die Ihr Browser automatisch an uns übermittelt. Dies sind in der Regel: Browsertyp und Browserversion verwendetes ","date":"0001-01-01","objectID":"/legal/:4:1","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#server-log-dateien"},{"categories":null,"collections":null,"content":"Vercel Web Analytics Diese Website nutzt Vercel Web Analytics, einen Analysedienst des Hosters Vercel Inc. (Adresse siehe oben). Vercel Web Analytics erfasst aggregierte Nutzungsdaten (z. B. aufgerufene Seiten, Herkunftsland, verwendeter Br","date":"0001-01-01","objectID":"/legal/:4:2","tags":null,"title":"Impressum \u0026 Datenschutz","uri":"/legal/#vercel-web-analytics"},{"categories":null,"collections":null,"content":"Site-scoped industrial asset inventory, evidence-aware merging, read-only discovery, search, and an immutable audit trail.","date":"0001-01-01","objectID":"/features/","tags":null,"title":"Industrial asset management built around trustworthy evidence","uri":"/features/"},{"categories":null,"collections":null,"content":"OTserver keeps discovery evidence, human decisions, and access boundaries together in one self-hosted inventory. ","date":"0001-01-01","objectID":"/features/:0:0","tags":null,"title":"Industrial asset management built around trustworthy evidence","uri":"/features/#"},{"categories":null,"collections":null,"content":"Inventory that survives network changes Every asset is identified by its normalized MAC address, not an IP address, device name, or serial number. Records without a usable MAC are skipped instead of being attached to the wrong device. Track","date":"0001-01-01","objectID":"/features/:1:0","tags":null,"title":"Industrial asset management built around trustworthy evidence","uri":"/features/#inventory-that-survives-network-changes"},{"categories":null,"collections":null,"content":"Evidence-aware imports OTserver accepts three discovery formats: Source Format What it preserves OTserver Otter Schema-version-2 JSON Observations, interfaces, ports, topology, warnings, and field quality Siemens PRONETA XML topology export","date":"0001-01-01","objectID":"/features/:2:0","tags":null,"title":"Industrial asset management built around trustworthy evidence","uri":"/features/#evidence-aware-imports"},{"categories":null,"collections":null,"content":"Network topology Inspect the selected site\u0026rsquo;s assets and connections in the network topology view. Solid links show recorded connections; dotted links distinguish inferred membership. ","date":"0001-01-01","objectID":"/features/:3:0","tags":null,"title":"Industrial asset management built around trustworthy evidence","uri":"/features/#network-topology"},{"categories":null,"collections":null,"content":"Sites, roles, and accountability Build a hierarchy with the site types and depth your organization uses. Grant users read-only or read/write permission at any site; access applies to its descendants. The protected Admin role retains unrestr","date":"0001-01-01","objectID":"/features/:4:0","tags":null,"title":"Industrial asset management built around trustworthy evidence","uri":"/features/#sites-roles-and-accountability"},{"categories":null,"collections":null,"content":"Native read-only discovery The scanner is called OTserver Otter — a Rust CLI and GUI that runs on Windows, Linux, and headless AArch64 Linux and exports evidence directly for OTserver. It uses fixed identity requests and does not perform co","date":"0001-01-01","objectID":"/features/:5:0","tags":null,"title":"Industrial asset management built around trustworthy evidence","uri":"/features/#native-read-only-discovery"},{"categories":null,"collections":null,"content":"OTserver Enterprise is coming soon. Contact us to register your interest.","date":"0001-01-01","objectID":"/enterprise/","tags":null,"title":"OTserver Enterprise","uri":"/enterprise/"},{"categories":null,"collections":null,"content":"OTserver Enterprise is coming soon. ","date":"0001-01-01","objectID":"/enterprise/:0:0","tags":null,"title":"OTserver Enterprise","uri":"/enterprise/#"},{"categories":null,"collections":null,"content":"Licensing The OTserver asset-management web application and OTserver Otter, the discovery scanner, are dual-licensed. Otter and all detection needed to find assets and device capabilities will remain 100% open source under AGPLv3. The base ","date":"0001-01-01","objectID":"/enterprise/:1:0","tags":null,"title":"OTserver Enterprise","uri":"/enterprise/#licensing"},{"categories":null,"collections":null,"content":"Configure and automate OTserver Otter, the Windows and Linux read-only industrial discovery scanner for OTserver.","date":"0001-01-01","objectID":"/scanner/","tags":null,"title":"OTserver Otter: Read-only industrial discovery for OTserver","uri":"/scanner/"},{"categories":null,"collections":null,"content":"OTserver\u0026rsquo;s scanner is called OTserver Otter. Like an otter diving beneath the surface to retrieve what is hidden, Otter dives into the industrial network, identifies the devices living there, and brings the evidence back to the surfac","date":"0001-01-01","objectID":"/scanner/:0:0","tags":null,"title":"OTserver Otter: Read-only industrial discovery for OTserver","uri":"/scanner/#"},{"categories":null,"collections":null,"content":"Windows Windows uses native IP Helper for active ARP. Active PROFINET discovery uses separately installed Npcap; Microsoft pktmon provides a passive fallback that requires Administrator rights and cannot transmit DCP Identify. Driver instal","date":"0001-01-01","objectID":"/scanner/:1:0","tags":null,"title":"OTserver Otter: Read-only industrial discovery for OTserver","uri":"/scanner/#windows"},{"categories":null,"collections":null,"content":"Store the complete setup in otter.json Place otter.json beside otserver-otter.exe on Windows or the otserver-otter binary on Linux. The GUI saves changes to this file and the CLI loads it automatically, so a fully configured scan only needs","date":"0001-01-01","objectID":"/scanner/:2:0","tags":null,"title":"OTserver Otter: Read-only industrial discovery for OTserver","uri":"/scanner/#store-the-complete-setup-in-otterjson"},{"categories":null,"collections":null,"content":"Linux Linux Ethernet discovery uses a native AF_PACKET raw socket and needs root or CAP_NET_RAW. cargo build --locked --release sudo ./target/release/otserver-otter doctor sudo ./target/release/otserver-otter interfaces sudo ./target/releas","date":"0001-01-01","objectID":"/scanner/:3:0","tags":null,"title":"OTserver Otter: Read-only industrial discovery for OTserver","uri":"/scanner/#linux"},{"categories":null,"collections":null,"content":"Safety and credentials Otter does not perform configuration writes, SNMP SET, DCP Set, brute force, exploits, vulnerability scripts, or Modbus requests. Disable individual discovery protocols with their no* JSON settings or --no-* CLI flags","date":"0001-01-01","objectID":"/scanner/:4:0","tags":null,"title":"OTserver Otter: Read-only industrial discovery for OTserver","uri":"/scanner/#safety-and-credentials"},{"categories":null,"collections":null,"content":"Validate and import otserver-otter validate ./scan.otserver.json Exit code 0 means every configuration completed, 2 means at least one valid output is partial, and 1 means a configuration, scan, validation, or upload failed. Multi-configura","date":"0001-01-01","objectID":"/scanner/:5:0","tags":null,"title":"OTserver Otter: Read-only industrial discovery for OTserver","uri":"/scanner/#validate-and-import"},{"categories":null,"collections":null,"content":"Schedule automatic scans Only automate scans for networks your organization continuously owns or is authorized to assess. Keep --ack-authorized in the scheduled command as the explicit record of that authorization. ","date":"0001-01-01","objectID":"/scanner/:6:0","tags":null,"title":"OTserver Otter: Read-only industrial discovery for OTserver","uri":"/scanner/#schedule-automatic-scans"},{"categories":null,"collections":null,"content":"Windows: Task Scheduler with PowerShell Otter runs the configured entries sequentially and exits, so use Windows Task Scheduler rather than a service wrapper. Run this PowerShell as Administrator to execute Otter every day at 02:00 under th","date":"0001-01-01","objectID":"/scanner/:6:1","tags":null,"title":"OTserver Otter: Read-only industrial discovery for OTserver","uri":"/scanner/#windows-task-scheduler-with-powershell"},{"categories":null,"collections":null,"content":"Linux: systemd service and timer This example assumes the binary and otter.json are in /opt/otserver-otter, the service runs as otserver-otter, and the configured output path is writable by that user. Create /etc/systemd/system/otserver-ott","date":"0001-01-01","objectID":"/scanner/:6:2","tags":null,"title":"OTserver Otter: Read-only industrial discovery for OTserver","uri":"/scanner/#linux-systemd-service-and-timer"},{"categories":null,"collections":null,"content":"Source code OTserver Otter and the canonical otserver-scan export contract are developed in the open: OTserver Otter (scanner): github.com/ruveydac/otserver-otter OTserver (asset-management application): github.com/ruveydac/OTserver Set up ","date":"0001-01-01","objectID":"/scanner/:7:0","tags":null,"title":"OTserver Otter: Read-only industrial discovery for OTserver","uri":"/scanner/#source-code"}]