Contact Sales
Contact Sales

ICS Asset Inventory: Passive, or Active? Siemens S7-1200 PLCs

ICS Asset Inventory: Passive, or Active? Siemens S7-1200 PLCs (PDF, 3.50MB)Published: 12 Mar, 2026
Created by:
Justin Wilson

ICS cybersecurity professionals and vendors make conflicting claims about the accuracy and completeness of asset inventory data obtained via passive network traffic analysis vs. active "scanning" of OT assets. Some vendors of OT inventory scanning tools emphasize that passive analysis is the “gold standard” for OT (Korus, 2025). Other professionals contend that more active methods identify “substantially more information than methods that exclusively rely on passive scanning” (Amoresano et al., 2024).

This research builds on previous research to determine what information can and cannot be gleaned solely from passive traffic analysis, specifically for a Siemens S7-1200 PLC. The purpose of this paper is to determine the effectiveness of active versus passive collection of asset inventory information for Siemens S7-1200 PLCs and provide a methodology for conducting similar future research.