The report includes a general overview of the current situation with SCADA — the largest vendors, vulnerability statistics. The analysis of the main industrial protocols (Modbus, DNP3, S7, PROFINET) is described in details. Some interesting features and vulnerabilities of the protocols are analyzed from the point of view of a pentester. The authors of the report will speak about a protocol analysis technology and about used tools. They will also demonstrate software, developed in the course of their researches. Alexander Timorin graduated from the Mathematics and Mechanics Department of the Ural State University in 2004 (specializing in System Programming). He was engaged in the development of applications for Oracle, of the web configurator of an IP telephony system, and of IBM WebSphere. Now he is the Lead Specialist of the Security Assessment Department at Positive Technologies. Moscow, Russia Dmitry Yefanov graduated from the Institute of Cryptography, Communications and Informatics, Academy of Federal Security Service of Russia in 2006 (specializing in Information Security). Now he is the Head of the Network Application Security Analysis Team at Positive Technologies. Moscow, Russia Alexander Timorin, Dmitry Yefanov Alexander Timorin, Dmitry Yefanov