By RUGERO Tesla (@404Saint).
I approached this research with the same general workflow I have used for the other industrial protocols in my lab. Start with the architecture, identify a usable implementation, reproduce the visible protocol behavior, inspect the traffic, and then move toward security-relevant experiments. PROFINET made that process more complicated than I expected.
The first challenge was getting the laboratory into a useful state. I spent a considerable amount of time working through Linux namespaces, virtual interfaces, routing, and the behavior of the available open-source implementation. Once the environment was working, the next challenge appeared: some parts of PROFINET were easy to observe, while other parts depended on controller/device behavior that the available stack did not fully expose. That changed the shape of the research.
I could still examine discovery, application-relation traffic, cyclic Real-Time framing, and crafted Layer 2 inputs. I simply had to be more careful about what each experiment actually established.
The goal of this project became straightforward:






