OT/ICS Detection & Response Platform

Secure the systems that keep the world running

OTDefend unifies passive network monitoring, a featherweight Windows endpoint agent, integrated threat intelligence and vendor-neutral response — full OT/ICS visibility, detection and protection, from a single PLC to a multi-site, high-availability deployment.

Windows XP → 11 endpoint agent Data-diode ready sensors Multi-tenant & high availability
https://otdefend.console / dashboard

Security Overview

OperationalA
Assets
1,284
Open Alerts
23
Critical
4
OT Traffic
68%
Threat Landscape 30d
142 EVENTS
  • Zone violation 48
  • Dangerous cmd 37
  • New talker 31
  • CTI match 26
Assets by Purdue Level
L3 · Operations
L2 · Supervisory
L1 · Control
L0 · Field
Recent Alerts
SeverityDetectionSource → DestProtocol
CriticalPLC program download10.4.1.22 → 10.4.0.9S7comm
HighCross-zone write10.7.2.5 → 10.4.1.30Modbus
MediumUnexpected new talker10.4.1.40 → 10.4.1.11DNP3
Real-time detectionATT&CK for ICS tagged

Integrates with the security stack you already run

Splunk
IBM QRadar
CrowdStrike
Microsoft Defender
SentinelOne
Fortinet FortiGate
Palo Alto Networks
Check Point
ServiceNow
Atlassian Jira
The platform

Everything OT security needs — in one platform

Network, endpoint, intelligence and response, unified — and engineered to be safe on live process networks.

Passive Network IDS

Pure-passive deep packet inspection of 16+ industrial protocols from a mirror/TAP port — never injects traffic, safe on live process networks.

Windows XP → 11

Endpoint Agent

A dependency-free ~8–11 KB Windows agent runs from XP to 11 — no driver, no reboot. Edge inventory plus a host-IDS streaming new processes, ports and persistence.

CTI

Integrated Threat Intelligence

Built-in CTI store with TAXII 2.1 / STIX 2.1 feeds matches live traffic — IPs, domains, JA3 fingerprints and file hashes — and alerts on a hit.

IDS + Sigma + YARA

Three detection formats in one engine: network IDS signatures, Sigma analytics (host & network) and YARA malware signatures — 688 rules shipped.

Vulnerability Management

Passive CVE / ICS-CERT matching with exposure-weighted prioritization (CVSS × Purdue × KEV) and a full remediation lifecycle.

Multi-Tenant

Strict, server-enforced per-tenant isolation with sites and role-based access — one platform for many plants, customers or business units.

High Availability

Active/standby core with warm failover, so monitoring and detection keep running through a node loss or maintenance window.

Air-gap

Data-Diode Sensors

One-way, sequence-numbered sensor uplink with forward-error-correction — collect from diode-protected, air-gapped segments that have no return path.

Vendor-Neutral Response

One "Contain" blocks an attacker at FortiGate / PAN / Check Point and isolates hosts on CrowdStrike / Defender / SentinelOne / Cortex — explicit and reversible.

Offline · Air-gap

AI OT Analyst

An offline AI analyst explains every alarm, suggests an OT-safe response and answers asset questions — a local model with zero data egress, safe for air-gapped sites.

Physics-aware

Process Safety Envelopes

Engineer-defined hard limits — min/max and rate-of-change per controller register — catch protocol-valid but physically dangerous commands: the TRITON / Stuxnet class.

Prove it

Live Attack Simulation

Inject Industroyer2, TRITON or BlackEnergy into an isolated engine and watch real alarms and ATT&CK techniques fire on your live stream — one click, instantly cleared.

Endpoint agent

Security for hosts the wire can't see

Some OT hosts can't be watched passively. OTDefend ships a tiny, install-free Windows agent — under ~11 KB, linking only built-in system libraries — that runs from Windows XP through Windows 11 with no .NET, no driver and no reboot.

  • Edge inventory

    Collects host details, neighbours, listening ports and processes — write a file for offline upload, or send straight to the console.

  • Host intrusion detection

    Runs persistently to stream new process executions, listening ports and persistence entries — evaluated by host Sigma rules in the core.

  • Tiny & safe on legacy OT

    No runtime dependencies and a dedicated legacy-TLS upload path, so even XP-era HMIs are covered without risk.

https://otdefend.console / sensors / endpoint-agent

Endpoint Agent

Windows XP → 11
agent-x86.exe
Windows XP+ · ~9 KB
agent-x64.exe
Windows 7 → 11 · ~11 KB
Host-IDS Alerts via Sigma
SeverityDetectionSource
CriticalCredential dumping (LSASS access)process
HighLOLBin: certutil remote downloadprocess
MediumNew persistence — Run keyregistry
MediumNew listening port 4444port
OT / ICS NETWORK SOC / ENTERPRISE one-way SPAN / TAP Sensor AF_XDP Sensor Data-Diode Sensor Endpoint Agents · XP→11 OTDefend Core Standby · HA Console · Multi-tenant SIEM / EDR / Firewall Compliance · Reports
Architecture

Distributed sensors, one central brain

Lightweight sensors collect at the edge and stream normalized events to a central core that analyzes, stores and serves the console. The same pipeline scales from one appliance to a federated, multi-site deployment.

  • Flexible capture

    Live AF_PACKET (incl. multi-queue fanout), AF_XDP zero-copy, SPAN/RSPAN/ERSPAN decapsulation and PCAP replay — or all-in-one, with the core capturing on its own NICs, no separate sensor.

  • Resilient transports

    HTTP store-and-forward, NATS JetStream, mTLS enrollment, or a one-way UDP path for true data-diode segments.

  • Scales out, durably

    Multi-tenant isolation, an HA core and multi-site federation — backed by durable PostgreSQL/TimescaleDB, ClickHouse or OpenSearch event stores.

  • Deploy anywhere

    Offline Docker bundle, .deb sensor or a hardened, bootable appliance ISO — with a performance proof pack (EPS, peak and storage projections) for clean sizing.

See your network

A live map of every device and conversation

OTDefend learns your entire industrial network from observed traffic and renders it as a live, interactive map — relational, Purdue-zoned and inventory views, with cross-zone violations highlighted instantly.

  • Force-directed relational view

    Device-type icons coloured by health, animated flow edges, and per-flow detail on hover.

  • Purdue (virtual zones)

    Devices placed in their level (L0–L5) with observed connections and live zone-violation markers.

  • CVE roll-ups per zone

    Inventory grouped by zone with vulnerability exposure surfaced where it matters.

More on the platform
https://otdefend.console / network-map

Network Map · Purdue Zones

RelationalPurdue
L4 · Enterprise L3 · Operations L2 · Supervisory L1/L0 · Control & Field ERP Jump host Historian SCADA HMI-1 EWS HMI-2 PLC-1 PLC-2 RTU-1 RTU-2
Zone violationL4 → L1 direct
https://otdefend.console / detection

ATT&CK for ICS — Coverage

16 OT protocols
Technique coverage heatmap replay-verified
Deep Packet Inspection
Modbus/TCPFC16 · write multiple
S7commPLC program download
DNP3Cold restart
IEC-104C_SC · single command
OPC UAWrite · 12 nodes
Detection Content
Network IDS signatures 484
Sigma analytics 90
YARA signatures 71
Engine OT pack 43
Detection engine

Threats caught at the protocol level

OTDefend's pure-Go engine reads industrial protocols on the wire — classifying read, write, program, firmware and start/stop intent — and ships a maintained, license-clean content set validated against the real engines.

  • 16+ OT protocols, natively parsed

    Modbus (TCP & RTU), S7comm, DNP3, EtherNet/IP, IEC-104, IEC 61850, PROFINET, EtherCAT, POWERLINK, CC-Link IE, OPC UA, BACnet, FINS, MELSEC, HART-IP and more.

  • Behaviour, baseline & ML analytics

    New-talker, out-of-range process variables, blind state changes and off-cadence anomalies, learned from a baseline — with an optional unsupervised ML anomaly sidecar.

  • Replay-verified — and prove it live

    Real attack scenarios (Industroyer2, TRITON, BlackEnergy) replay-verify ATT&CK coverage — and inject safely into an isolated engine for an on-demand, live demo.

16+
OT protocols inspected
688
IDS · Sigma · YARA rules
XP→11
Windows endpoint agent
3
Compliance frameworks
Sectors

Protection tuned to your industry

Specialized solutions for the critical infrastructure that can't afford downtime.

Customer voices

Trusted by industrial security teams

"OTDefend lifted the security of our industrial systems to the next level — easy to use and quick to integrate with what we already run."

EU
Head of OT SecurityRegional Energy Utility

"Being able to visually monitor our network topology and catch threats early has made it indispensable to our operations team."

MF
CISODiscrete Manufacturer

"The reporting makes preparing the security briefings we present to the board dramatically faster and clearer."

OG
Security DirectorOil & Gas Operator

See OTDefend on your network

Book a personalized demo and watch OTDefend discover assets, map your network and surface threats — passively, in minutes.