OTDefend unifies passive network monitoring, a featherweight Windows endpoint agent, integrated threat intelligence and vendor-neutral response — full OT/ICS visibility, detection and protection, from a single PLC to a multi-site, high-availability deployment.
Windows XP → 11 endpoint agent Data-diode ready sensors Multi-tenant & high availability
https://otdefend.console / dashboard
Security Overview
OperationalA
Assets
1,284
Open Alerts
23 ▲
Critical
4
OT Traffic
68%
Threat Landscape 30d
Zone violation 48
Dangerous cmd 37
New talker 31
CTI match 26
Assets by Purdue Level
L3 · Operations
L2 · Supervisory
L1 · Control
L0 · Field
Recent Alerts
Severity
Detection
Source → Dest
Protocol
Critical
PLC program download
10.4.1.22 → 10.4.0.9
S7comm
High
Cross-zone write
10.7.2.5 → 10.4.1.30
Modbus
Medium
Unexpected new talker
10.4.1.40 → 10.4.1.11
DNP3
Real-time detectionATT&CK for ICS tagged
Integrates with the security stack you already run
The platform
Everything OT security needs — in one platform
Network, endpoint, intelligence and response, unified — and engineered to be safe on live process networks.
Passive Network IDS
Pure-passive deep packet inspection of 16+ industrial protocols from a mirror/TAP port — never injects traffic, safe on live process networks.
Windows XP → 11
Endpoint Agent
A dependency-free ~8–11 KB Windows agent runs from XP to 11 — no driver, no reboot. Edge inventory plus a host-IDS streaming new processes, ports and persistence.
CTI
Integrated Threat Intelligence
Built-in CTI store with TAXII 2.1 / STIX 2.1 feeds matches live traffic — IPs, domains, JA3 fingerprints and file hashes — and alerts on a hit.
IDS + Sigma + YARA
Three detection formats in one engine: network IDS signatures, Sigma analytics (host & network) and YARA malware signatures — 688 rules shipped.
Vulnerability Management
Passive CVE / ICS-CERT matching with exposure-weighted prioritization (CVSS × Purdue × KEV) and a full remediation lifecycle.
Multi-Tenant
Strict, server-enforced per-tenant isolation with sites and role-based access — one platform for many plants, customers or business units.
High Availability
Active/standby core with warm failover, so monitoring and detection keep running through a node loss or maintenance window.
Air-gap
Data-Diode Sensors
One-way, sequence-numbered sensor uplink with forward-error-correction — collect from diode-protected, air-gapped segments that have no return path.
Vendor-Neutral Response
One "Contain" blocks an attacker at FortiGate / PAN / Check Point and isolates hosts on CrowdStrike / Defender / SentinelOne / Cortex — explicit and reversible.
Offline · Air-gap
AI OT Analyst
An offline AI analyst explains every alarm, suggests an OT-safe response and answers asset questions — a local model with zero data egress, safe for air-gapped sites.
Physics-aware
Process Safety Envelopes
Engineer-defined hard limits — min/max and rate-of-change per controller register — catch protocol-valid but physically dangerous commands: the TRITON / Stuxnet class.
Prove it
Live Attack Simulation
Inject Industroyer2, TRITON or BlackEnergy into an isolated engine and watch real alarms and ATT&CK techniques fire on your live stream — one click, instantly cleared.
Endpoint agent
Security for hosts the wire can't see
Some OT hosts can't be watched passively. OTDefend ships a tiny, install-free Windows agent — under ~11 KB, linking only built-in system libraries — that runs from Windows XP through Windows 11 with no .NET, no driver and no reboot.
Edge inventory
Collects host details, neighbours, listening ports and processes — write a file for offline upload, or send straight to the console.
Host intrusion detection
Runs persistently to stream new process executions, listening ports and persistence entries — evaluated by host Sigma rules in the core.
Tiny & safe on legacy OT
No runtime dependencies and a dedicated legacy-TLS upload path, so even XP-era HMIs are covered without risk.
Lightweight sensors collect at the edge and stream normalized events to a central core that analyzes, stores and serves the console. The same pipeline scales from one appliance to a federated, multi-site deployment.
Flexible capture
Live AF_PACKET (incl. multi-queue fanout), AF_XDP zero-copy, SPAN/RSPAN/ERSPAN decapsulation and PCAP replay — or all-in-one, with the core capturing on its own NICs, no separate sensor.
Resilient transports
HTTP store-and-forward, NATS JetStream, mTLS enrollment, or a one-way UDP path for true data-diode segments.
Scales out, durably
Multi-tenant isolation, an HA core and multi-site federation — backed by durable PostgreSQL/TimescaleDB, ClickHouse or OpenSearch event stores.
Deploy anywhere
Offline Docker bundle, .deb sensor or a hardened, bootable appliance ISO — with a performance proof pack (EPS, peak and storage projections) for clean sizing.
See your network
A live map of every device and conversation
OTDefend learns your entire industrial network from observed traffic and renders it as a live, interactive map — relational, Purdue-zoned and inventory views, with cross-zone violations highlighted instantly.
Force-directed relational view
Device-type icons coloured by health, animated flow edges, and per-flow detail on hover.
Purdue (virtual zones)
Devices placed in their level (L0–L5) with observed connections and live zone-violation markers.
CVE roll-ups per zone
Inventory grouped by zone with vulnerability exposure surfaced where it matters.
OTDefend's pure-Go engine reads industrial protocols on the wire — classifying read, write, program, firmware and start/stop intent — and ships a maintained, license-clean content set validated against the real engines.
New-talker, out-of-range process variables, blind state changes and off-cadence anomalies, learned from a baseline — with an optional unsupervised ML anomaly sidecar.
Replay-verified — and prove it live
Real attack scenarios (Industroyer2, TRITON, BlackEnergy) replay-verify ATT&CK coverage — and inject safely into an isolated engine for an on-demand, live demo.
16+
OT protocols inspected
688
IDS · Sigma · YARA rules
XP→11
Windows endpoint agent
3
Compliance frameworks
Sectors
Protection tuned to your industry
Specialized solutions for the critical infrastructure that can't afford downtime.