Skip to content
Platform

See every asset. Catch every dangerous command. Show the auditor.

One console for plant IT, OT engineers and the analysts who back them up. Every view is built from passive observation, with no scanning and no agents.

MVP

Asset inventory & communication map

Every PLC, HMI, drive and engineering workstation, identified from the traffic it already sends: vendor, model, firmware and who it talks to.

  • Identity from S7 SZL, Modbus device ID, EtherNet/IP, PROFINET DCP and BACnet
  • Firmware drift and end-of-life list
  • Remote-access exposure report
  • Risk score weighted by asset criticality
AssetsPlant 1 · 143 assets
AssetVendor / modelFirmwareProtocolRisk
PLC-Line2Siemens S7-1500V2.9.4S7comm+High
EWS-02Windows 10 workstation—RDP · S7High
PLC-Line1Siemens S7-300V3.3.17S7commMed
Filler-PLCSchneider M340V3.20ModbusMed
HMI-01Siemens TP1200V17S7commLow
Drive-04ABB ACS8803.4PROFINETLow

Identified passively in 6 h 12 min

Sample data

Sends to
  • Syslog / CEF / LEEF
  • Webhooks
  • REST API
  • Microsoft Sentinel
  • Splunk
  • Elastic
  • Wazuh
Detection philosophy

Deterministic first.ML second. LLM last.

Most OT tools ask you to trust a model you can’t inspect. Aragog leads with rules you can read, adds learned baselines once there is something to learn from, and uses a language model only to explain what the rules and baselines already found.

  1. Day 0

    Rules

    Dangerous operations are flagged from the first minute: CPU stop, program download or upload, writes from new sources, firmware sessions, scans and new remote-access paths. Mapped to MITRE ATT&CK for ICS.

    Rule

    rule s7.cpu_stop
      when proto = s7comm
       and function = 0x29
      severity  critical
      attack    T0858
  2. Week 1

    Baselines

    The cloud learns who talks to whom, with which protocol and function, at what rhythm and within which value ranges. A human then accepts the baseline, so an attacker present during learning isn’t learned as normal.

    Learned pair

    HMI-01 → PLC-Line2
      s7comm read_var   500 ms ± 12
      s7comm write_var  DB12  2–6/h
      learned 7 d · accepted
  3. Week 4

    Narratives

    Alerts arrive as short narratives grounded in parsed facts, in Italian or English. The language model writes the summary. It never decides what is an attack.

    Narrative

    At 14:06 EWS-02 sent CPU STOP
    to PLC-Line2 over S7comm. EWS-02
    has not stopped this PLC in the
    30-day baseline and no maintenance
    window is open.
False alerts per sensor per dayTarget curve we test pilots against. Illustrative, not measured data.
Target false alerts per sensor per day, by week
WeekFalse alerts per sensor per day
022
117
211
37
44.6
53.2
61.8
71
80.7

Targets we test against

< 5
false alerts per sensor per day after learning
< 1
per sensor per day after pilot tuning
0
missed scripted critical attacks in the lab

Put a sensor on one line. See what it finds.

A pilot is a real, passive deployment at one of your sites. Tell us a little about your plant and we will get back to you to scope it.

Passive only. Nothing on your process network changes.