See every asset. Catch every dangerous command. Show the auditor.
One console for plant IT, OT engineers and the analysts who back them up. Every view is built from passive observation, with no scanning and no agents.
Asset inventory & communication map
Every PLC, HMI, drive and engineering workstation, identified from the traffic it already sends: vendor, model, firmware and who it talks to.
- Identity from S7 SZL, Modbus device ID, EtherNet/IP, PROFINET DCP and BACnet
- Firmware drift and end-of-life list
- Remote-access exposure report
- Risk score weighted by asset criticality
| Asset | Vendor / model | Firmware | Protocol | Risk |
|---|---|---|---|---|
| PLC-Line2 | Siemens S7-1500 | V2.9.4 | S7comm+ | High |
| EWS-02 | Windows 10 workstation | — | RDP · S7 | High |
| PLC-Line1 | Siemens S7-300 | V3.3.17 | S7comm | Med |
| Filler-PLC | Schneider M340 | V3.20 | Modbus | Med |
| HMI-01 | Siemens TP1200 | V17 | S7comm | Low |
| Drive-04 | ABB ACS880 | 3.4 | PROFINET | Low |
Identified passively in 6 h 12 min
Sample data
- Syslog / CEF / LEEF
- Webhooks
- REST API
- Microsoft Sentinel
- Splunk
- Elastic
- Wazuh
Deterministic first.ML second. LLM last.
Most OT tools ask you to trust a model you can’t inspect. Aragog leads with rules you can read, adds learned baselines once there is something to learn from, and uses a language model only to explain what the rules and baselines already found.
- Day 0
Rules
Dangerous operations are flagged from the first minute: CPU stop, program download or upload, writes from new sources, firmware sessions, scans and new remote-access paths. Mapped to MITRE ATT&CK for ICS.
Rule
rule s7.cpu_stop when proto = s7comm and function = 0x29 severity critical attack T0858
- Week 1
Baselines
The cloud learns who talks to whom, with which protocol and function, at what rhythm and within which value ranges. A human then accepts the baseline, so an attacker present during learning isn’t learned as normal.
Learned pair
HMI-01 → PLC-Line2 s7comm read_var 500 ms ± 12 s7comm write_var DB12 2–6/h learned 7 d · accepted
- Week 4
Narratives
Alerts arrive as short narratives grounded in parsed facts, in Italian or English. The language model writes the summary. It never decides what is an attack.
Narrative
At 14:06 EWS-02 sent CPU STOP to PLC-Line2 over S7comm. EWS-02 has not stopped this PLC in the 30-day baseline and no maintenance window is open.
| Week | False alerts per sensor per day |
|---|---|
| 0 | 22 |
| 1 | 17 |
| 2 | 11 |
| 3 | 7 |
| 4 | 4.6 |
| 5 | 3.2 |
| 6 | 1.8 |
| 7 | 1 |
| 8 | 0.7 |
Targets we test against
- < 5
- false alerts per sensor per day after learning
- < 1
- per sensor per day after pilot tuning
- 0
- missed scripted critical attacks in the lab
Put a sensor on one line. See what it finds.
A pilot is a real, passive deployment at one of your sites. Tell us a little about your plant and we will get back to you to scope it.
Passive only. Nothing on your process network changes.