New · Wire DVR with time-travel retro-hunt: rewind the plant network to the second it mattered →
SYNAPTIC OT Secure · Monitor · Protect

Monitor · Asset Intelligence & Vulnerabilities

An asset register that notices when the plant changes.

Synaptic OT reconciles what it sees on the wire with what your engineering files and inventory say should be there. New, unknown and missing devices surface on their own, each with its vulnerabilities attached.

Why it matters

Find the device nobody declared

Every asset carries a state: verified, shadow, under review, rogue or stale. A laptop that appears on a control network shows up as shadow until someone accounts for it.

Patch what matters first

Vulnerabilities are matched against the CISA CSAF catalogue and tracked against SLAs, so the team works the list in order of real exposure.

One inventory for IT and OT views

Fingerprints, Purdue levels and observed connections feed the same register the topology map and the auditor pack read from.

Asset register entries
PLC-07     verified     Rockwell 1756-L83E  fw 33.011   L1
EWS-02     verified     Windows 10 LTSC                L2
10.0.4.19  shadow       first seen 02:11  no project match
HMI-03     stale        last traffic 41 days ago

Illustrative values

Capabilities

What's included

Asset Intelligence & Vulnerabilities is part of the full Synaptic OT suite. One licence covers every capability on this site.

01

Five-state asset lifecycle

Verified, shadow, under review, rogue and stale, with role-checked transitions and a full history of who changed what and why.

02

Passive fingerprinting

Vendor, model, firmware, MAC and Purdue level inferred from traffic, with conflict detection when sources disagree.

03

CVE correlation

Matched against 12,022 CVEs from 3,854 CISA CSAF advisories, shipped offline and updatable by secure package.

04

Vulnerability SLA tracking

Due dates and breaches per asset and per team, visible to managers and executives.

05

Observed topology

An interactive map of who actually talks to whom, layered by Purdue level.

06

Suggested assets

An address that keeps appearing across incidents but is not in the register is proposed as a new asset for a person to approve.

Questions

Asked by OT and security teams

Do we have to scan the network to build the inventory?

No. The register is built from passive traffic, your engineering project files and existing inventory exports. Nothing is scanned.

How do you count licensed assets?

Real devices only: PLCs, RTUs, workstations, servers, switches and controllers. Integrations such as your SIEM or ticketing system never count.

See it on your own traffic.

Request an evaluation licence and run Synaptic OT on a mirror port or a PCAP from your plant. Fully offline if you need it to be.