Monitor · OT Network Monitoring & IDS
An IDS that reads Modbus the way your engineers do.
A write to holding register 40001 is a setpoint change, not a TCP payload. Synaptic OT decodes eight OT protocols passively and runs three deterministic detection layers, so an alert always comes with a reason you can check.
Why it matters
Nothing touches the controllers
Synaptic OT only listens on a SPAN port, TAP or PCAP. Active PLC drivers are blocked from the product by an automated code gate, so it can never query or crash a fragile device.
Alerts you can explain to an auditor
Detection is rule-based and repeatable. Each alert states which layer fired and why, from a first-seen function code to a match against a documented real-world attack.
Known and unknown attacks
Baseline anomaly detection catches what has never been seen before. Corpus correlation and protocol rules confirm known tradecraft with high precision.
protocol_anomaly HIGH
modbus/tcp fc=06 write_single_register
src 10.0.0.55 EWS-02 dst 10.0.0.107:502 PLC-07
register 40001 value 4000 baseline 3200–3450
reasons first_seen_value · off_hours (02:34) Illustrative values
Capabilities
What's included
OT Network Monitoring & IDS is part of the full Synaptic OT suite. One licence covers every capability on this site.
Eight native dissectors
Modbus TCP, DNP3, OPC UA (wire and audit log), IEC 60870-5-104, Siemens S7comm, MQTT, BACnet/IP and EtherNet/IP, decoded down to function codes, objects and registers.
Protocol anomaly layer
Learns a baseline per protocol, segment and asset, then flags new talkers, first-seen function codes or values, statistical outliers and off-hours activity.
CyOTE correlation layer
Matches observables against 27 documented OT incidents from the Idaho National Laboratory CyOTE corpus: 6,076 observables mapped to 71 MITRE ATT&CK for ICS techniques.
Protocol compliance layer
Flags specification violations such as reserved function codes, broadcast writes and unauthorised commands. Documented operational exceptions can be suppressed per asset.
ATT&CK for ICS coverage
A live coverage matrix shows which ICS techniques your detections cover, with export to MITRE ATT&CK Navigator.
Process-aware context
Process values carried in Modbus and DNP3 traffic are extracted into curves, so an analyst sees what the physical process was doing when the alert fired.
Questions
Asked by OT and security teams
Does Synaptic OT need agents on PLCs or HMIs?
No. It works entirely from mirrored network traffic (SPAN or TAP) and from project files you upload. Nothing is installed on controllers.
Does it ever send traffic to OT devices?
No. The product contains no active PLC drivers, and an automated check in the build blocks any dependency that would open a connection to a device.
Is AI used to decide what is an attack?
No. All three detection layers are deterministic. AI is used only afterwards to write a plain-language summary, and it cannot change an alert or its severity.
Works with
See it on your own traffic.
Request an evaluation licence and run Synaptic OT on a mirror port or a PCAP from your plant. Fully offline if you need it to be.