New · Wire DVR with time-travel retro-hunt: rewind the plant network to the second it mattered →
SYNAPTIC OT Secure · Monitor · Protect

Monitor · OT Network Monitoring & IDS

An IDS that reads Modbus the way your engineers do.

A write to holding register 40001 is a setpoint change, not a TCP payload. Synaptic OT decodes eight OT protocols passively and runs three deterministic detection layers, so an alert always comes with a reason you can check.

Why it matters

Nothing touches the controllers

Synaptic OT only listens on a SPAN port, TAP or PCAP. Active PLC drivers are blocked from the product by an automated code gate, so it can never query or crash a fragile device.

Alerts you can explain to an auditor

Detection is rule-based and repeatable. Each alert states which layer fired and why, from a first-seen function code to a match against a documented real-world attack.

Known and unknown attacks

Baseline anomaly detection catches what has never been seen before. Corpus correlation and protocol rules confirm known tradecraft with high precision.

A protocol anomaly alert, as an analyst sees it
protocol_anomaly          HIGH
modbus/tcp  fc=06 write_single_register
src  10.0.0.55  EWS-02      dst  10.0.0.107:502  PLC-07
register  40001  value 4000   baseline 3200–3450
reasons   first_seen_value · off_hours (02:34)

Illustrative values

Capabilities

What's included

OT Network Monitoring & IDS is part of the full Synaptic OT suite. One licence covers every capability on this site.

01

Eight native dissectors

Modbus TCP, DNP3, OPC UA (wire and audit log), IEC 60870-5-104, Siemens S7comm, MQTT, BACnet/IP and EtherNet/IP, decoded down to function codes, objects and registers.

02

Protocol anomaly layer

Learns a baseline per protocol, segment and asset, then flags new talkers, first-seen function codes or values, statistical outliers and off-hours activity.

03

CyOTE correlation layer

Matches observables against 27 documented OT incidents from the Idaho National Laboratory CyOTE corpus: 6,076 observables mapped to 71 MITRE ATT&CK for ICS techniques.

04

Protocol compliance layer

Flags specification violations such as reserved function codes, broadcast writes and unauthorised commands. Documented operational exceptions can be suppressed per asset.

05

ATT&CK for ICS coverage

A live coverage matrix shows which ICS techniques your detections cover, with export to MITRE ATT&CK Navigator.

06

Process-aware context

Process values carried in Modbus and DNP3 traffic are extracted into curves, so an analyst sees what the physical process was doing when the alert fired.

Questions

Asked by OT and security teams

Does Synaptic OT need agents on PLCs or HMIs?

No. It works entirely from mirrored network traffic (SPAN or TAP) and from project files you upload. Nothing is installed on controllers.

Does it ever send traffic to OT devices?

No. The product contains no active PLC drivers, and an automated check in the build blocks any dependency that would open a connection to a device.

Is AI used to decide what is an attack?

No. All three detection layers are deterministic. AI is used only afterwards to write a plain-language summary, and it cannot change an alert or its severity.

See it on your own traffic.

Request an evaluation licence and run Synaptic OT on a mirror port or a PCAP from your plant. Fully offline if you need it to be.