New · Wire DVR with time-travel retro-hunt: rewind the plant network to the second it mattered →
SYNAPTIC OT Secure · Monitor · Protect

Resources · Scenarios

Three incidents, start to finish.

Illustrative scenarios built from the attack patterns the platform is designed for. They are not customer stories, and the names and values are invented.

Scenario Water & wastewater

An off-hours setpoint write to a dosing PLC

At 02:34 an engineering workstation writes a new value to a holding register on the chlorine dosing PLC. The value is above anything seen during normal operation.

  1. Protocol anomaly detection flags a first-seen value at an off-hours time and opens an incident.
  2. The analyst opens the case with the decoded write, the register’s tag name from the PLC project and the process curve around it.
  3. Retro-hunt over the recorded traffic finds two earlier writes from the same workstation.
  4. A remediation card proposes blocking the workstation on TCP/502 to three PLCs; the shift manager approves; the network team applies the exported rule.
  5. The incident closes with a signed evidence pack and a five-year retention record.
What the team sees
protocol_anomaly  HIGH   tag Cl2_Dose_SP
src EWS-02 → PLC-07  fc 06  40001 ← 4000
retro-hunt  2 earlier matches  pending review
RC-118  deny EWS-02 → PLC-03/05/07 tcp/502
status  approved by shift manager

Scenario Manufacturing

A program download that doesn’t match the approved project

During a weekday shift, a ControlLogix controller on a packaging line receives a program download. No change request is open for that line.

  1. The download is matched against the approved project baseline. One routine differs.
  2. The block-level diff shows a new write to the emergency-stop interlock tag.
  3. Config-drift detection classifies it as a safety-tag write (Tier 1) and fuses it with the live-traffic alert on the same controller.
  4. The OT action card gives the on-call engineer a five-question checklist to confirm whether the change was planned.
  5. The engineer rejects the change, the previous baseline stays active, and the conduit violation is signed for the audit file.
What the team sees
program download  PLC-L3-01  routine MainSafety
+ OTE EStop_Interlock        SAFETY_TAG_WRITE  TIER_1
baseline  Line3_Packaging.L5X v4 (approved)
maintenance window  none
decision  rejected · baseline v4 stays active

Scenario Airports & buildings

A contractor laptop reaching building controllers

The corporate SIEM reports a new laptop connecting to the building-automation network. A minute later, BACnet write requests reach HVAC controllers.

  1. IT-OT lateral movement correlation checks the laptop against authorised engineering workstations and maintenance windows. Neither matches.
  2. The asset register marks the laptop as shadow, then rogue after analyst review.
  3. The zones-and-conduits verifier records a signed violation: IT office zone to building-control zone with no declared conduit.
  4. A remediation card recommends an additive deny rule on the building firewall, exported as CSV for the facility vendor.
  5. A vendor-safe evidence pack with scrambled addresses is shared with the building-automation contractor.
What the team sees
lateral_movement  verdict: unauthorised
asset 10.4.20.17  shadow → rogue
violation CV-0077  Zone IT-Office → Zone BMS  signed Ed25519
export  CSV for FW-BMS-01
evidence pack  sanitised: vendor

Want to see these run live?

We replay attack captures through the full product in a walkthrough, or on your own PCAPs during an evaluation.