Resources · Scenarios
Three incidents, start to finish.
Illustrative scenarios built from the attack patterns the platform is designed for. They are not customer stories, and the names and values are invented.
Scenario Water & wastewater
An off-hours setpoint write to a dosing PLC
At 02:34 an engineering workstation writes a new value to a holding register on the chlorine dosing PLC. The value is above anything seen during normal operation.
- Protocol anomaly detection flags a first-seen value at an off-hours time and opens an incident.
- The analyst opens the case with the decoded write, the register’s tag name from the PLC project and the process curve around it.
- Retro-hunt over the recorded traffic finds two earlier writes from the same workstation.
- A remediation card proposes blocking the workstation on TCP/502 to three PLCs; the shift manager approves; the network team applies the exported rule.
- The incident closes with a signed evidence pack and a five-year retention record.
protocol_anomaly HIGH tag Cl2_Dose_SP src EWS-02 → PLC-07 fc 06 40001 ← 4000 retro-hunt 2 earlier matches pending review RC-118 deny EWS-02 → PLC-03/05/07 tcp/502 status approved by shift manager
Scenario Manufacturing
A program download that doesn’t match the approved project
During a weekday shift, a ControlLogix controller on a packaging line receives a program download. No change request is open for that line.
- The download is matched against the approved project baseline. One routine differs.
- The block-level diff shows a new write to the emergency-stop interlock tag.
- Config-drift detection classifies it as a safety-tag write (Tier 1) and fuses it with the live-traffic alert on the same controller.
- The OT action card gives the on-call engineer a five-question checklist to confirm whether the change was planned.
- The engineer rejects the change, the previous baseline stays active, and the conduit violation is signed for the audit file.
program download PLC-L3-01 routine MainSafety + OTE EStop_Interlock SAFETY_TAG_WRITE TIER_1 baseline Line3_Packaging.L5X v4 (approved) maintenance window none decision rejected · baseline v4 stays active
Scenario Airports & buildings
A contractor laptop reaching building controllers
The corporate SIEM reports a new laptop connecting to the building-automation network. A minute later, BACnet write requests reach HVAC controllers.
- IT-OT lateral movement correlation checks the laptop against authorised engineering workstations and maintenance windows. Neither matches.
- The asset register marks the laptop as shadow, then rogue after analyst review.
- The zones-and-conduits verifier records a signed violation: IT office zone to building-control zone with no declared conduit.
- A remediation card recommends an additive deny rule on the building firewall, exported as CSV for the facility vendor.
- A vendor-safe evidence pack with scrambled addresses is shared with the building-automation contractor.
lateral_movement verdict: unauthorised asset 10.4.20.17 shadow → rogue violation CV-0077 Zone IT-Office → Zone BMS signed Ed25519 export CSV for FW-BMS-01 evidence pack sanitised: vendor
Want to see these run live?
We replay attack captures through the full product in a walkthrough, or on your own PCAPs during an evaluation.