New · Wire DVR with time-travel retro-hunt: rewind the plant network to the second it mattered →
SYNAPTIC OT Secure · Monitor · Protect

OT/ICS security operations · air-gap native

TheSOCthatstaysinsidetheairgap.

Synaptic OT watches your industrial network without touching it, records every packet, and turns an attack into evidence and a firewall rule your team approves. One platform, fully on-premises, for plants that cannot send their data to a cloud.

  • Decoded passively
  • Modbus TCP
  • DNP3
  • OPC UA
  • IEC 60870-5-104
  • Siemens S7comm
  • MQTT
  • BACnet/IP
  • EtherNet/IP
Illustrative scenario
Monitor

A write lands where it shouldn't.

The engineering workstation sends a Modbus FC 06 write to PLC-07 at 02:34, hours outside its normal pattern. Synaptic OT sees it on a mirrored copy of the switch traffic. It never sends a packet to a controller.

modbus/tcp  10.0.0.55 → 10.0.0.107:502
function    06 write single register
register    40001 ← 4000   (baseline 3200–3450)
Monitor

Detected by rule, explained in plain language.

The protocol anomaly layer flags a first-seen value at an off-hours time and opens an incident. The assistant then writes a short explanation for the analyst. It annotates. It never decides.

protocol_anomaly  HIGH
reasons   first_seen_value · off_hours
incident  INC-0412 · playbook matched
summary   Setpoint write from EWS-02 at 02:34,
          above the learned range for PLC-07.
Secure

Rewind the network before you act.

The Wire DVR already holds the traffic. Retro-hunt runs the new indicator across the last fourteen days and finds two earlier writes from the same workstation to PLC-03 and PLC-05. The response now covers three controllers, not one.

retro-hunt  src=10.0.0.55 · tcp/502 · writes
window      14 days of recorded traffic
matches     2 → PLC-03 · PLC-05   pending review
Secure

Evidence you can hand to an auditor.

Packets, decodes and the timeline are sealed into an evidence pack with an Ed25519 signature and a Merkle root. Anyone can verify it offline, with no call back to us.

evidence-pack/INC-0412
├─ pcap/          02:31–02:37
├─ decode.json    timeline.json
├─ manifest.json  sha-256 per file
└─ manifest.sig   Ed25519 · verifies offline
Protect

A person approves. Your team applies it.

The remediation card shows what to block, why, and the blast radius. The shift manager approves it and Synaptic OT exports the rule for FortiOS, Cisco ASA or PAN-OS. Nothing is pushed to a firewall automatically.

# FortiOS · exported, applied by your team
config firewall policy
  edit 0
    set srcaddr "EWS-02"
    set dstaddr "PLC-03" "PLC-05" "PLC-07"
    set service "MODBUS-TCP-502"
    set action deny
  next
end
  • Modbus TCP
  • DNP3
  • OPC UA
  • IEC 60870-5-104
  • Siemens S7comm
  • MQTT
  • BACnet/IP
  • EtherNet/IP
  • Rockwell L5X
  • Rockwell ACD
  • Schneider XEF
  • Schneider ZEF
  • PLCopen XML
  • Siemens IEC 61850 SCD
  • PROFINET GSDML
  • EtherNet/IP EDS
  • AutomationML
  • CSV tag databases
Why now

Attacks have reached the process.

Adversaries now write directly to controllers over plain industrial protocols. Regulators have responded by asking for proof, not intentions: logs, evidence and audit trails that most mid-size plants don't have.

  • NESA / UAE IA
  • NCA OTCC
  • CERT-In
  • NIS2
  • IEC 62443
  • NERC CIP
  1. 2023

    Internet-exposed Unitronics PLCs taken over at US water utilities

    CISA advisory AA23-335A
  2. 2024

    FrostyGoop malware uses Modbus TCP to cut heating to buildings in Lviv, Ukraine

    Disclosed July 2024
  3. 2024

    US agencies warn Volt Typhoon has pre-positioned inside critical infrastructure

    CISA advisory AA24-038A
One platform

From first packet to audit proof.

Most plants buy detection, forensics, response tooling and compliance help separately, then try to make them talk. Synaptic OT does the whole job in one product, in the order an incident actually happens.

8protocols

OT protocols decoded passively

0packets

packets ever sent to your controllers

27incidents

real OT incidents in the detection corpus

71techniques

MITRE ATT&CK for ICS techniques mapped

10formats

engineering project-file formats

7frameworks

compliance frameworks mapped

The suite

Nine capabilities. One licence.

Each pillar is strong enough to stand on its own, and every operator gets all three. Small, mid-size and large plants run the same product, with nothing sold as an add-on.

On the wire

Watch it work.

What the platform does every hour of every shift: decode, detect, record, hunt, seal and hand a decision to a person.

Process-aware detectionA setpoint write far outside the learned range, caught from mirrored traffic.
Protocol anomaly
CyOTE correlation
Protocol compliance
fc=06 write_single_register
reason  first_seen_value
reason  off_hours 02:34
→ incident INC-0412
Three deterministic layersNo AI in the detection path. Every alert says which layer fired.
Wire DVRThe minutes around every incident are locked and indexed.
Time-travel retro-huntNew indicator, old traffic: two earlier matches found.
  • pcap/ 02:31–02:37
  • decode.json
  • timeline.json
  • manifest.json
  • manifest.sig · Ed25519
Signed evidence packsMerkle root and Ed25519 signature. Verifiable offline.
Zones & conduits, verifiedEvery cross-zone flow checked against your IEC 62443 design.
RC-118Awaiting approvalApproved · 03:06

Deny EWS-02 → PLC-03/05/07 on TCP/502

blast radius · 1 hostexport · FortiOS
Approve
A person decidesRules are exported for your team. Nothing is pushed.

Illustrative values

Consolidation

Replace the OT security stack.

Four or five separate purchases plus specialist staff is what OT security costs today. Most mid-size plants cannot fund all of it, so they go without. Synaptic OT gives every operator the full suite.

  • Intrusion detectionToday: An OT IDS sensor licenceSynaptic OT: Passive detection across 8 OT protocols
  • ForensicsToday: An IR retainer or manual PCAP analysisSynaptic OT: Wire DVR, state replay and retro-hunt
  • Engineering change controlToday: Spreadsheets and trustSynaptic OT: Project baselines, logic diff and drift alerts
  • ResponseToday: A SOAR plus hand-written firewall changesSynaptic OT: Playbooks and approved remediation cards
  • Compliance & auditToday: Consultants and screenshots every cycleSynaptic OT: Evidence packs, retention and audit trail
  • SOC operationsToday: Analysts at every plantSynaptic OT: One small team covering several plants
What passive monitors miss

The plant as designed, against the plant as it runs.

Upload the PLC and HMI project files your engineers already export. Synaptic OT turns them into an approved baseline, resolves registers to tag names, and catches logic downloads and connections the design never allowed.

  • Ten formats including Rockwell L5X, Schneider XEF and PLCopen XML
  • Block-level logic diff when a program download doesn't match the baseline
  • One fused alert when the project and the wire disagree
Project files, baselines & drift →
Baseline diff for an unapproved change
project   Line3_Packaging.L5X   v2 vs v1 (active baseline)
+ tag write   EStop_Interlock        SAFETY_TAG_WRITE        TIER_1
+ connection  IT-VLAN → PLC-07        UNAUTHORIZED_PATH       TIER_2
- connection  PLC-07 → Historian      config drift            TIER_4
decision      pending engineering approval
Built for plants

Three commitments we will not trade away.

These are architecture decisions, enforced in code. They are why regulated operators can put Synaptic OT on their control network.

Same product, fully offline

The installer, threat intelligence, AI assistant and licence all work with zero internet. Air gap is the default deployment, not a reduced edition.

We never touch your controllers

Visibility comes from mirrored traffic and project files. Active PLC drivers are blocked from the codebase by an automated check.

No action without a person

Detection is deterministic and explainable. Every response step waits for approval, and firewall rules are applied by your team.

Deployment

From one air-gapped plant to an MSSP.

The same installer and the same features in every tier. Choose the architecture your regulator and network allow; licensing stays the same.

Tier 1

Full air gap

Zero internet. Nothing leaves the site, ever.

  • Installer, threat intelligence, AI assistant and licence all work offline
  • Updates and intelligence arrive by signed offline package
  • Secrets generated on the host at install; no default credentials
  • Optional TPM-backed keys for evidence signing

Built forNuclear, defence, water, government and any site that forbids external connectivity

Industries

Anywhere OT infrastructure runs.

The same platform protects a refinery, a substation and a water district. Already run an OT sensor? Synaptic OT ingests Nozomi and Claroty alerts and adds forensics, response and compliance around them.

See it on your own traffic.

Request an evaluation licence and run Synaptic OT on a mirror port or a PCAP from your plant. Fully offline if you need it to be.