Secure · Record · Investigate
Investigate with the full recording, not a summary of it.
A virtual SOC built for small teams covering several plants. Every incident comes with the packets around it, a replayable timeline and evidence you can hand to an auditor.
Virtual SOC
A SOC for every plant, without an analyst at every plant.
Alerts become incidents, incidents become cases, and every case opens with the protocol decode, the asset context and a plain-language summary. Your team spends its time deciding, not assembling.
- Alert to incident to case. Five alert families feed one queue. Tier 1 alerts auto-promote to incidents; Tier 2 waits for an analyst.
- Triage workspace. Protocol decode, asset context (vendor, firmware, Purdue level), baseline at alert time and AI summary on one screen. Confirm, escalate or close as false positive.
- Investigation graph. Attack-chain graph, packet timeline and cross-event correlation, plus blast radius for any proposed action.
- IT-OT lateral movement. SIEM alerts are checked against authorised engineering workstations and maintenance windows, with a clear verdict on each.
INC-0412 Unauthorised register write to PLC-07 Engineering workstation EWS-02 wrote 4000 to register 40001 at 02:34, outside its usual hours and above the learned range. Two earlier writes from the same source were found by retro-hunt. Suggested next step: review remediation card RC-118.
Wire DVR & Forensics
Rewind the plant network to the second it mattered.
Synaptic OT records OT traffic continuously, the way a DVR records a camera. When an incident opens, the minutes around it are locked, indexed and ready to replay, then sealed into evidence anyone can verify offline.
- Rolling capture per sensor. Continuous recording with health monitoring for gaps, packet drops, zero-traffic periods and unclean shutdowns, so you know how complete a recording is.
- Incident-locked clips. A configurable window around every incident is protected from rotation, with a back-chain that follows earlier conversations from the same hosts.
- Per-packet index. Every recorded packet is indexed by address, port, protocol and OT fields such as Modbus unit, function code and value, so searches take seconds.
- State replay. Replay recorded OT events across any window on a timeline, with protocol decode and process values.
evidence-pack/INC-0412
├─ INDEX.json sha-256 per file
├─ pcap/ 02:31:40 – 02:37:10 (sanitised: vendor)
├─ decode.json timeline.json
├─ manifest.json merkle root 9f2c…41ab
└─ manifest.sig Ed25519 · verifies offline Threat Hunting & Retro-Hunt
Learn of a new threat today. Check last month’s traffic for it today.
When a new indicator arrives from your CERT, a vendor advisory or your own investigation, Synaptic OT runs it across recorded traffic. Matches become incidents for review, grouped by hour so the time of the attack is clear.
- Time-travel retro-hunt. Streams across millions of indexed packets in pages, so even large hunts run within bounded memory.
- Review before action. Every match is created as a pending-review incident. Nothing is escalated or blocked automatically.
- Offline threat intelligence. Import IOC and STIX/TAXII bundles by secure package in air-gapped sites, or by allow-listed feed where outbound is permitted.
- Campaign tracking. Related alerts across time and assets are grouped into campaigns that mirror multi-stage OT attacks.
retro-hunt RH-0031 ioc src 10.0.0.55 · tcp/502 · fc in (5, 6, 15, 16) window 14 days of recorded traffic scanned 4.8 M packets matches 2 → INC-0409 (PLC-03), INC-0410 (PLC-05) pending review
See it on your own traffic.
Request an evaluation licence and run Synaptic OT on a mirror port or a PCAP from your plant. Fully offline if you need it to be.