Purdue
L0–L5 on the topology board
- Terms on this page match the Edge topology UI.
- Edge = L3 / industrial DMZ.
- Telemetry up. Command into L0–L2: none.

Shared language for CISOs, SOC analysts, and plant engineers evaluating industrial cyber defense.
Purdue

| Protocol | Where it runs | Why it matters to a defender |
|---|---|---|
| Modbus TCP / RTU | Manufacturing, water, building automation | Unauthenticated register writes can change process setpoints. |
| DNP3 | Electric and water utilities | Control commands and unsolicited responses can be spoofed without secure authentication. |
| OPC-UA | Modern IIoT and MES integration | Tag harvesting and session abuse expose process structure to an attacker. |
| MQTT | IIoT sensor fleets and edge gateways | Wildcard subscriptions leak telemetry across zones that should stay isolated. |
| S7comm | Siemens PLC estates | Program upload and download operations are high-impact and rarely monitored. |
| IEC 60870-5-104 | European grid SCADA | Telecontrol commands cross the DMZ with limited native authentication. |
| BACnet | Building automation and facilities OT | Broadcast discovery and unauthenticated writes can affect HVAC and access-control points. |
| EtherNet/IP (CIP) | North American manufacturing and robotics cells | Common Industrial Protocol messages can reconfigure I/O without native authentication. |
PQC

| Level | What lives there | CyberDragon posture |
|---|---|---|
| L0–L1 | Sensors, actuators, PLCs and safety instrumented systems | Never touched. No agents, no command plane, no active scanning. |
| L2 | HMIs, SCADA supervisory control, local historians | Observed passively through mirrored traffic only. |
| L3 | Site operations, engineering workstations, industrial DMZ | Edge deploys here on a SPAN port or hardware TAP. |
| L4–L5 | Enterprise enterprise, ERP, corporate identity | Syslog, cloud telemetry, and identity events feed the same kill chain. |
Protocols

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.