CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
CyberDragon Core · Control plane

Indigenous SIEM/SOAR control plane for plant-connected estates.

~62 microservices behind a single reverse proxy. Identity, ingest, threat intel fusion, kill-chain detection, risk, compliance, Temporal-orchestrated response, and a tamper-evident evidence vault. Layout and theme are distinct from Edge.

Hard rules

Telemetry up only. Sovereign identity. Dual-gate OT response.

No command plane into L0–L2

Core never pushes control into Purdue process networks. Edge is passive-first.

Human approval AND OPA

OT-affecting automation requires both. Policy can deny even after analyst approval.

Sovereign identity

Hybrid ML-DSA-65 + Ed25519 JWTs. No third-party IdP dependency for core sessions.

Evidence-grade audit

Hash-chained, Ed25519-signed vault with ZIP export for auditors and regulators.

SIEM + SOAR

Unified SOC command center

  • Kafka ingest → detect → correlate → decide inside Core.
  • MITRE ATT&CK coverage and 24h detection timeline on one board.
  • Built for global SOC teams and MSSP tenants.
CyberDragon Unified SOC dashboard

Response

SOAR playbooks with OT guardrails

  • Run playbooks as Temporal workflows — not a fire-and-forget script.
  • Tier-3 OT actions still need dual approval.
  • OPA can deny an action even after a human clicks approve.
CyberDragon Response playbooks
Runtime substrate

The systems Core is actually built on.

ComponentRole in the control plane
Apache KafkaEvent backbone for ingest, normalization, enrichment, and detection topics.
PostgreSQL + RLSPrimary store with row-level security enforcing structural tenant isolation.
Neo4jCyber-physical knowledge graph powering attack-path and blast-radius queries.
TemporalDurable orchestration for response playbooks and human approval workflows.
Open Policy AgentPlatform ABAC plus the OT guardrails that can deny an approved action.
HashiCorp VaultCustody of Ed25519 and ML-DSA-65 signing material.
nginx + TLS 1.3Single-hostname reverse proxy in front of roughly 62 microservices.

Threat intel

TI Fusion Center

  • OTX, Abuse.ch, ThreatFox, MITRE TAXII, and GreyNoise in-flight.
  • Intel joins the same kill-chain timeline as Edge protocol events.
  • Not a separate dashboard silo.
TI Fusion Center
Pipeline

Seven stages between the plant and the auditor.

01

Capture

Edge mirrors traffic from a SPAN port or hardware TAP at the industrial DMZ and parses OT protocols locally.

02

Buffer

Events land in a SQLite WAL store-and-forward queue (~5,000 events) so a link outage never loses telemetry.

03

Transport

HMAC-SHA256 signed batches, optionally mTLS, are shipped to Core over the ingest network only.

04

Enrich

Threat-intel fusion adds OTX, Abuse.ch, ThreatFox, MITRE TAXII, and GreyNoise context in flight.

05

Correlate

Cascading W15 / W60 / W24 windows assemble events into kill chains and flag Enterprise→OT pivots explicitly.

06

Decide

Risk scoring, compliance auto-mapping, and Temporal playbooks with human approval and OPA guardrails.

07

Seal

Detections, approvals, and denials are hash-chained and Ed25519-signed into the evidence vault.

FAQ

Frequently asked questions.

What runs inside Core?
Around 62 microservices behind a single-hostname nginx reverse proxy: identity, ingest, Kafka normalization, TI fusion, detection, graph, risk, compliance, response, and evidence.
Which datastores are used?
PostgreSQL with row-level security, Neo4j for the attack-path graph, Kafka for the event pipeline, Temporal for orchestration, and HashiCorp Vault for signing keys.
Can Core run on-premises?
Yes. Sovereign on-prem (Mode B) runs the full control plane at your site, including air-gapped installs.

Start your 7-day free trial.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.