CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
CyberDragon Edge · On-site plane

Plant DMZ collector — Modbus writes without PLC agents.

Distinct Edge experience: orange industrial theme, protocol tables first, appliance profiles, and offline buffer. Not the same layout as Core.

Deploy at IEC 62443 L3

Industrial DMZ. Telemetry up only.

Edge sits at the Enterprise/OT boundary. It reads SPAN / mirror-port traffic. There is no command plane into Purdue L0–L2. If connectivity to Core drops, Edge buffers ~5,000 events in SQLite WAL and forwards when the link returns.

Passive packet capture

SPAN / TAP

Scapy / libpcap — never injects into OT networks.

Protocol parsers

OT-native

Modbus TCP/RTU, DNP3, OPC-UA, MQTT.

Local detection

Edge AI

YAML rules + EWMA/z-score behavior + Purdue zone policy.

Offline buffer

Air-gap safe

SQLite WAL, ~5,000-event store-and-forward.

Secure transport

Zero-trust

HMAC-SHA256 with optional mTLS to Core.

Fleet identity

Multi-site

Per-node edge_id, scoped to tenant_id.

Local ops dashboard

Plant ops

FastAPI dashboard: assets, events, transport health.

Protocols

Modbus TCP/RTU · DNP3 · OPC-UA · MQTT

Protocol-native parsing — not generic PCAP dumps. Plant engineers and SOC analysts see the same session change in OT language.

Protocols

Deep inspect Modbus, DNP3, OPC-UA

  • Parser throughput per industrial protocol.
  • No software on the PLC. No injected packets.
  • Feeds Core SIEM with OT semantics, not generic PCAP dumps.
Protocol deep inspector
Parser depth

What the collector actually understands on the wire.

ProtocolParsed structureWhat that enables
Modbus TCP / RTUFunction codes, unit IDs, register ranges, read vs write intentWrites to protected registers, function-code sweeps, out-of-window changes
DNP3Application objects, control relay output blocks, unsolicited responsesUnauthorized control commands and spoofed outstation traffic
OPC-UASessions, subscriptions, node browse and read patternsTag harvesting, address-space enumeration, session abuse
MQTTTopics, client IDs, subscription scope, publish cadenceWildcard subscriptions crossing zones and rogue publishers

Zones

Purdue L0–L5 topology

  • IEC 62443 zone map the SOC and plant engineers can both read.
  • Edge sits at L3 / industrial DMZ by design.
  • Telemetry up only.
Zone and Purdue topology
Form factors

Size the collector to the site, not the other way round.

Explore Now
Explore Now
Explore Now
Explore Now
Event lifecycle

From mirrored frame to sealed record.

01

Capture

Edge mirrors traffic from a SPAN port or hardware TAP at the industrial DMZ and parses OT protocols locally.

02

Buffer

Events land in a SQLite WAL store-and-forward queue (~5,000 events) so a link outage never loses telemetry.

03

Transport

HMAC-SHA256 signed batches, optionally mTLS, are shipped to Core over the ingest network only.

04

Enrich

Threat-intel fusion adds OTX, Abuse.ch, ThreatFox, MITRE TAXII, and GreyNoise context in flight.

05

Correlate

Cascading W15 / W60 / W24 windows assemble events into kill chains and flag Enterprise→OT pivots explicitly.

06

Decide

Risk scoring, compliance auto-mapping, and Temporal playbooks with human approval and OPA guardrails.

07

Seal

Detections, approvals, and denials are hash-chained and Ed25519-signed into the evidence vault.

FAQ

Frequently asked questions.

Does Edge ever transmit into the OT network?
No. Capture is passive via SPAN or TAP using Scapy/libpcap. Nothing is injected into the process network.
What happens during a network outage?
Roughly 5,000 events buffer locally in SQLite WAL and forward once the secure HMAC (optionally mTLS) transport to Core recovers.
What do plant operators see locally?
A FastAPI dashboard on the collector with asset inventory, security events, and transport health — no cloud dependency to read it.

Add an Edge kit to your PoV.

Start with a 7-day free trial, then extend to a 30-day Proof of Value with on-site collection.