SOC
Where every Core module lands
- Live, partial, and roadmap labeled honestly on the platform page.
- Detection, risk, compliance, and identity share the same incident.
- Click a module, then come back to the operator board.

Endpoint stacks see identity abuse. Edge sees protocol writes. CyberDragon stitches both into an explicitly labeled Enterprise→OT pivot so SOC analysts and plant engineers read the same story — across W15, W60, and W24 windows.
Explicit pivot labeling on correlated incidents
Identity-to-protocol timeline stitching
Engineering workstation and industrial DMZ crossover detection
MITRE ATT&CK + ICS tactic coverage on one object
OPA-guarded response proposals with evidence sealing
Lab-validated S2 IT/OT pivot scenario
SOC

Failed auth bursts or successful logins land in the W15 burst window.
Source addresses match C2 or staging indicators in the fused corpus.
Remote sessions to engineering hosts join through the W60 window.
Edge reports unexpected Modbus writes or DNP3 commands from that host.
Incident is labeled Enterprise→OT — not two unrelated alerts.
Playbook proposes containment; OPA evaluates OT action class independently.
Playbooks

Session issuance, MFA outcomes, and API-key usage per tenant.
Corporate AD, VPN, and EDR-forwarded events via syslog or HEC.
Modbus function codes, DNP3 controls, OPC-UA session changes.
C2 and staging indicators raise confidence during pivot assembly.
UEBA

One platform, two planes — Core control plane and Edge collector for converged IT/OT.
Kafka-backed indigenous SIEM/SOAR — ingest, detection, risk, compliance, and response.
Passive SPAN capture at the industrial DMZ — telemetry up only, no PLC agents.
Modbus, DNP3, OPC-UA, and MQTT parsed natively at Purdue L3.
Indigenous global SIEM and Temporal-orchestrated SOAR with human approval gates.
W15 / W60 / W24 cascading windows across MITRE ATT&CK and ICS tactics.
A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.