CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Core module · IT→OT correlation

When corporate compromise reaches the plant floor — one incident, not two tickets.

Endpoint stacks see identity abuse. Edge sees protocol writes. CyberDragon stitches both into an explicitly labeled Enterprise→OT pivot so SOC analysts and plant engineers read the same story — across W15, W60, and W24 windows.

What it delivers

Live in Core today.

Explicit pivot labeling on correlated incidents

Identity-to-protocol timeline stitching

Engineering workstation and industrial DMZ crossover detection

MITRE ATT&CK + ICS tactic coverage on one object

OPA-guarded response proposals with evidence sealing

Lab-validated S2 IT/OT pivot scenario

SOC

Where every Core module lands

  • Live, partial, and roadmap labeled honestly on the platform page.
  • Detection, risk, compliance, and identity share the same incident.
  • Click a module, then come back to the operator board.
CyberDragon Unified SOC dashboard
How it works

From signal to sealed evidence.

01

Enterprise signal

Failed auth bursts or successful logins land in the W15 burst window.

02

Intel match

Source addresses match C2 or staging indicators in the fused corpus.

03

Lateral movement

Remote sessions to engineering hosts join through the W60 window.

04

OT anomaly

Edge reports unexpected Modbus writes or DNP3 commands from that host.

05

Pivot declared

Incident is labeled Enterprise→OT — not two unrelated alerts.

06

Guarded response

Playbook proposes containment; OPA evaluates OT action class independently.

Playbooks

SOAR module in the workspace

  • Run from the incident, not from a disconnected automation island.
  • OT guardrails stay in the path.
  • YAML for teams who version playbooks.
CyberDragon Response playbooks
Key capabilities

Built for regulated IT/OT estates.

Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Signal sources

What feeds this module.

Identity & MFA

Session issuance, MFA outcomes, and API-key usage per tenant.

Enterprise syslog

Corporate AD, VPN, and EDR-forwarded events via syslog or HEC.

Edge parsers

Modbus function codes, DNP3 controls, OPC-UA session changes.

Threat intel

C2 and staging indicators raise confidence during pivot assembly.

UEBA

User and entity behavior

  • Anomaly signals join the same kill chain as OT protocol events.
  • Useful when identity abuse starts the campaign in enterprise.
  • Not a stand-alone UEBA SKU.
UEBA dashboard
Proof points

Measured in the lab — not marketing adjectives.

S2
IT/OT pivot scenario detected
14.3s
APT kill-chain MTTD (lab)
6/6
Attack scenarios detected
W15·W60·W24
Cascading windows
Lab-validated metrics. Proof of Value results may vary.
FAQ

Frequently asked questions.

What makes the pivot label special?
It is explicit. When enterprise compromise precedes OT-side anomalies, the incident is labeled as a pivot so teams do not reconcile two siloed tickets.
Does this require CrowdStrike agents on PLCs?
No. OT telemetry is passive Edge capture. Enterprise signals can come from syslog, HEC, or your existing EDR forwarding.
Can plant engineers trust the timeline?
Yes. Protocol events are parsed at the DMZ with no command plane into L0–L2. Safety Gate can still deny automated response.

Watch a pivot assemble on sample Enterprise/OT telemetry.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.