CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Kill-chain detection

One timeline from corporate identity to the plant floor.

CyberDragon correlates across three cascading windows so slow intrusions and fast bursts land in the same incident — with the Enterprise→OT pivot called out explicitly.

Correlation windows

W15 · W60 · W24 — cascading, not competing.

15-minute window

W15

Burst correlation — brute force, scanning, and rapid recon across enterprise and OT sensors.

1-hour window

W60

Lateral movement and engineering-workstation pivots that stitch enterprise identity abuse to OT sessions.

24-hour window

W24

Slow APT dwell — staged persistence, C2 beaconing, and pre-positioning before an OT action.

Triage

Alert Triage Center

  • AI-assisted queue with confidence, not a wall of undifferentiated pages.
  • Close FP, escalate, assign — hotkeys for the L1 shift.
  • Enterprise→OT pivots are first-class.
Alert Triage Center
MITRE mapping

ATT&CK for enterprise and for ICS, side by side.

Tacticenterprise behaviorOT behavior
ReconnaissanceNetwork and identity enumerationModbus function-code sweeps, device fingerprinting
Initial AccessPhishing, exposed remote servicesVendor VPN and engineering workstation entry
Lateral MovementCredential reuse, remote servicesEnterprise→OT pivot across the industrial DMZ
CollectionData stagingOPC-UA tag harvesting, historian scraping
Impair Process ControlUnauthorized Modbus writes, DNP3 control commands
ImpactRansomware deploymentLoss of view, loss of control, production downtime

Queue

Incident Queue

  • Work by severity and status: open → in-progress → resolved.
  • Same incident model the workspace and playbooks share.
  • MSSP-ready multi-tenant isolation.
Incident Queue
Lab-validated

6/6 scenarios detected, 8.0–20.5s MTTD.

OT Reconnaissance

S1

Enterprise/OT Pivot

S2

Credential Brute Force

S3

C2 / Threat Intel match

S4

SCADA Guardrails (post-approval block)

S5

APT Kill-Chain (14.3s MTTD)

S6
Lab-validated metrics. PoV results may vary.
Worked example

How a pivot incident assembles itself.

01

Credential abuse on enterprise

Repeated failed authentications followed by a success land inside the W15 burst window.

02

Intel match

The source address matches a C2 indicator in the fused corpus, raising the confidence score in flight.

03

Engineering workstation reached

A remote session to an L3 host joins the same chain through the W60 lateral-movement window.

04

OT protocol anomaly

Edge reports an unexpected Modbus write to a protected register from that host.

05

Pivot declared

The incident is explicitly labelled an Enterprise→OT pivot so SOC and plant engineering read one story.

06

Guarded response

The playbook proposes containment; OPA evaluates the OT action class independently before anything executes.

07

Sealed

Detections, the analyst decision, and the policy verdict are hash-chained into the evidence vault.

SOAR

Response playbooks

  • Library → Run → Active workflows → Tier-3 OT queue.
  • YAML playbooks, Temporal orchestration.
  • Safety Gate can still deny after approve.
Response playbooks
Signal sources

What feeds the correlation windows.

Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
FAQ

Frequently asked questions.

Why three windows instead of one?
Bursty attacks (brute force, scanning) and slow APT dwell need different correlation horizons. W15 catches bursts, W60 catches lateral movement, and W24 catches staged persistence — all feeding the same incident.
What makes the Enterprise→OT pivot special?
It is signaled explicitly. When an enterprise compromise precedes an OT-side anomaly, the incident is labeled as a pivot so the SOC and plant engineering see the same story.
Does detection require agents on PLCs?
No. OT telemetry comes from passive Edge capture on a SPAN tap at the industrial DMZ.

Watch the kill chain assemble on your own traffic.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.