CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Core module 02 · LIVE

Cascading windows that assemble the full intrusion story.

W15, W60, and W24 correlation windows stitch burst recon, lateral movement, and slow APT dwell into one indigenous SIEM timeline — not a pile of unrelated alerts.

What it delivers

Live in Core today.

W15 burst correlation for scanning and brute force

W60 lateral movement and engineering pivots

W24 slow APT dwell and C2 staging

MITRE ATT&CK + ICS tactic coverage

SOC

Where every Core module lands

  • Live, partial, and roadmap labeled honestly on the platform page.
  • Detection, risk, compliance, and identity share the same incident.
  • Click a module, then come back to the operator board.
CyberDragon Unified SOC dashboard
How it works

From signal to sealed evidence.

01

Capability 1

W15 burst correlation for scanning and brute force

02

Capability 2

W60 lateral movement and engineering pivots

03

Capability 3

W24 slow APT dwell and C2 staging

04

Capability 4

MITRE ATT&CK + ICS tactic coverage

Playbooks

SOAR module in the workspace

  • Run from the incident, not from a disconnected automation island.
  • OT guardrails stay in the path.
  • YAML for teams who version playbooks.
CyberDragon Response playbooks
Key capabilities

Built for regulated IT/OT estates.

Explore Now
Explore Now
Explore Now
Explore Now
Signal sources

What feeds this module.

Kill-Chain Detection

Cascading W15 (15 min) / W60 (1 hr) / W24 (24 hr) correlation windows.

Kafka event pipeline

Ingest, normalize, enrich, detect, and respond on shared topics.

Edge & connectors

Passive OT capture plus syslog, HEC, and cloud telemetry.

Evidence vault

Detections and decisions hash-chained for auditors.

UEBA

User and entity behavior

  • Anomaly signals join the same kill chain as OT protocol events.
  • Useful when identity abuse starts the campaign in enterprise.
  • Not a stand-alone UEBA SKU.
UEBA dashboard
Proof points

Measured in the lab — not marketing adjectives.

LIVE
Module maturity
2
Core module number
6/6
Lab attack scenarios
62
Core microservices
Lab-validated metrics. Proof of Value results may vary.
FAQ

Frequently asked questions.

Is Kill-Chain Detection available in the free trial?
The 7-day trial includes Core modules marked LIVE. PARTIAL modules are visible with honest maturity labels.
Does this page replace the platform overview?
No. Each module has its own URL so buyers can deep-link a capability without landing on a generic platform dump.
Where does this module sit in the stack?
Cascading W15 (15 min) / W60 (1 hr) / W24 (24 hr) correlation windows.

Try Kill-Chain Detection on your traffic.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.