SOC
Where every Core module lands
- Live, partial, and roadmap labeled honestly on the platform page.
- Detection, risk, compliance, and identity share the same incident.
- Click a module, then come back to the operator board.

CyberDragon requires human approval for OT-affecting playbooks — and independent OPA policy can still deny the action afterward. Maintenance windows, action-class allowlists, and reason codes give plant engineers veto power backed by tamper-evident evidence.
OPA deny-after-approve on OT-affecting action classes
Action-class allowlists by asset type (PLC / HMI / RTU)
Dual-approval for critical state-changing actions
Maintenance-window enforcement for OT_CONFIG_CHANGE
Policy reason codes sealed in the evidence vault
Lab-demonstrated post-approval denial (1 block recorded)
SOC

Kill-chain engine raises an incident with OT impact classification.
Temporal playbook suggests containment or configuration change.
Analyst with appropriate RBAC tier approves the proposed action.
Independent policy checks zone, asset class, and maintenance window.
Allowed actions run; denials return reason codes to the SOC and plant team.
Approval, denial, and execution outcomes hash-chained for auditors.
Playbooks

Platform ABAC plus OT-specific guardrails versioned per tenant.
L3 DMZ collection boundary respected in policy evaluation.
Durable playbooks pause for approval and policy gates.
Every decision — including denials — is immutable.
UEBA

One platform, two planes — Core control plane and Edge collector for converged IT/OT.
Kafka-backed indigenous SIEM/SOAR — ingest, detection, risk, compliance, and response.
Passive SPAN capture at the industrial DMZ — telemetry up only, no PLC agents.
Modbus, DNP3, OPC-UA, and MQTT parsed natively at Purdue L3.
Indigenous global SIEM and Temporal-orchestrated SOAR with human approval gates.
W15 / W60 / W24 cascading windows across MITRE ATT&CK and ICS tactics.
A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.