CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Core module · OT safety

We automate up to the plant floor — not against it.

CyberDragon requires human approval for OT-affecting playbooks — and independent OPA policy can still deny the action afterward. Maintenance windows, action-class allowlists, and reason codes give plant engineers veto power backed by tamper-evident evidence.

What it delivers

Live in Core today.

OPA deny-after-approve on OT-affecting action classes

Action-class allowlists by asset type (PLC / HMI / RTU)

Dual-approval for critical state-changing actions

Maintenance-window enforcement for OT_CONFIG_CHANGE

Policy reason codes sealed in the evidence vault

Lab-demonstrated post-approval denial (1 block recorded)

SOC

Where every Core module lands

  • Live, partial, and roadmap labeled honestly on the platform page.
  • Detection, risk, compliance, and identity share the same incident.
  • Click a module, then come back to the operator board.
CyberDragon Unified SOC dashboard
How it works

From signal to sealed evidence.

01

Detect

Kill-chain engine raises an incident with OT impact classification.

02

Propose

Temporal playbook suggests containment or configuration change.

03

Human approve

Analyst with appropriate RBAC tier approves the proposed action.

04

OPA evaluate

Independent policy checks zone, asset class, and maintenance window.

05

Execute or deny

Allowed actions run; denials return reason codes to the SOC and plant team.

06

Seal

Approval, denial, and execution outcomes hash-chained for auditors.

Playbooks

SOAR module in the workspace

  • Run from the incident, not from a disconnected automation island.
  • OT guardrails stay in the path.
  • YAML for teams who version playbooks.
CyberDragon Response playbooks
Key capabilities

Built for regulated IT/OT estates.

Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Signal sources

What feeds this module.

OPA policy bundles

Platform ABAC plus OT-specific guardrails versioned per tenant.

Purdue zone context

L3 DMZ collection boundary respected in policy evaluation.

Temporal workflows

Durable playbooks pause for approval and policy gates.

Evidence vault

Every decision — including denials — is immutable.

UEBA

User and entity behavior

  • Anomaly signals join the same kill chain as OT protocol events.
  • Useful when identity abuse starts the campaign in enterprise.
  • Not a stand-alone UEBA SKU.
UEBA dashboard
Proof points

Measured in the lab — not marketing adjectives.

1
Post-approval OT denial (lab)
S5
SCADA guardrails scenario passed
7-tier
RBAC from read-only to super-admin
0
Command plane into L0–L2
Lab-validated metrics. Proof of Value results may vary.
FAQ

Frequently asked questions.

Will CyberDragon change my PLCs automatically?
No. OT-affecting automation requires human approval and OPA evaluation. Policy can deny even after approval.
What happened in the lab denial?
Scenario S5 demonstrated a post-approval block — the denial and reason code were sealed in the evidence vault.
How is this different from endpoint SOAR?
Plant safety is first-class. Policies understand Purdue zones and OT action classes, not just IT remediation scripts.

Prove dual-gate OT response in your 7-day trial.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.