CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
CyberDragon.ai · Industrial Cybersecurity · Axix Technologies LLC USA

Industrial Cybersecurity & OT Security Platform for Enterprise, ICS & IIoT

Quantum-resilient plant-floor defense built on passive Edge capture of Modbus, DNP3, OPC-UA, and MQTT at the industrial DMZ — hybrid post-quantum identity, kill-chain detection, Threat Atlas enrichment, tamper-evident evidence, and OT safety policies that can deny an action even after human approval across Purdue L0 through L5.

CyberDragon.ai is an industrial cybersecurity platform that provides passive OT visibility, SIEM/SOAR, cyber threat intelligence, enterprise-to-OT attack detection, compliance evidence and quantum-resilient identity for industrial and critical infrastructure environments.

IEC 62443-3-3 aligned
NERC CIP mapped
NIST CSF 2.0
ISO 27001:2022
Indigenous SIEM + SOAR
Hybrid ML-DSA-65 + Ed25519, live today
Purdue L0–L5 · Industry 4.0
Purdue / IEC 62443 · Industry 4.0

L3Industrial DMZ

Where CyberDragon Edge deploys — SPAN/TAP, passive only, telemetry up.

Edge sits here. Telemetry flows up only. This is the safe collection boundary for Industry 4.0 and classic ICS.

Built for the sectors that can't afford a breach — click any vertical
CyberDragon complete cyber defense architecture — Unified SOC, Edge collectors, Purdue zones, and industry vertical dashboards
What is CyberDragon?

Not a generic SIEM with OT adapters. OT is first-class — Edge capture, indigenous SIEM/SOAR, and evidence in one stack.

OT-native collection, indigenous global SIEM and SOAR, AI-assisted kill-chain correlation, and tamper-evident evidence in one stack for enterprise, OT, IoT, Industry 4.0, and IIoT.

Edge deploys at plant DMZs as a passive SPAN collector parsing Modbus, DNP3, OPC-UA, and MQTT across Purdue L0–L5. Core runs a Kafka-backed indigenous SIEM/SOAR pipeline — ingest, TI fusion, Threat Atlas context, kill-chain detection, risk, compliance, Temporal-orchestrated response, and hash-chained evidence — secured by hybrid PQC JWTs and OPA OT guardrails.

Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now

SOC Operations

Unified SOC Dashboard

  • Morning posture: open incidents, risk, and MITRE coverage in one console.
  • Live incident feed with kill-chain confidence — not a pile of uncorrelated alerts.
  • OT and enterprise share one indigenous SIEM/SOAR timeline.
CyberDragon Unified SOC dashboard
The problem

Legacy tools stop at the DMZ. Attackers don't.

Industrial and Industry 4.0 campaigns start in corporate identity, pivot through engineering workstations, and reach Modbus, DNP3, and OPC-UA sessions on the plant floor. Endpoint-first stacks excel where agents run. Inventory-first stacks answer what is installed. Neither correlates the full Enterprise→OT kill chain end to end — and neither ships an indigenous OT-native SIEM/SOAR with hybrid post-quantum identity and tamper-evident evidence in one plane.

Endpoint-first and inventory-first tools stop where agents stop. CyberDragon correlates the full corridor — identity to industrial protocol — inside one indigenous SIEM/SOAR timeline.

Kill-chain deep dive →

Edge & OT

Passive Edge collector status

  • SPAN/TAP receive-only capture at the industrial DMZ — no packets into the process network.
  • Modbus, DNP3, and OPC-UA parser throughput on every Edge node.
  • Purdue L0–L5 logical ring so operators see where the collector actually sits.
CyberDragon Edge collector status board

Quantum-resilient identity

Hybrid post-quantum readiness

  • ML-DSA-65 + Ed25519 session identity live today — not a 2030 slide.
  • Track vulnerable keys and crypto inventory as you migrate.
  • Same control plane as the indigenous SIEM/SOAR — not a bolted-on PQC widget.
CyberDragon Quantum Readiness dashboard
Architecture

Two planes. One rule: telemetry only ever flows up.

CyberDragon Core is the indigenous SIEM/SOAR and cyber threat intelligence control plane. CyberDragon Edge is the on-site industrial collector. Together they cover Purdue L0–L5 without opening a command plane into process networks.

Control plane · SIEM + SOAR

CyberDragon Core

~62 microservices behind a single reverse proxy — sovereign identity, ingest, threat intel fusion, kill-chain detection, risk, compliance, Temporal-orchestrated response, and the evidence vault. Built as a global-ready cyber defense plane for MSSPs and sovereign operators alike.

  • · Kafka ingest → normalize → detect → correlate
  • · Neo4j attack-path graph
  • · Hash-chained, Ed25519-signed evidence
  • · Hybrid ML-DSA-65 + Ed25519 session identity
  • · OPA OT Safety Gate (deny after approve)

Core deep dive →

On-site plane · Industry 4.0 / ICS

CyberDragon Edge

Deploys once at the plant DMZ (IEC 62443 L3). Sees every Modbus write, DNP3 command, and OPC-UA session change — without a single agent on a PLC, robot controller, or medical device.

  • · Passive libpcap capture, never injects packets
  • · SQLite WAL offline buffer, ~5,000 events
  • · HMAC-SHA256 + mTLS transport to Core
  • · Local YAML + behavior detection
  • · Purdue zone policy at the boundary

Edge deep dive →

Pipeline

Capture → buffer → transport → enrich → correlate → decide → seal

1. Capture

Edge mirrors traffic from a SPAN port or hardware TAP at the industrial DMZ and parses OT protocols locally.

Industry 4.0

IIoT and smart-factory security

  • Assembly, painting, QA, and packaging cells on one OT security topology.
  • Production risk scored against OEE — security events that actually stop the line.
  • Built for manufacturing PoVs without agents on PLCs.
CyberDragon IIoT manufacturing dashboard
6/6
Attack scenarios detected
lab validation
8–21s
Mean time to detect
MTTD range
15,093
Live IOCs in TI corpus
continuously enriched
0
False incidents
22.4h baseline run
L0–L5
Purdue coverage model
Industry 4.0 ready
Lab-validated metrics. PoV results may vary.
Threat Atlas

Live cyber threat intelligence for IoT, ICS & industrial risk.

Public advisories and ransomware context on one board — feeding the same operator narrative as your kill-chain SIEM/SOAR plane.
FAQ

Technical & educational questions.

What is OT cybersecurity?
OT cybersecurity protects operational technology environments — industrial control systems, PLCs, SCADA and plant networks — from cyber threats while preserving operational and safety requirements. CyberDragon treats OT as first-class: passive capture at the industrial DMZ, protocol-native parsing, and correlation with enterprise identity events.
How does passive OT monitoring work?
CyberDragon Edge uses SPAN/TAP or mirror-port capture with libpcap — it observes Modbus, DNP3, OPC-UA and MQTT traffic without injecting packets or installing agents on controllers. Events buffer locally when links fail, then transport securely to Core for correlation and evidence.
What is OT SIEM?
OT SIEM correlates industrial protocol events, zone policy and enterprise telemetry in timelines meaningful to both SOC analysts and plant engineers — not flat syslog tags. CyberDragon’s indigenous SIEM/SOAR plane includes kill-chain windows, MITRE ATT&CK and ICS ATT&CK mapping, and OT safety guardrails on response workflows.
How does enterprise-to-OT detection work?
When identity or endpoint compromise precedes plant-floor protocol abuse, CyberDragon signals an explicit Enterprise→OT pivot — linking corporate campaigns to Modbus writes, DNP3 commands or OPC-UA session changes in cascading W15 / W60 / W24 correlation windows.
What OT protocols are supported?
Modbus TCP/RTU, DNP3, OPC-UA and MQTT at the Edge, deployed at IEC 62443 Level 3 / industrial DMZ. See the OT-native capture page for parser behavior, limitations and deployment diagrams.
What is IEC 62443?
IEC 62443 is the international standard for industrial automation and control system security, organized by zones, conduits and system requirements (SR). CyberDragon maps live events to SR controls and exports evidence — alignment support, not a claim that your site is certified.
What is post-quantum cryptography (PQC)?
PQC refers to cryptographic algorithms designed to resist attacks from cryptographically relevant quantum computers. CyberDragon ships hybrid ML-DSA-65 + Ed25519 JWTs today for sessions, API calls and Edge→Core transport — Vault-backed signing material, live in production tenants.
What is ML-DSA?
ML-DSA (Module-Lattice-Based Digital Signature Algorithm) is the NIST FIPS 204 standard derived from CRYSTALS-Dilithium. CyberDragon uses ML-DSA-65 alongside Ed25519 in hybrid tokens so operators retain a quantum-resistant signature path without a future migration project.
How does Threat Atlas work?
Threat Atlas aggregates public IoT/ICS advisories, malware context and vulnerability feeds into operator-facing boards — threat, malware and ICS views — so analysts contextualize plant risk alongside SIEM/SOAR incidents. It is an awareness layer; volumetric series follow public source cadence.
How does CyberDragon handle threat intelligence?
In-flight enrichment from OTX, Abuse.ch, ThreatFox, MITRE TAXII, GreyNoise and mirrored NVD/CISA KEV/OSV corpora — correlated to OT events before analysts triage. Feeds are configurable; air-gapped tenants can operate from offline mirrors.

Start your 7-day free trial.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See unified quantum-resilient cyber defense, indigenous SIEM/SOAR kill chains, and Threat Atlas context on your network.

Evaluating purchase, pricing or deployment timelines? View Pricing · Start Free Trial