CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Threat Research Unit

Signed detection content. Kill-chain evidence. ISAC alignment.

Quarterly threat reports, YAML detection packs with MITRE mapping, CVE coordination, and ICS-ISAC / E-ISAC / FS-ISAC alignment.

TRU deliverables

Reports, signed packs, CVE process, ISAC alignment.

Explore Now →
Explore Now →
Explore Now →
Explore Now →
Live threat picture

The same public threat landscape operators see in Threat Atlas.

KEV, ransomware disclosures, and ICS advisories — the briefing video sits next to the live board, not a separate marketing silo.

Lab-validated scenarios

6/6 attack scenarios detected.

OT Reconnaissance

S1

Enterprise/OT Pivot

S2

Credential Brute Force

S3

C2 / Threat Intel match

S4

SCADA Guardrails (post-approval block)

S5

APT Kill-Chain (14.3s MTTD)

S6
Proof metrics

Controlled test environments. PoV results may vary.

Explore Now →
Explore Now →
Explore Now →
Explore Now →
Explore Now →
Explore Now →
Explore Now →
Explore Now →

UEBA

Behavior plus OT

  • Identity anomalies that precede plant-floor writes.
  • Useful in ransomware-to-OT narratives.
  • Same Core as the SOC.
UEBA
Correlation windows

Three time horizons, one kill chain.

15-minute window

W15

Burst correlation — brute force, scanning, and rapid recon across enterprise and OT sensors.

1-hour window

W60

Lateral movement and engineering-workstation pivots that stitch enterprise identity abuse to OT sessions.

24-hour window

W24

Slow APT dwell — staged persistence, C2 beaconing, and pre-positioning before an OT action.

ATT&CK coverage

The same tactic, read on both sides of the DMZ.

Tacticenterprise expressionOT expression
ReconnaissanceNetwork and identity enumerationModbus function-code sweeps, device fingerprinting
Initial AccessPhishing, exposed remote servicesVendor VPN and engineering workstation entry
Lateral MovementCredential reuse, remote servicesEnterprise→OT pivot across the industrial DMZ
CollectionData stagingOPC-UA tag harvesting, historian scraping
Impair Process Control—Unauthorized Modbus writes, DNP3 control commands
ImpactRansomware deploymentLoss of view, loss of control, production downtime
Public intelligence

Research the team publishes openly.

Threat Atlas — Threat

Exploited-in-the-wild vulnerabilities from the CISA Known Exploited Vulnerabilities catalog, tagged for OT and ICS relevance.

Threat Atlas — Malware

Ransomware leak-site disclosures with sector and country attribution, flagged when the victim profile implies industrial exposure.

Threat Atlas — ICS

CISA industrial control system advisories, cross-referenced against the protocols Edge parses natively.

IOC corpus

A live corpus of 15,093 indicators fused from OTX, Abuse.ch, ThreatFox, MITRE TAXII, and GreyNoise, applied to events in flight.

Open the live board: Threat Atlas.

FAQ

Frequently asked questions.

Where can I see live threat data?
The Threat Atlas publishes live threat, malware, and ICS advisory views sourced from public feeds and refreshed continuously.
Are detection packs signed?
Yes. TRU ships YAML detection content with MITRE mapping, signed and distributed through the Marketplace.
How does TRU handle vulnerability disclosure?
Through a coordinated CVE process, with ICS-ISAC, E-ISAC, and FS-ISAC alignment for sector sharing.

Start your 7-day free trial.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.