CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Use cases

What teams actually run CyberDragon for.

Each use case pairs a detection path with the modules that carry it — from passive capture at the plant to the signed evidence packet.

Enterprise→OT pivot detection

Correlate a compromised corporate identity to an anomalous Modbus write in one timeline.

Kill-chain detection, Edge, attack-path graph

Unauthorized OT write attempt

Passive capture flags a write to a protected register outside a maintenance window.

Edge, OT safety guardrails, evidence vault

Ransomware pre-positioning

TI fusion matches C2 infrastructure before encryption starts on the enterprise side.

TI fusion, W24 window, SOAR

Vendor remote-access abuse

Third-party maintenance sessions tracked against approved windows and asset classes.

Identity, OPA policy, incident queue

NERC CIP evidence pack

Auto-mapped controls exported as a signed auditor packet at quarter close.

Compliance auto-mapper, evidence vault, reporting

Legacy PLC exposure

Agentless asset identification finds unsupported firmware without touching the device.

Edge, VSI, risk engine

MSSP client onboarding

New industrial tenant provisioned with RLS isolation and framework packs in days.

MSSP portal, tenant admin

Quantum readiness inventory

Crypto inventory and hybrid PQC session tokens evidence crypto agility today.

Sovereign identity, quantum readiness

Where endpoint-only stacks fall short

Scenarios that need OT semantics.

Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Signal path

From mirrored packet to signed evidence.

Every use case on this page rides the same seven-stage pipeline. Nothing on the path opens a write channel into the process network.

01

Capture

Edge mirrors traffic from a SPAN port or hardware TAP at the industrial DMZ and parses OT protocols locally.

02

Buffer

Events land in a SQLite WAL store-and-forward queue (~5,000 events) so a link outage never loses telemetry.

03

Transport

HMAC-SHA256 signed batches, optionally mTLS, are shipped to Core over the ingest network only.

04

Enrich

Threat-intel fusion adds OTX, Abuse.ch, ThreatFox, MITRE TAXII, and GreyNoise context in flight.

05

Correlate

Cascading W15 / W60 / W24 windows assemble events into kill chains and flag Enterprise→OT pivots explicitly.

06

Decide

Risk scoring, compliance auto-mapping, and Temporal playbooks with human approval and OPA guardrails.

07

Seal

Detections, approvals, and denials are hash-chained and Ed25519-signed into the evidence vault.

By role

The same incident, read six different ways.

RolePrimary concernWhat they get
CISOBoard-level risk narrative, quantified exposure, and audit readinessExecutive reporting, FAIR scenario scoring, and signed evidence packets.
SOC ManagerAlert quality, MTTD, and analyst throughputKill-chain correlation instead of raw alerts, plus playbooks with approval gates.
OT / Plant EngineerNothing may disturb the processPassive SPAN capture, no agents on PLCs, no command plane into L0–L2.
Compliance LeadControl coverage and evidence on demandAuto-mapped IEC 62443, NERC CIP, NIST CSF, ISO 27001, and SOC 2 controls.
MSSP OperatorMargin, isolation, and onboarding speedPostgreSQL RLS tenancy, cross-tenant portfolio views, and white-label options.
AuditorCan this record be trusted?Tamper-evident hash chain with Ed25519 signatures and reproducible verification.
FAQ

Frequently asked questions.

Can we start with one use case?
Yes. Most Proof of Value engagements start with Enterprise→OT pivot detection or unauthorized OT write attempts, then expand to compliance evidence.
Do these need a full deployment?
No. A single Edge collector at the industrial DMZ plus the cloud tenant is enough to exercise most use cases.
How long until first detection?
Ingest validation typically completes in the first days of a trial; lab MTTD for tier-1 scenarios is 8.0–20.5 seconds.

Start your 7-day free trial.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.