OT Security

Home  /  OT Security
OT Security

See the process,
not just the packets.

A passive sensor on your backbone switch maps every PLC, RTU and HMI without touching them — and reads Modbus all the way down to the function code, the register and the value being written.

0Packets sent to the process network
Layer 7Modbus function code & register
AgentlessNothing installed on a controller
TAP / SPANDeploys without a change window
Why a tap

The devices that run the plant will never run your agent.

A PLC is under vendor warranty. An IED ships a fixed firmware image. The HMI runs an operating system nobody is allowed to patch. You cannot install on them, and active scanning is the one thing every plant engineer forbids — a stray sweep or an unexpected Modbus read has stopped production lines.

So ReviveSec listens instead. Mirror the backbone traffic to the sensor and it identifies every device from what it already says to its own master, continuously, with nothing to install and nothing injected.

Receive-only by design. The sensor has no IP address on the monitored side. It cannot delay a scan cycle, exhaust a controller's connection table, or trip a safety function — which is why it goes onto live production without a maintenance window.
  • Cleartext on the wire. Modbus carries no encryption and no authentication, so intent is directly readable rather than inferred from ports and volume.
  • Every asset, including the undocumented ones. The tap reaches devices nobody logged into for a decade and devices nobody wrote down.
  • Serial devices too. Slaves sitting behind a Modbus gateway are resolved individually by unit ID, not collapsed into the gateway's IP.
  • No TLS to break, no proxy to insert. Nothing is terminated, delayed or rewritten in the path of the process.
  • One sensor per aggregation point. Coverage scales with switches, not with device count.
OT capabilities

Everything the wire already tells you.

Asset discovery, protocol dissection, behavioural baselining and detection — from one mirrored copy of the traffic.

01 / DISCOVERY

Passive asset mapping

Every device on the segment identified from its own traffic — MAC, OUI vendor, IP, VLAN and switch port, with no scan and no probe.

02 / IDENTITY

Device fingerprinting

Vendor, product code and firmware revision harvested from identity replies the controller already sends, plus device class: PLC, RTU, IED, HMI, drive, historian.

03 / LAYER 7

Modbus dissection

MBAP header, transaction and unit ID, function code, start address, quantity, values and exception responses — parsed on every transaction.

04 / BASELINE

Behaviour profiling

Per master–slave pair, per unit ID: which function codes, which registers, at which cadence, within which value envelope. Learned, not configured.

05 / GRAPH

Smart Map

A live dependency graph of the process network, so blast-radius questions are answered from observed traffic instead of a commissioning spreadsheet.

06 / DETECTION

Unauthorised writes

A write from a master that has only ever read, a new master against a controller, a setpoint outside its envelope, a logic download or a run/stop.

07 / DRIFT

Change detection

New firmware revision, a slave serving a register range it never served, an engineering laptop that appears on a segment at 02:00 — each raised with the session that proved it.

08 / EVIDENCE

Attributable audit trail

Asset, session, function code, register, value and timestamp, with the stored packets behind every alert for the post-incident review.

How it works

Four stages, all of them inside the plant.

Capture through detection runs on the sensor. Nothing about the process leaves the tenant.

STAGE 01

Mirror

A TAP or SPAN port on the backbone switch delivers a copy of the traffic crossing between cells and zones.

STAGE 02

Dissect

Sessions are reassembled and parsed to Layer 7, tying every transaction to a physical asset and a unit ID.

STAGE 03

Baseline

Normal masters, function codes, register scope, poll cadence and value envelopes are learned per conversation.

STAGE 04

Detect

Deviations are scored and raised as an incident naming the device and the command, with packet evidence attached.

Continuous · the baseline keeps learning as the process changes
Modbus, in depth

A function code is a finding. A port number is not.

Most OT monitoring stops at Layer 4 and reports that one address talked to another on port 502 — the normal state of a plant. Here is what the sensor pulls out of every transaction instead.

Function codeWhat it tells youProfile signal
0x01 / 0x02Read Coils and Read Discrete Inputs — the routine digital polling that defines the normal scan cycleCadence baseline
0x03 / 0x04Read Holding and Read Input Registers — which ranges each master legitimately consumesRegister scope
0x05 / 0x06Write Single Coil and Write Single Register — a control action against one specific pointWrite authority
0x0F / 0x10Write Multiple Coils and Write Multiple Registers — bulk setpoint or recipe changeHigh severity
0x08Diagnostics, including restart communications and listen-only mode — rarely legitimate in productionAbuse candidate
0x2B / 0x0ERead Device Identification — vendor, product code and revision, harvested passively for fingerprintingAsset identity
0x80 +Exception responses — illegal function, illegal address, illegal value, device failure, busyError baseline
VendorVendor-specific and engineering codes used to upload, download or run/stop controller logicCritical event
Why behaviour is the only control. Modbus has no authentication and no integrity. Any host that can reach a slave can command it, and a valid frame from the wrong source is still a valid frame. Which master, which register and which value is therefore the only thing that separates an operation from an attack.
Protocol coverage

Deep on Modbus. Wide on assets.

Layer 7 dissection and baselining are available today for Modbus. Everything else on the segment is still discovered, fingerprinted and mapped, so your inventory is complete from day one.

CoverageWhat the sensor does with itStatus
Modbus TCPFull Layer 7: MBAP header, transaction and unit ID, function code, start address, quantity, data values, exception responsesAVAILABLE
Modbus RTU over TCPFull Layer 7 on encapsulated serial framing, including slaves reached through a serial gateway, resolved per unit IDAVAILABLE
Modbus behaviour baselineFunction-code set, register and coil scope, poll cadence and jitter, and value envelopes per master–slave pairAVAILABLE
All other OT trafficAsset discovery, vendor fingerprinting, VLAN and switch-port location, peer and dependency mapping, new-talker detectionL2–L4
DNP3, S7comm, EtherNet/IP + CIP, IEC 61850, OPC UA, BACnet, PROFINETDeep dissection and per-protocol baselining, on the same engine and the same asset modelROADMAP
Deployment

One port on the backbone switch.

The sensor sits at the aggregation point where traffic crosses between cells, zones and Purdue levels, as a hardened appliance or a virtual machine. It talks to the Revive OT Server — on premises or in your private cloud — over a single outbound mTLS channel it initiates itself.

There is no inbound port on the sensor and no path from the server back into the process network. If the link drops, the sensor keeps mapping and detecting from its local baseline and re-syncs when it returns.

Enforcement stays where you already trust it. The sensor never writes to the process network. Where you want containment, verdicts are exported to the control points you run today — the OT firewall, the switch, or your NAC.
LEVEL 3 / 3.5

Site & OT DMZ

Historians, OPC servers, jump hosts

LEVEL 2

Supervisory

HMIs, SCADA masters, engineering workstations

▲  TAP / SPAN on backbone switch  ·  receive-only  ·  no IP on the monitored side  ▲
LEVEL 0–1

Field & Control

PLCs, RTUs, IEDs, drives, I/O, safety controllers

Integrations

Into the console you already watch.

OT incidents arrive with process context — asset, function code, register and value — over standard Syslog and CEF.

CEF / Syslog forwarding Splunk IBM QRadar Microsoft Sentinel Wazuh REST API CMDB export OT firewall enforcement

Find out what is really on your OT network.

Mirror one switch port and see the asset map, the Modbus profile and the first deviations — without touching a controller.

Schedule a demo