See the process,
not just the packets.
A passive sensor on your backbone switch maps every PLC, RTU and HMI without touching them — and reads Modbus all the way down to the function code, the register and the value being written.
The devices that run the plant will never run your agent.
A PLC is under vendor warranty. An IED ships a fixed firmware image. The HMI runs an operating system nobody is allowed to patch. You cannot install on them, and active scanning is the one thing every plant engineer forbids — a stray sweep or an unexpected Modbus read has stopped production lines.
So ReviveSec listens instead. Mirror the backbone traffic to the sensor and it identifies every device from what it already says to its own master, continuously, with nothing to install and nothing injected.
- Cleartext on the wire. Modbus carries no encryption and no authentication, so intent is directly readable rather than inferred from ports and volume.
- Every asset, including the undocumented ones. The tap reaches devices nobody logged into for a decade and devices nobody wrote down.
- Serial devices too. Slaves sitting behind a Modbus gateway are resolved individually by unit ID, not collapsed into the gateway's IP.
- No TLS to break, no proxy to insert. Nothing is terminated, delayed or rewritten in the path of the process.
- One sensor per aggregation point. Coverage scales with switches, not with device count.
Everything the wire already tells you.
Asset discovery, protocol dissection, behavioural baselining and detection — from one mirrored copy of the traffic.
Passive asset mapping
Every device on the segment identified from its own traffic — MAC, OUI vendor, IP, VLAN and switch port, with no scan and no probe.
Device fingerprinting
Vendor, product code and firmware revision harvested from identity replies the controller already sends, plus device class: PLC, RTU, IED, HMI, drive, historian.
Modbus dissection
MBAP header, transaction and unit ID, function code, start address, quantity, values and exception responses — parsed on every transaction.
Behaviour profiling
Per master–slave pair, per unit ID: which function codes, which registers, at which cadence, within which value envelope. Learned, not configured.
Smart Map
A live dependency graph of the process network, so blast-radius questions are answered from observed traffic instead of a commissioning spreadsheet.
Unauthorised writes
A write from a master that has only ever read, a new master against a controller, a setpoint outside its envelope, a logic download or a run/stop.
Change detection
New firmware revision, a slave serving a register range it never served, an engineering laptop that appears on a segment at 02:00 — each raised with the session that proved it.
Attributable audit trail
Asset, session, function code, register, value and timestamp, with the stored packets behind every alert for the post-incident review.
Four stages, all of them inside the plant.
Capture through detection runs on the sensor. Nothing about the process leaves the tenant.
Mirror
A TAP or SPAN port on the backbone switch delivers a copy of the traffic crossing between cells and zones.
Dissect
Sessions are reassembled and parsed to Layer 7, tying every transaction to a physical asset and a unit ID.
Baseline
Normal masters, function codes, register scope, poll cadence and value envelopes are learned per conversation.
Detect
Deviations are scored and raised as an incident naming the device and the command, with packet evidence attached.
A function code is a finding. A port number is not.
Most OT monitoring stops at Layer 4 and reports that one address talked to another on port 502 — the normal state of a plant. Here is what the sensor pulls out of every transaction instead.
| Function code | What it tells you | Profile signal |
|---|---|---|
| 0x01 / 0x02 | Read Coils and Read Discrete Inputs — the routine digital polling that defines the normal scan cycle | Cadence baseline |
| 0x03 / 0x04 | Read Holding and Read Input Registers — which ranges each master legitimately consumes | Register scope |
| 0x05 / 0x06 | Write Single Coil and Write Single Register — a control action against one specific point | Write authority |
| 0x0F / 0x10 | Write Multiple Coils and Write Multiple Registers — bulk setpoint or recipe change | High severity |
| 0x08 | Diagnostics, including restart communications and listen-only mode — rarely legitimate in production | Abuse candidate |
| 0x2B / 0x0E | Read Device Identification — vendor, product code and revision, harvested passively for fingerprinting | Asset identity |
| 0x80 + | Exception responses — illegal function, illegal address, illegal value, device failure, busy | Error baseline |
| Vendor | Vendor-specific and engineering codes used to upload, download or run/stop controller logic | Critical event |
Deep on Modbus. Wide on assets.
Layer 7 dissection and baselining are available today for Modbus. Everything else on the segment is still discovered, fingerprinted and mapped, so your inventory is complete from day one.
| Coverage | What the sensor does with it | Status |
|---|---|---|
| Modbus TCP | Full Layer 7: MBAP header, transaction and unit ID, function code, start address, quantity, data values, exception responses | AVAILABLE |
| Modbus RTU over TCP | Full Layer 7 on encapsulated serial framing, including slaves reached through a serial gateway, resolved per unit ID | AVAILABLE |
| Modbus behaviour baseline | Function-code set, register and coil scope, poll cadence and jitter, and value envelopes per master–slave pair | AVAILABLE |
| All other OT traffic | Asset discovery, vendor fingerprinting, VLAN and switch-port location, peer and dependency mapping, new-talker detection | L2–L4 |
| DNP3, S7comm, EtherNet/IP + CIP, IEC 61850, OPC UA, BACnet, PROFINET | Deep dissection and per-protocol baselining, on the same engine and the same asset model | ROADMAP |
One port on the backbone switch.
The sensor sits at the aggregation point where traffic crosses between cells, zones and Purdue levels, as a hardened appliance or a virtual machine. It talks to the Revive OT Server — on premises or in your private cloud — over a single outbound mTLS channel it initiates itself.
There is no inbound port on the sensor and no path from the server back into the process network. If the link drops, the sensor keeps mapping and detecting from its local baseline and re-syncs when it returns.
Site & OT DMZ
Historians, OPC servers, jump hosts
Supervisory
HMIs, SCADA masters, engineering workstations
Field & Control
PLCs, RTUs, IEDs, drives, I/O, safety controllers
Into the console you already watch.
OT incidents arrive with process context — asset, function code, register and value — over standard Syslog and CEF.
Find out what is really on your OT network.
Mirror one switch port and see the asset map, the Modbus profile and the first deviations — without touching a controller.
Schedule a demo