Skip to content
Apex
ApexProductsAetherGuard

AetherGuard.

OT, ICS & IoT security — passive-first, on one model.

Security for the networks where a scan can stop a line: passive asset discovery, OT protocol DPI, behaviour anomaly detection, attack-path and ICS threat detection, with segmentation simulation and IoT protection. Baseline inventory under 24 hours, detection under 10 seconds, a million assets per deployment, seven-day offline edge autonomy — OT-security parity, and it couples to the physics so an alert is ranked by its real-world consequence.

Engines
12, one platform
Posture
Passive-first
Baseline
≤ 24h
Deploy
Cloud · self-hosted · air-gapped
Coverage

The whole OT estate, without touching it.

OT security has a constraint IT security doesn't: the network you're protecting can't tolerate the scan. AetherGuard is passive-first — it builds the inventory, parses the protocols, learns the behaviour and finds the threats from traffic alone, and only enforces where you choose. One model across discovery, detection, attack-path and segmentation, on the same platform that simulates the physics.

01

Passive asset discovery

Build a full inventory of every PLC, RTU, controller, drive and device — passively, from network traffic, with no active probing of fragile OT. Time-to-baseline under 24 hours.

02

OT protocol DPI

Deep packet inspection of OT/ICS protocols — Modbus, DNP3, OPC-UA, EtherNet/IP, PROFINET, S7 and more — parsing the commands, not just the packets.

03

Behaviour anomaly detection

Learn the normal rhythm of the process and the network, and flag the deviation — an unexpected command, a new flow, a setpoint change — that signals an intrusion or a fault.

04

Vulnerability intelligence

Passive vulnerability and exposure assessment mapped to OT advisories (ICS-CERT) and prioritised by reachability and consequence — never by raw CVSS.

05

Attack-path analysis

Map the path from a phished IT laptop to a controller across the Purdue model, and the shortest set of conduits to cut it — before an attacker walks it.

06

ICS threat detection

Detect OT-specific threats and known ICS malware (TRITON, Industroyer-class) against ATT&CK for ICS — detection-to-alert under 10 seconds.

07

Risk engine

Score every asset by criticality, exploitability and physical consequence, so the queue is ordered by what actually threatens the process.

08

Segmentation simulation

Discover real device-to-device flows and simulate a segmentation policy against them in under five minutes — validate before you enforce, so you never break a running line.

09

Device & network control

Safe, optional enforcement — virtual patching, access control and containment — applied with the passive-first discipline OT demands, reversible and audited.

10

IoT & IIoT security

Fingerprint and protect unmanaged IoT and IIoT devices — cameras, sensors, building systems — that traditional agents can't reach.

11

Edge sensor

A passive sensor at over 1 Gbps and 50,000 events/s, with seven days of offline autonomy — so coverage holds even when the link to the plant drops.

12

Security copilot

Ask the OT estate a question in plain language — what changed on this segment, what's the blast radius of this CVE, what should I do — grounded in your telemetry.

One platform vs the OT tools

Visibility, detection — and consequence.

The OT vendors see the network and the threats. Only Aether forward-rolls the intrusion to what it does to the process — the difference between a list of alerts and a list ranked by physical impact.

✓Passive asset discovery
✓OT protocol DPI
✓Behaviour anomaly detection
✓Attack-path analysis
✓ICS threat detection
✓Segmentation simulation
✓IoT / IIoT coverage
✓Consequence simulation
✓Self-hosted / air-gapped
The numbers

Safe, fast, at plant scale.

OT security lives and dies on being safe to deploy and fast to stand up. These are the budgets the platform is built to.

Passive-first
safe for live OT

no active probing

≤ 24 h
time to baseline

full asset inventory

≤ 10 s
detection-to-alert (p95)

OT threats

≥ 1 Gbps
passive throughput

per sensor

≥ 7 days
edge autonomy

offline, link drops

1,000,000+
assets

per deployment

≤ 5 min
segmentation simulation

validate before enforce

Air-gapped
self-hosted option

where OT must stay

Stack it replaces

One platform for the plant.

OT IDS, asset inventory, vuln management and segmentation review collapse into one model, one queue and one audit trail.

OT visibility platforms
OT/ICS monitoring
ICS threat platforms
asset-visibility platforms
network access control
Standalone OT IDS
Manual asset inventories
Tabletop segmentation reviews
FAQ

Good to know.

Is it safe to run on a live process network?

Yes — it's passive-first by design. Discovery, DPI, anomaly detection and vulnerability assessment all run from a span/tap with no active probing of fragile OT devices; active enforcement is optional, reversible and applied only where you choose. Breaking a running line to scan it is exactly what an OT security tool must never do.

How is this different from OT visibility platforms or OT/ICS monitoring?

Those are strong OT visibility and detection platforms. AetherGuard matches them on passive discovery, DPI and detection — and adds what they can't: it couples to Aether's physics, so a flagged intrusion can be forward-rolled to its physical consequence (which feeder it drops, which vessel it overpressures), turning a list of alerts into a list ranked by real-world impact.

How fast does it stand up?

Time-to-baseline inventory is under 24 hours from connecting a sensor, detection-to-alert is under 10 seconds, and a sensor handles over 1 Gbps and 50,000 events/s with seven days of offline autonomy if the link to the plant drops.

Will it scale to our whole estate?

Yes — over a million assets per deployment, self-hosted and fully air-gapped, with segmentation policies you can simulate against real flows in under five minutes before enforcing them.

See the OT estate — safely.

Passive discovery to consequence-ranked detection, on one model that also simulates the physics. Request access to deploy it self-hosted or air-gapped on your plant network.

Part of Aether Security — one platform across thirteen domains. OT security sits on the same foundation as the rest of Aether — one model, every discipline.