🛡️
DEFENSE-GRADE OT CYBERSECURITY MONITOR
SURICATA ICS DEEP PACKET INSPECTION • PURDUE ZERO-TRUST ZONE CONTROLLER • K3s ARM64
• PERIMETER ACTIVE • ZERO TRUST ENFORCED
Active ICS Protocol Decoders
NOMINAL
5 / 5 ACTIVE
Real-time passive packet inspection on physical interface (eth0)
Protocol
Port
Decoder Status
Modbus TCP
502
INSPECTING
EtherNet/IP (CIP)
44818
INSPECTING
Siemens S7comm
102
INSPECTING
DNP3 / IEC-104
20000
INSPECTING
MQTT / Sparkplug B
1883
INSPECTING
Purdue Zone Microsegmentation
ISA/IEC 62443
Level 1 / 2: Field & Control
(PLCs, Remote I/O)
AIR-GAPPED
Level 3: Operations SCADA
(Ignition, InfluxDB, EMQX)
NODEPORT SECURE
Level 3.5: Industrial DMZ
(WireGuard Hub, Traefik)
TLS 1.3 / mTLS
Level 4: Cloud Ingress
(AWS EC2 xk3s.com)
EIP ZERO TRUST
Return to Mission Control HUD →
Security Telemetry Metrics
LIVE
0 THREATS
Unauthorized PLC function code executions: 0
•
Engine:
Suricata 8.0 ICS Protocol Inspection
•
Host Architecture:
Dual Raspberry Pi 5 (xrpi1 Master + xrpi2 Worker)
•
Ingress Encryption:
WireGuard ChaCha20-Poly1305 + Cloudflare Universal SSL
•
Alert Dispatch:
Mattermost Webhook + Splunk HEC + Datadog APM