OT/ICS Security Tools
OT and ICS security tools passively monitor industrial protocols, inventory control-system assets, and flag anomalies in environments where active scanning can disrupt physical processes.
| Tool | License | Platforms | Pricing | Action |
|---|---|---|---|---|
| Claroty | Proprietary | Web | Commercial | Profile→ |
| Dragos | Proprietary | Web, Hardware | Commercial | Profile→ |
| Forescout | Proprietary | Web | Commercial | Profile→ |
| Honeywell Cyber Insights | Proprietary | Web | Commercial | Profile→ |
| MarlinSpike | AGPL-3.0-or-later | Linux, Windows | Open Source | Profile→ |
| Nozomi Networks | Proprietary | Web, Hardware | Commercial | Profile→ |
Software in OT/ICS Security Tools
Claroty
CommercialCPS protection platform spanning OT, IoT, and medical devices with monitoring, access, and exposure modules.
Dragos
CommercialOT cybersecurity platform for asset visibility, vulnerability prioritization, and ICS threat detection.
Forescout
CommercialIT, OT, and IoT visibility and control platform with agentless OT monitoring and device compliance.
Honeywell Cyber Insights
CommercialContinuous OT network monitoring platform, formerly the SCADAfence product line.
MarlinSpike
Open SourceOpen source passive OT/ICS network analysis and topology mapping, positioned as a GRASSMARLIN replacement.
Nozomi Networks
CommercialOT and IoT visibility platform with AI-driven anomaly detection across industrial networks.
Frequently Asked Questions
What is OT/ICS Security Tools?→
OT and ICS security tools passively monitor industrial protocols, inventory control-system assets, and flag anomalies in environments where active scanning can disrupt physical processes.
What topics does the OT/ICS Security Tools category cover?→
ICS Protocol Analysis, OT Asset Inventory, Passive Industrial Monitoring, PLC/SCADA Security, OT Vulnerability Management
About OT/ICS Security Tools
OT and ICS security tools protect the systems that run factories, utilities, pipelines, and building controls. The category covers passive network monitoring platforms that watch industrial protocols such as Modbus, DNP3, S7, and EtherNet/IP without injecting traffic, since an active scan can crash a PLC or interrupt a process. Asset inventory builds from that passive observation, listing controllers, engineering workstations, and firmware versions that no agent can be installed on. Vulnerability assessment and configuration review tools compare those findings against known issues and standards such as IEC 62443. Specialized fuzzers exercise protocol implementations in a lab before deployment, and evaluation tools guide a structured self-assessment of overall posture. Most platform vendors in this category are commercial, because protocol parsing libraries for industrial equipment are expensive to build and maintain. Open source coverage includes passive analysis and topology mapping tools and protocol fuzzers. The category overlaps with network monitoring for capture and with vulnerability scanning for prioritization, but the safety constraint distinguishes it from both.
Covered Topics & Disciplines
Related Security Categories
Packet capture tools, protocol analyzers, and network security monitors for traffic visibility.
SIEM platforms, EDR agents, SOAR automation, and detection rule engines for security operations.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.