Watcher offers a unique solution with a sophisticated visualization engine that displays network nodes and communications pathways. Watcher has full packet capture techniques to create a live model of the client’s network, I.T., O.T and IoT offering live forensics in minutes.
Watcher has the unique ability to operate on OT / ICS networks as it does with traditional IT networks. Watcher performs the same tasks outlined above but with an added feature. When enabled, Watcher utilizes custom built ICS data libraries that allows Watcher to ingest and monitor ICS specific protocols and alert on ICS events.
Watcher inspects the application layer of the packet and process all the index variables for known PLCs / Data type (BacNET, ModBus, DNP3 and more). Watcher process each customer defined index variables and maintains an understanding of the value, monitors for any change in each value. Our process detects network anomalies, security threats, and ZeroDay events. When a value change is outside of the parameters it alerts the operators via the GUI or SIEM. Watcher operates “out of band” to monitor for spoofing events that would cause the HMI to show altered numbers versus what is actually happening on the PLC.