License & Deployment Mix: 11 tools – 5 OSS, 6 commercial.
Color: Blue team.
What Is This Category?
OT / ICS security is the specialty of monitoring and defending industrial control systems. Where IT networks speak TCP / TLS / HTTP, OT networks speak Modbus / DNP3 / IEC 60870-5-104 / S7Comm / EtherNet/IP and run on PLCs / RTUs / HMIs that often can’t take patches without downtime. Tools must be passive (active scans can crash old PLCs), protocol- aware (deep packet parsing of ICS protocols), and safety-first (any false-positive block can stop a production line).
Distinct from neighbouring categories
- IDS / IPS – Standard IDS / IPS focuses on IT protocols; OT IDS parses ICS protocols and operates passively
- SCADA / Industrial Control – SCADA covers HMI / operator-console software; OT security covers the network and detection layer
- Network Monitoring / NPM – Network monitoring is health metrics; OT security is threat detection in safety-critical environments
- Deception & Honeypots – Conpot is cross-listed in both categories (deception lens vs OT-defender lens)
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
OT / ICS security splits between an OSS toolchain (Malcolm bundle + GRASSMARLIN one-shot mapping + Conpot ICS honeypot + Suricata-with-ICS-rules + snap7 protocol library) and commercial OT-security platforms (Claroty, Dragos, Nozomi, Tenable.ot, Armis, Defender for IoT). The OSS toolchain handles open protocols (Modbus / DNP3 / IEC-104 / S7Comm / BACnet / EtherNet/IP / CIP); commercial vendors add proprietary protocols (Rockwell DH+ / ControlNet / DeviceNet – see the README Protocol Coverage Gaps callout).
Capability Matrix
| Tool | Passive | Active (Safe) | Asset Inventory | Vuln Mgmt | IT+OT |
|---|---|---|---|---|---|
| Malcolm (CISA / INL) | yes (Zeek + Suricata + Arkime) | – | yes | – | partial |
| GRASSMARLIN (NSA) | yes (offline PCAP) | – | yes | – | – |
| Conpot (honeypot) | yes (tripwire) | – | – | – | – |
| snap7 | – | yes (active S7) | – | – | – |
| Suricata + ICS rules | yes | – | partial | – | – |
| Claroty CTD | yes | partial (safe) | yes | yes | yes |
| Dragos Platform | yes | – | yes | yes | yes |
| Nozomi Guardian | yes | partial (Smart Polling) | yes | yes | yes (+ IoT) |
| Tenable.ot | yes | partial | yes | yes (Tenable One) | yes |
| Armis | yes (agentless) | – | yes | yes | yes (all device types) |
| Defender for IoT | yes | – | yes | yes | yes (M365-aligned) |
ICS Protocol Coverage
Where OSS draws the line and where commercial picks up.
| Protocol | OSS coverage | Commercial coverage |
|---|---|---|
| Modbus | yes (Malcolm / Suricata / Conpot) | yes (all vendors) |
| DNP3 | yes (Malcolm / Suricata) | yes (all vendors) |
| IEC-104 | yes (Malcolm) | yes (all vendors) |
| S7Comm (Siemens) | yes (Malcolm / snap7 / Conpot) | yes (all vendors) |
| BACnet (Building Automation) | yes (Malcolm / Conpot) | yes (all vendors) |
| EtherNet/IP + CIP | yes (Malcolm / Suricata) | yes (all vendors) |
| Data Highway (DH-485) – Rockwell | no | yes (Claroty / Dragos / Nozomi / Tenable.ot / Defender for IoT) |
| Data Highway Plus (DH+) – Rockwell | no | yes (Claroty / Dragos / Nozomi) |
| ControlNet – Rockwell | no | yes (Claroty / Dragos / Nozomi) |
| DeviceNet – Rockwell | no | yes (Claroty / Dragos) |
License Comparison
| Tool | License | OSI | Type |
|---|---|---|---|
| Malcolm | BSD-3-Clause | yes | OSS bundle (Zeek + Suricata + Arkime + OpenSearch) |
| GRASSMARLIN | Apache-2.0 | yes | OSS desktop |
| Conpot | GPL-2.0-only | yes | OSS honeypot |
| snap7 | LGPL-3.0-only | yes | OSS protocol library |
| Suricata + ICS | GPL-2.0-only | yes | OSS IDS + paid rule feeds |
| Claroty CTD | Proprietary | – | Commercial leader |
| Dragos Platform | Proprietary | – | Commercial (threat-intel heritage) |
| Nozomi Guardian | Proprietary | – | Commercial (OT + IoT + IIoT) |
| Tenable.ot | Proprietary | – | Commercial (Tenable One integration) |
| Armis | Proprietary | – | Commercial (all-device coverage) |
| Defender for IoT | Proprietary | – | Microsoft (Entra-native) |
Composition Patterns
1. OSS-only OT-network monitoring
Malcolm -- bundled Zeek + Suricata + Arkime GRASSMARLIN -- one-shot topology mapping from PCAP Conpot -- ICS honeypot tripwire Suricata + ICS rules -- IDS for ICS-protocol traffic
Output: open-protocol OT-monitoring at zero license cost. Does not cover Rockwell DH+ / ControlNet / DeviceNet.
2. Commercial OT platform
Claroty CTD (or Dragos / Nozomi / Tenable.ot / Defender for IoT)
+ Malcolm or Conpot as complementary defence layerOutput: full ICS-protocol coverage including Rockwell. Per-site enterprise cost.
3. Tenable ecosystem customer
Tenable.ot -- OT-side exposure management
+ Tenable.io VM -- IT-side vulnerability management
+ Tenable One -- unified exposure platformOutput: unified IT + OT + cloud + identity exposure under one vendor / one console.
Tools
11 tools.
Armis
Armis’s agentless device-security platform; broad IoT + IoMT + OT + IT coverage; asset-discovery focused.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
Claroty CTD
Claroty’s Continuous Threat Detection platform; the OT-security category leader; the deepest commercial ICS-protocol coverage.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
Conpot (ICS Honeypot)
ICS / SCADA honeypot emulating PLCs, RTUs, HMIs; Modbus + S7Comm + BACnet + others; cross-listed from tools/deception/.
License: GPL-2.0-only (OSS) · Kind: service · Deploy: docker, native · SSO: none
Dragos Platform
Dragos’s OT-security platform; founded by former NSA / ICS-CERT staff; threat-intel heritage; strong critical-infrastructure customer base.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
GRASSMARLIN
NSA-released open-source ICS / SCADA passive network mapper; java- based; produces ICS-protocol-aware network topology diagrams.
License: Apache-2.0 (OSS) · Kind: cli · Deploy: native · SSO: none
Malcolm
CISA / Idaho National Labs OSS network-traffic analysis suite; Zeek + Suricata + Arkime + OpenSearch tuned for OT / ICS environments.
License: BSD-3-Clause (OSS) · Kind: service · Deploy: docker, native · SSO: OIDC
Microsoft Defender for IoT
Microsoft’s OT / IoT security platform (formerly CyberX); Entra- native; integrated with Defender XDR.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
Nozomi Guardian
Nozomi Networks’ OT / IoT / IIoT security platform; Swiss vendor; Vantage cloud + Guardian on-prem; one of the three established OT- security leaders.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
snap7
Open-source Siemens S7 protocol library; talks to S7-200/300/400/1200/1500 PLCs; used for legitimate integration + ICS security testing.
License: LGPL-3.0-only (OSS) · Kind: library · Deploy: native, package · SSO: none
Suricata + ICS Rules
Suricata with ICS / SCADA-specific rule sets; Quickdraw / SCADAhacker / Emerging Threats ICS Pro feeds; OT-IDS coverage atop a standard Suricata sensor.
License: GPL-2.0-only (OSS) · Kind: service · Deploy: native, docker, package · SSO: none
Tenable.ot
Tenable’s OT-security platform (formerly Indegy); integrates with Tenable One for unified IT + OT vulnerability and exposure management.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML