Industrial systems you can break safely.
Physics-honest SCADA telemetry, Docker-delivered Virtual PLCs, and ground-truth-labelled ICS attack datasets.
All under the same sealed evidence chain as our synthetic data. Every run is reproducible and byte-identical under the same seed — so benchmarks stay stable, regressions stay visible, and no synthetic-data vendor offers this range.
Water treatment pump station SCADA, 60 seconds, Modbus + OPC-UA, 8 signals: discharge pressure, suction pressure, motor temperature, VFD output, flow rate, tank level, and an over-pressure alarm. [Protocols: modbus, opcua] [Duration: 1m] [Poll: 1 Hz] [Streaming: off]
small_wwtpRun a SCADA simulation for the water treatment pump station.
Verify the quality and provenance of the simulated data.
One physics engine. One evidence chain.
Telemetry, simulator and attack data share the same sealed-contract pipeline — so a SCADA run can be replayed inside an air-gapped Virtual PLC and labelled by ICS Security, without leaving the platform.
Virtual SCADA
Real telemetry. Real protocols. Replayable physics.
Continuous, physics-honest sensor telemetry over Modbus/TCP, OPC-UA, BACnet, MQTT and DNP3 — driving analytics, an IDS, or operator training, and feeding the same evidence chain.
- Physics-honest plant model fit to any process you describe — not a fixed catalogue
- Disturbance library: storm-surge, blower failure, sensor drift
- pcapng + signals.parquet + alarms.json sealed per run
Virtual PLC
Air-gapped PLC simulation, Docker-delivered.
An enterprise Docker image for air-gapped training, red-team exercises and OT vendor PoCs. Runs inside your VPC — no telemetry, logs or model weights leave.
- Allen-Bradley / Siemens / Schneider rung semantics
- Per-tag calibrated response model for analog signals
- Event-driven state machines with safety interlocks
ICS Security
Ground-truth attack data for SOC training.
MITRE ATT&CK for ICS attack datasets with per-event ground-truth labels, a full pcapng capture, a signals.parquet trace, and a benign-to-attack mix you dial per scenario. Score precision and recall mechanically against the truth file — no hand-mapping, no drift.
- Per-event technique ID + tactic ID + payload hash + target asset
- Configurable benign/attack ratio, seeded and byte-stable
- pcapng + truth.ndjson + signals.parquet in one .tar.zst
- Verifiable offline with the verifier — no phone-home
Not a fixed catalogue — any plant you can describe.
There is no menu of supported industries to fit your site into. Describe the process and the engine calibrates a physics-honest model for it — the same LLM-driven approach that lets Mock fabricate a dataset for any industry from one sentence.
Describe the plant
Your process, the analog loops, the discrete states, the protocols — in plain English or a P&ID.
Calibrated per loop
A physics-honest response model is fit for every analog loop; event-driven state machines with safety interlocks cover discrete state.
Sealed pack
pcapng + signals.parquet + alarms.json, byte-stable under the seed, sealed into one verifiable bundle.
SCADA + ICS, end-to-end, in one bundle.
Live SCADA telemetry
A realistic disturbance schedule drives process dynamics in real time.
Attack injection
Inject command-injection, replay and MITM events on real protocol traffic.
IDS / SOC capture
pcapng captures the wire; parquet captures the process; truth.ndjson labels both.
Sealed evidence
A hash-chained .tar.zst — verifiable offline by your SOC platform owner.
Posture that satisfies OT security review.
Per-deployment key
The evidence chain is signed locally; no licence-server phone-home.
Real protocols
5 SCADA protocols (Modbus, OPC-UA, BACnet, MQTT, DNP3); Virtual PLC adds IEC 61850.
Physics honest
Per-tag calibrated response models; event-driven state machines with safety interlocks.
Single Docker image
Distroless, signed with cosign, offline registry supported.
Bring your P&ID. Keep a sealed cyber-range bundle.
A 45-minute session: describe a plant and one or two adversary behaviours; we generate the SCADA run and the labelled attack mix, and you keep the sealed bundle to load into your IDS/SOC pipeline.