OT cyber-range on demand. Ground-truth per event.
Physics-honest Virtual SCADA telemetry + ground-truth-labelled MITRE ATT&CK for ICS attack datasets + air-gapped Virtual PLC images, composed into a sealed cyber-range your IDS, SOC platform, or red-team engagement can score against. Every run produces a signed evidence bundle with per-event technique labels — and deployable detection rules.
Every ICS attack bundle ships ready-to-deploy detection rules across 4 industry-standard formats. Import the format that matches your SOC stack — the rules trigger on the same attack signatures the engine emits, so the bundle is self-detecting.
Generic SIEM-agnostic detection rules. One file per canonical attack-event archetype (e.g. modbus_read, alarm_acknowledgement, remote_access_session). Translates to Splunk / Elastic / Sentinel / Graylog via `sigmac --target <backend>`.
$ sigmac --target splunk sigma/*.yml > radmah-ics.splunk.confFile / binary signature rules. Same archetypes as Sigma; useful for forensic scans of captured pcaps / dropped tooling. Compiles with `yarac` for production deployment.
$ yarac yara/*.yar radmah-ics.yarcSingle multi-rule file for the Suricata IDS engine. Carries every protocol-level signature the generator emits with modbus.access constraints where applicable.
$ cp suricata/radmah-ics.rules /etc/suricata/rules/ && suricatactl reloadSingle multi-rule file for the Snort IDS engine. Same protocol signatures as the Suricata file in Snort's rule syntax.
$ cp snort/radmah-ics.rules /etc/snort/rules/ && systemctl reload snortPer-category counts are computed at render time from the bundle’s actual detection_rules.tar.gz contents — no hardcoded values, no drift with future generator revisions. The README inside the tar.gz documents the full archetype list + per-rule rationale.
Four workflows OT security teams pay for first.
IDS / SOC training sets
Run a MITRE ATT&CK for ICS attack mix against a physics-honest plant simulation and capture every packet at wire level. Your detection team gets a labelled dataset with ground-truth technique IDs on every event — the thing vendor-supplied datasets almost never give you.
Red-team + purple-team exercise
Spin up an air-gapped Virtual PLC image inside your VPC, run the engagement against it, capture the full pcapng + per-event ground truth, then retire the environment without a single real plant touching the exercise.
Operator training scenarios
Scripted attack sequences against a realistic SCADA HMI — operators learn to recognise the shape of a real incident (valve oscillation, sensor spoof, unauthorized setpoint change) in an environment with no production blast radius.
Regression-test your anomaly detector
Every generation run is byte-reproducible from the sealed contract + seed. Your anomaly detector's performance on v3 can be compared directly against v2 on the same attack sequence — no drift, no “we re-captured the dataset” excuse.
Classified networks, critical infrastructure, export control.
Air-gapped by design
The Virtual PLC runs entirely inside your VPC (a Docker image shipped under an Enterprise licence). No network path out, no telemetry back to RadMah AI — suitable for classified networks under the appropriate engagement.
NERC CIP-compatible
Cyber-range datasets contain no real BES Cyber System data and can be generated entirely off the operational network. The ground-truth labels and sealed evidence bundle satisfy the audit-trail expectations for CIP-008 (incident reporting) exercise scenarios.
FedRAMP / ITAR-compatible Enterprise deployment
The Enterprise on-premise deployment has no AWS dependency and can be delivered as a signed container set for classified or export-controlled networks. Contact our security team for deployment details.
Ground-truth evidence per exercise
Every generation run ships a sealed evidence bundle: the contract, the per-step run log, the quality report, the hash manifest, and a per-event ground-truth file that maps each packet / log entry / control-surface command to a technique ID.
Three products. One sealed cyber-range.
Virtual SCADA
Five OT protocols at binary-spec level (Modbus, OPC-UA, BACnet, MQTT, DNP3), with IEC 61850 added by Enterprise VPLC. 67 CI-gated plant templates spanning water, power, chemical, oil & gas. Wire-level pcapng capture.
ExploreICS Security
32 engine-implemented MITRE ATT&CK for ICS techniques with per-event ground-truth labels, plus deployable Sigma / YARA / Suricata / Snort rules. Configurable benign-to-attack density and dwell time.
ExploreVirtual PLC
An air-gapped signed Docker image for inside-VPC deployment. Ladder-logic programmable. Red-team / operator-training friendly. No external network dependency.
ExploreClose the cyber-range-data gap.
Free tier: 25 runs a month. Enterprise: signed-container delivery for inside-VPC deployment, an air-gapped Virtual PLC licence, a dedicated OT security engineer, and a 21 CFR / NERC CIP validation pack under NDA.