Industries · Industrial Cybersecurity

OT cyber-range on demand. Ground-truth per event.

Physics-honest Virtual SCADA telemetry + ground-truth-labelled MITRE ATT&CK for ICS attack datasets + air-gapped Virtual PLC images, composed into a sealed cyber-range your IDS, SOC platform, or red-team engagement can score against. Every run produces a signed evidence bundle with per-event technique labels — and deployable detection rules.

5 SCADA protocols + IEC 61850 VPLC 32 engine-implemented ATT&CK ICS techniques 67 CI-gated plant templates Air-gapped Enterprise deployment
app.radmah.ai / evidenceproduct view
Detection rules bundle
48 rule files + 1 README Download .tar.gz

Every ICS attack bundle ships ready-to-deploy detection rules across 4 industry-standard formats. Import the format that matches your SOC stack — the rules trigger on the same attack signatures the engine emits, so the bundle is self-detecting.

Sigma23 files (.yml)

Generic SIEM-agnostic detection rules. One file per canonical attack-event archetype (e.g. modbus_read, alarm_acknowledgement, remote_access_session). Translates to Splunk / Elastic / Sentinel / Graylog via `sigmac --target <backend>`.

$ sigmac --target splunk sigma/*.yml > radmah-ics.splunk.conf
YARA23 files (.yar)

File / binary signature rules. Same archetypes as Sigma; useful for forensic scans of captured pcaps / dropped tooling. Compiles with `yarac` for production deployment.

$ yarac yara/*.yar radmah-ics.yarc
Suricata1 file (.rules)

Single multi-rule file for the Suricata IDS engine. Carries every protocol-level signature the generator emits with modbus.access constraints where applicable.

$ cp suricata/radmah-ics.rules /etc/suricata/rules/ && suricatactl reload
Snort1 file (.rules)

Single multi-rule file for the Snort IDS engine. Same protocol signatures as the Suricata file in Snort's rule syntax.

$ cp snort/radmah-ics.rules /etc/snort/rules/ && systemctl reload snort

Per-category counts are computed at render time from the bundle’s actual detection_rules.tar.gz contents — no hardcoded values, no drift with future generator revisions. The README inside the tar.gz documents the full archetype list + per-rule rationale.

◆ Where teams use it

Four workflows OT security teams pay for first.

IDS / SOC training sets

Run a MITRE ATT&CK for ICS attack mix against a physics-honest plant simulation and capture every packet at wire level. Your detection team gets a labelled dataset with ground-truth technique IDs on every event — the thing vendor-supplied datasets almost never give you.

Red-team + purple-team exercise

Spin up an air-gapped Virtual PLC image inside your VPC, run the engagement against it, capture the full pcapng + per-event ground truth, then retire the environment without a single real plant touching the exercise.

Operator training scenarios

Scripted attack sequences against a realistic SCADA HMI — operators learn to recognise the shape of a real incident (valve oscillation, sensor spoof, unauthorized setpoint change) in an environment with no production blast radius.

Regression-test your anomaly detector

Every generation run is byte-reproducible from the sealed contract + seed. Your anomaly detector's performance on v3 can be compared directly against v2 on the same attack sequence — no drift, no “we re-captured the dataset” excuse.

◆ Compliance posture

Classified networks, critical infrastructure, export control.

Air-gapped by design

The Virtual PLC runs entirely inside your VPC (a Docker image shipped under an Enterprise licence). No network path out, no telemetry back to RadMah AI — suitable for classified networks under the appropriate engagement.

NERC CIP-compatible

Cyber-range datasets contain no real BES Cyber System data and can be generated entirely off the operational network. The ground-truth labels and sealed evidence bundle satisfy the audit-trail expectations for CIP-008 (incident reporting) exercise scenarios.

FedRAMP / ITAR-compatible Enterprise deployment

The Enterprise on-premise deployment has no AWS dependency and can be delivered as a signed container set for classified or export-controlled networks. Contact our security team for deployment details.

Ground-truth evidence per exercise

Every generation run ships a sealed evidence bundle: the contract, the per-step run log, the quality report, the hash manifest, and a per-event ground-truth file that maps each packet / log entry / control-surface command to a technique ID.

Close the cyber-range-data gap.

Free tier: 25 runs a month. Enterprise: signed-container delivery for inside-VPC deployment, an air-gapped Virtual PLC licence, a dedicated OT security engineer, and a 21 CFR / NERC CIP validation pack under NDA.