Get listed

OT and IoT

OT Monitoring Tools in 2026: 6 Options for Industrial Networks

Span the industrial network and parse the controller protocol. A laptop agent on the cabin PC never saw that traffic.

Expertise: OT and IoT · Level: Intermediate · 6 min read

NIST SP 800-82 Rev. 3 (September 2023) says anti-malware software may not be available for PLCs and DCS, so malware protection cannot be applied to those endpoints. The compensating control it names is a firewall with deep packet inspection, not another process on the cabin PC.

Windows telemetry on that laptop never saw the PLC programming session. The session ran a proprietary control protocol the endpoint agent does not decode. NIST also places OT network monitoring on SPAN ports or passive network taps, with host-based tools only on compatible devices such as HMIs, SCADA servers, and engineering workstations.

The cabin laptop still needs an endpoint agent, and that work stays on EDR tools. A passive TAP you operate, a vendor OT platform, and the IT detection grid you already staff see different layers of the same plant. Defense only. This page will not walk a protocol attack.

How we evaluated

We read first-party docs, source, licenses, and release notes, and we treat a marketing page as a claim, not as proof that two products do the same work.

We cared about whether the product parses a protocol the laptop agent cannot take, whether you operate the tap, whether the page stays on visibility, and whether an industrial suite and a hunt grid are named as different installs.

We read first-party docs, licenses, and release notes. Unless a write-up says otherwise, we did not run a paid tenant.

ToolBest forWhat to check
MalcolmOpen ICS-friendly traffic analysisICS-friendly bundle ยท BSD-3-Clause ยท you host it
ZeekThe language for the spanProtocol parsers ยท BSD-3-Clause ยท you write the script
Security OnionSOC bundle that can sit on a spanZeek Suricata Elastic ยท GPL-2.0 ยท you operate the bundle
Nozomi NetworksKnown OT visibility optionProtocol visibility on the public docs ยท commercial ยท industrial option
ClarotyKnown OT security platformAsset and threat stories they publish ยท commercial ยท enterprise
DragosKnown OT threat monitoringOT detections on the public docs ยท commercial ยท plant-shaped
How the tools differ
Open ICS
Industrial OEM
Packet language
SOC bundle
1

Malcolm

Best for open ICS-friendly traffic analysis

Malcolm

Malcolm is Idaho National Laboratory’s traffic analysis bundle with ICS-friendly pieces. Open. You operate it.

A plant that cannot buy an industrial suite this year can still parse a span. You staff it. It is not a 24/7 MDR contract. No exploit guide.

Key features

  • Packet analysis bundle
  • ICS-aware docs
  • You host it
  • Open license

Why we like it

An open bundle that already thinks about industrial traffic is the parser you can run this year.

Limits

You staff it. Not a 24/7 MDR contract. No exploit guide.

2

Zeek

Best for the language for the span

Zeek

Zeek is the network analysis language. Not OT-only. You write scripts for the protocol you actually have.

If Malcolm or Onion is the bundle, Zeek is often the brain. Name it. You write the script. It is not a plant vendor. It is not EDR.

Key features

  • Protocol parsers
  • Script language
  • BSD
  • Huge community

Why we like it

A language for the span is how you see a protocol the agent cannot take.

Limits

You write the script. Not a plant vendor. Not EDR.

3

Security Onion

Best for SOC bundle that can sit on a span

Security Onion

Security Onion is on the SIEM list. Here it is the bundle you can point at a tap. Overlap declared.

If the SOC already runs Onion, ask for an OT tap before a fourth console. You staff the cluster. It is not an industrial-option replacement in a quarter. Open SIEM alternatives.

Key features

  • Zeek Suricata Elastic
  • You operate it
  • Hunt UIs
  • GPL

Why we like it

Pointing the SOC bundle you already staff at a tap is cheaper than a fourth console.

Limits

You staff the cluster. Not an industrial replacement in a quarter. Open SIEM alternatives.

4

Nozomi Networks

Best for known OT visibility option

Nozomi Networks

Nozomi sells OT and IoT visibility. Known industrial option.

Steering-committee name in plants. Commercial. No payload content.

Key features

  • Protocol visibility on the public docs
  • Asset inventory stories
  • Enterprise
  • Commercial

Why we like it

A visibility option plants already wrote down is the first known OEM row.

Limits

Commercial. No payload content.

5

Claroty

Best for known OT security platform

Claroty

Claroty is the other known industrial name. xDome and neighbors on their current site.

Second commercial option so the page is not one logo. Commercial. OT-first marketing is first-party language, not a score.

Key features

  • Asset and threat stories they publish
  • Enterprise
  • Commercial
  • OT-first marketing

Why we like it

A second industrial platform is here so the shortlist matches the plant RFP, not a single-logo myth.

Limits

Commercial. Defense only.

6

Dragos

Best for known OT threat monitoring

Dragos

Dragos sells OT threat monitoring and intel. Known in critical infrastructure conversations.

Third commercial option. Intel is their pitch. We do not recap it as a score. Defense only.

Key features

  • OT detections on the public docs
  • Intel add-on
  • Commercial
  • Plant-shaped

Why we like it

Threat monitoring with intel attached is why this name shows up next to the other two shelves.

Limits

Commercial. Defense only.

What we left out

  • Microsoft Defender for IoT. Enterprises already on Defender want the first-party plant SKU. Three industrial shelves already sit here, and the EDR list owns the Microsoft agent on the laptop.
  • Tenable OT. Vulnerability programs want OT next to the scanner they already run. This page is protocol visibility, not a VM-platform add-on, and three OEM shelves are enough.

Zeek threads treat scripts as the way to see a protocol. We keep OT on that side of the line: parse, do not exploit.

Questions before you buy

Ask these before the trial clock starts. Vague answers usually mean a neighboring category.

  1. Which protocol on our span does this parser actually decode?
  2. Do we operate the watcher, or are we buying a sensor and a contract we cannot dump?
  3. Where does the laptop in the cabin go, and which list owns that agent?

Watch the protocol on a span you own. Do not put EDR on the PLC and hope.

FAQs

Can I put EDR on the PLC?

Usually no. That is why this pillar exists. Endpoint owns the laptop in the cabin.

Is this a SIEM list?

No. Onion appears because it can sit on a tap. The SIEM list is the console job.

Will you publish protocol attack steps?

No. Defense and parsers only.

Is this a scored bake-off?

No. Order is editorial.