OT and IoT
OT Monitoring Tools in 2026: 6 Options for Industrial Networks
Span the industrial network and parse the controller protocol. A laptop agent on the cabin PC never saw that traffic.
Expertise: OT and IoT · Level: Intermediate · 6 min read
NIST SP 800-82 Rev. 3 (September 2023) says anti-malware software may not be available for PLCs and DCS, so malware protection cannot be applied to those endpoints. The compensating control it names is a firewall with deep packet inspection, not another process on the cabin PC.
Windows telemetry on that laptop never saw the PLC programming session. The session ran a proprietary control protocol the endpoint agent does not decode. NIST also places OT network monitoring on SPAN ports or passive network taps, with host-based tools only on compatible devices such as HMIs, SCADA servers, and engineering workstations.
The cabin laptop still needs an endpoint agent, and that work stays on EDR tools. A passive TAP you operate, a vendor OT platform, and the IT detection grid you already staff see different layers of the same plant. Defense only. This page will not walk a protocol attack.
How we evaluated
We read first-party docs, source, licenses, and release notes, and we treat a marketing page as a claim, not as proof that two products do the same work.
We cared about whether the product parses a protocol the laptop agent cannot take, whether you operate the tap, whether the page stays on visibility, and whether an industrial suite and a hunt grid are named as different installs.
We read first-party docs, licenses, and release notes. Unless a write-up says otherwise, we did not run a paid tenant.
| Tool | Best for | What to check |
|---|---|---|
| Malcolm | Open ICS-friendly traffic analysis | ICS-friendly bundle ยท BSD-3-Clause ยท you host it |
| Zeek | The language for the span | Protocol parsers ยท BSD-3-Clause ยท you write the script |
| Security Onion | SOC bundle that can sit on a span | Zeek Suricata Elastic ยท GPL-2.0 ยท you operate the bundle |
| Nozomi Networks | Known OT visibility option | Protocol visibility on the public docs ยท commercial ยท industrial option |
| Claroty | Known OT security platform | Asset and threat stories they publish ยท commercial ยท enterprise |
| Dragos | Known OT threat monitoring | OT detections on the public docs ยท commercial ยท plant-shaped |
Malcolm
Best for open ICS-friendly traffic analysis

Malcolm is Idaho National Laboratory’s traffic analysis bundle with ICS-friendly pieces. Open. You operate it.
A plant that cannot buy an industrial suite this year can still parse a span. You staff it. It is not a 24/7 MDR contract. No exploit guide.
Key features
- Packet analysis bundle
- ICS-aware docs
- You host it
- Open license
Why we like it
An open bundle that already thinks about industrial traffic is the parser you can run this year.
Limits
You staff it. Not a 24/7 MDR contract. No exploit guide.
Zeek
Best for the language for the span

Zeek is the network analysis language. Not OT-only. You write scripts for the protocol you actually have.
If Malcolm or Onion is the bundle, Zeek is often the brain. Name it. You write the script. It is not a plant vendor. It is not EDR.
Key features
- Protocol parsers
- Script language
- BSD
- Huge community
Why we like it
A language for the span is how you see a protocol the agent cannot take.
Limits
You write the script. Not a plant vendor. Not EDR.
Security Onion
Best for SOC bundle that can sit on a span

Security Onion is on the SIEM list. Here it is the bundle you can point at a tap. Overlap declared.
If the SOC already runs Onion, ask for an OT tap before a fourth console. You staff the cluster. It is not an industrial-option replacement in a quarter. Open SIEM alternatives.
Key features
- Zeek Suricata Elastic
- You operate it
- Hunt UIs
- GPL
Why we like it
Pointing the SOC bundle you already staff at a tap is cheaper than a fourth console.
Limits
You staff the cluster. Not an industrial replacement in a quarter. Open SIEM alternatives.
Nozomi Networks
Best for known OT visibility option

Nozomi sells OT and IoT visibility. Known industrial option.
Steering-committee name in plants. Commercial. No payload content.
Key features
- Protocol visibility on the public docs
- Asset inventory stories
- Enterprise
- Commercial
Why we like it
A visibility option plants already wrote down is the first known OEM row.
Limits
Commercial. No payload content.
Claroty
Best for known OT security platform

Claroty is the other known industrial name. xDome and neighbors on their current site.
Second commercial option so the page is not one logo. Commercial. OT-first marketing is first-party language, not a score.
Key features
- Asset and threat stories they publish
- Enterprise
- Commercial
- OT-first marketing
Why we like it
A second industrial platform is here so the shortlist matches the plant RFP, not a single-logo myth.
Limits
Commercial. Defense only.
Dragos
Best for known OT threat monitoring

Dragos sells OT threat monitoring and intel. Known in critical infrastructure conversations.
Third commercial option. Intel is their pitch. We do not recap it as a score. Defense only.
Key features
- OT detections on the public docs
- Intel add-on
- Commercial
- Plant-shaped
Why we like it
Threat monitoring with intel attached is why this name shows up next to the other two shelves.
Limits
Commercial. Defense only.
What we left out
- Microsoft Defender for IoT. Enterprises already on Defender want the first-party plant SKU. Three industrial shelves already sit here, and the EDR list owns the Microsoft agent on the laptop.
- Tenable OT. Vulnerability programs want OT next to the scanner they already run. This page is protocol visibility, not a VM-platform add-on, and three OEM shelves are enough.
Zeek threads treat scripts as the way to see a protocol. We keep OT on that side of the line: parse, do not exploit.
Questions before you buy
Ask these before the trial clock starts. Vague answers usually mean a neighboring category.
- Which protocol on our span does this parser actually decode?
- Do we operate the watcher, or are we buying a sensor and a contract we cannot dump?
- Where does the laptop in the cabin go, and which list owns that agent?
Watch the protocol on a span you own. Do not put EDR on the PLC and hope.
FAQs
Can I put EDR on the PLC?
Usually no. That is why this pillar exists. Endpoint owns the laptop in the cabin.
Is this a SIEM list?
No. Onion appears because it can sit on a tap. The SIEM list is the console job.
Will you publish protocol attack steps?
No. Defense and parsers only.
Is this a scored bake-off?
No. Order is editorial.