Agonist proves whether your OT security actually works — and makes every device on your industrial (OT) network visible. It safely puts your defenses to the test, so protection becomes something you can show, not just assume. All without stopping production.
Agonist, OT güvenliğinizin gerçekten çalışıp çalışmadığını kanıtlar — ve endüstriyel (OT) ağınızdaki her cihazı görünür kılar. Savunmanızı güvenle sınar; böylece güvenlik bir varsayım değil, gösterebildiğiniz bir gerçek olur. Hepsi üretimi durdurmadan.
Industrial (OT) networks differ from IT: they can't tolerate downtime, devices are fragile, and classic security tools don't fit. Three problems organizations get stuck on:Üretim ağları (OT), BT'den farklıdır: kesintiye tahammülü yoktur, cihazlar kırılgandır, klasik güvenlik araçları buraya uymaz. Kurumların takıldığı üç temel sorun:
One platform, one console — see them in action further down.Tek platform, tek panel — aşağıda iş başında görün.
No deep OT expertise needed. Every test follows the same simple flow.Derin OT uzmanlığı gerekmez. Her test aynı basit akışı izler.
A device on your network, or the safe Lab simulator — you decide.Ağınızdaki bir cihaz ya da güvenli Lab simülatörü — siz seçersiniz.
A realistic OT protocol behavior or command set, run in a controlled and harmless way.Gerçekçi bir OT protokol davranışı ya da komut seti, kontrollü ve zararsız biçimde çalışır.
See whether your SIEM/IPS raised an alarm — or the attack passed silently.SIEM/IPS'iniz alarm üretti mi, yoksa saldırı sessizce mi geçti — görün.
A clear pass/fail record — ready for audit and for hardening what failed.Net bir geçti/kaldı kaydı — denetime ve eksiği sertleştirmeye hazır.
Real views from the product, next to a plain-language explanation. Click any image to enlarge.Üründen gerçek görünümler ve yanında sade anlatım. Büyütmek için bir görsele tıklayın.
The dashboard shows your whole OT security posture at a glance — how many devices, how many vulnerabilities, whether your agents are online, and recent test activity.Panel, OT güvenlik durumunuzu tek bakışta gösterir — kaç cihaz, kaç zafiyet, agent'lar çevrimiçi mi ve son test etkinliği.
Agonist automatically finds every industrial device and builds a live inventory — vendor, model, protocols and zone — so nothing hides on your network.Agonist her endüstriyel cihazı otomatik bulur ve canlı bir envanter çıkarır — üretici, model, protokol ve bölge — ağınızda hiçbir şey saklanamaz.
Choose a target and run real OT attack techniques in a controlled, harmless way. Point them at the safe Lab simulator or, when you're ready, a real device you own.Bir hedef seçin ve gerçek OT saldırı tekniklerini kontrollü, zararsız biçimde çalıştırın. Güvenli Lab simülatörüne ya da hazır olduğunuzda sahip olduğunuz gerçek bir cihaza yöneltin.
After the tests, see exactly which attacks your defenses caught and which slipped through — the evidence auditors and management ask for.Testlerden sonra, savunmanızın hangi saldırıları yakaladığını, hangilerinin kaçtığını tam görün — denetçilerin ve yönetimin istediği kanıt.
Pick how gentle the scan is: fully passive (no packets), safe discovery (the production default), or detailed — only when you enable it.Taramanın ne kadar nazik olacağını seçin: tamamen pasif (paket yok), güvenli keşif (üretim varsayılanı) ya da detaylı — yalnız siz açtığınızda.
In production networks the real issue isn't "being able to test" — it's testing without causing harm. With Agonist you choose the method to fit your need: on the most sensitive network you can listen fully passively — sending no packets at all — and go more detailed when needed. The default is the safest method, designed for production.Üretim ağlarında asıl mesele "test edebilmek" değil, zarar vermeden test edebilmektir. Agonist'te yöntemi ihtiyacınıza göre seçersiniz: en hassas ağda tamamen pasif — hiç paket göndermeden — dinleyebilir, gerektiğinde daha detaylı inceleyebilirsiniz. Varsayılan, üretim için tasarlanmış en güvenli yöntemdir.
“First, do no harm.”“Önce zarar verme.”
On a production network the default is the safest, least-touch method; in the most sensitive environments you can run fully passively. Broader inspection only kicks in when you enable it, usually in test environments — the decision is always yours.Üretim ağında varsayılan, cihaza en az dokunan güvenli yöntemdir; en hassas ortamlarda tamamen pasif çalışabilirsiniz. Daha geniş inceleme yalnız siz açtığınızda ve genellikle test ortamlarında devreye girer — karar her zaman sizde.
You can deploy Agonist as a permanent product — or consume it as a service from a partner, whether as an ongoing managed service or a short, project-based engagement.Agonist'i kalıcı bir ürün olarak kurabilir — ya da bir iş ortağından hizmet olarak alabilirsiniz: ister sürekli yönetilen hizmet, ister belirli bir ihtiyaç için kısa, proje bazlı.
You deploy and operate the product yourself — cloud, on-premise, hybrid or fully offline. Inventory, tests and reports stay with you.Ürünü kendiniz kurar ve sürekli işletirsiniz — bulut, şirket-içi, hibrit veya tam çevrimdışı. Envanter, test ve raporlar sizde kalır.
A service provider or partner runs Agonist for you — you just receive the results and reports. It can be continuous (a managed subscription, multiple sites from one console) or short-term for a specific need: a tabletop exercise, a vulnerability assessment or an attack simulation. The partner works with a license from the vendor; you don't own the product.Bir hizmet sağlayıcı ya da iş ortağı Agonist'i sizin için işletir — siz yalnız sonuçları ve raporları alırsınız. Sürekli (yönetilen abonelik, tek panelden çok saha) olabilir ya da belirli bir ihtiyaç için kısa süreli: masabaşı tatbikatı, zafiyet analizi veya saldırı simülasyonu. İş ortağı üreticiden aldığı lisansla çalışır; ürüne siz sahip olmazsınız.
For IT / security teams: how it's built and where it runs. Click to expand.BT / güvenlik ekipleri için: nasıl kurulu ve nerede çalışır. Açmak için tıklayın.
Your organization deploys only two things: the Central Server that runs the management console, and the Field Agent on the industrial network. Both are fed by continuously updated OT threat intelligence in the background.Kurumunuzun kurduğu yalnızca iki şey vardır: yönetim panelini çalıştıran Merkez Sunucu ve endüstriyel ağdaki Saha Agent'ı. İkisini de, arka planda sürekli güncellenen bir OT tehdit istihbaratı besler.
Two components fit into a familiar layout: the Central Server in the management layer (DMZ or IT), the Field Agent on the industrial network. For isolated OT segments that can't be reached directly, agents are chained master–slave — without breaking isolation at all.İki bileşen, tanıdık bir yerleşime oturur: Merkez Sunucu yönetim katmanında (DMZ ya da BT), Saha Agent endüstriyel ağda. Doğrudan erişilemeyen izole OT segmentleri için agent'lar master–slave zincirlenir — izolasyonu hiç bozmadan.
When you run the product yourself, the capabilities are the same in every scenario. The only thing that changes is where the Central Server runs and where your data sits. Four alternatives based on your cloud policy, critical-infrastructure and data-sovereignty requirements, and network:Ürünü kendiniz işlettiğinizde, yetenekler her senaryoda aynıdır. Değişen tek şey — Merkez Sunucu'nun nerede çalıştığı ve verinizin nerede durduğu. Bulut politikanız, kritik altyapı ve veri egemenliği gereksinimleri ve ağ yapınıza göre dört alternatif:
“You stay in the field — we run the management.”“Siz sahada olun — yönetimi biz üstlenelim.”
“Your data never leaves the building.”“Veriniz binanızdan çıkmasın.”
“Control is yours, freshness is automatic.”“Kontrol sizde, güncellik otomatik.”
“No internet — no problem.”“İnternet yok — sorun değil.”
| CriterionKriter | Cloud-ManagedBulut‑Yönetilen | On-PremiseŞirket‑İçi | HybridHibrit | Fully OfflineTam Çevrimdışı |
|---|---|---|---|---|
| OT data stays on siteOT verisi tesisten çıkmaz | nohayır | yesevet | yesevet | yesevet |
| Internet connectivity needİnternet bağlantısı ihtiyacı | continuoussürekli | limitedsınırlı | continuoussürekli | none (air-gap)yok (air‑gap) |
| Critical infrastructure / data sovereigntyKritik altyapı / veri egemenliği | mediumorta | highyüksek | highyüksek | highesten yüksek |
| Who carries setup & maintenanceKurulum & bakım yükü kimde | vendorüreticide | organizationkurumda | sharedpaylaşımlı | organizationkurumda |
| Content freshnessİçerik güncelliği | automaticotomatik | via packagepaket ile | automaticotomatik | manual · youelle · siz |
| Multi-site / service-provider mgmtÇok‑tesis / hizmet sağlayıcı yönetimi | yesevet | singletekil | optionalisteğe bağlı | singletekil |
If the OT network is reachable from the center, one agent is enough.OT ağına merkezden ulaşılabiliyorsa tek agent yeter.
If the OT segment can't be reached directly, the master sits at the gateway and the slave in the isolated segment reaches out only via the master — without breaking isolation.OT segmentine doğrudan erişilemiyorsa master ağ geçidinde durur, izole segmentteki slave yalnız master üzerinden ulaşır — izolasyonu bozmadan.
Virtual machine (VMware/OVA — zero-touch), Docker, or a locked-down hardware appliance.Sanal makine (VMware/OVA — sıfır‑dokunuş), Docker ya da kilitli donanım cihazı.