Prove whether your OT security actually works — without touching production.
Agonist proves whether your OT security actually works — and makes every device on your industrial (OT) network visible. It safely puts your defenses to the test, so protection becomes something you can show, not just assume. All without stopping production.
Agonist proves whether your OT security actually works — and makes every device on your industrial (OT) network visible. It safely puts your defenses to the test, so protection becomes something you can show, not just assume. All without stopping production.
Industrial (OT) networks differ from IT: they can't tolerate downtime, devices are fragile, and classic security tools don't fit. Three problems organizations get stuck on:
One platform, one console — see them in action further down.
No deep OT expertise needed. Every test follows the same simple flow.
A device on your network, or the safe Lab simulator — you decide.
A realistic OT protocol behavior or command set, run in a controlled and harmless way.
See whether your SIEM/IPS raised an alarm — or the attack passed silently.
A clear pass/fail record — ready for audit and for hardening what failed.
Real views from the product, next to a plain-language explanation. Click any image to enlarge.
The dashboard shows your whole OT security posture at a glance — how many devices, how many vulnerabilities, whether your agents are online, and recent test activity.

Agonist automatically finds every industrial device and builds a live inventory — vendor, model, protocols and zone — so nothing hides on your network.


Choose a target and run real OT attack techniques in a controlled, harmless way. Point them at the safe Lab simulator or, when you're ready, a real device you own.


After the tests, see exactly which attacks your defenses caught and which slipped through — the evidence auditors and management ask for.


Pick how gentle the scan is: fully passive (no packets), safe discovery (the production default), or detailed — only when you enable it.

In production networks the real issue isn't “being able to test” — it's testing without causing harm. With Agonist you choose the method to fit your need: on the most sensitive network you can listen fully passively — sending no packets at all — and go more detailed when needed. The default is the safest method, designed for production.
“First, do no harm.”
On a production network the default is the safest, least-touch method; in the most sensitive environments you can run fully passively. Broader inspection only kicks in when you enable it, usually in test environments — the decision is always yours.

You can deploy Agonist as a permanent product — or consume it as a service from a partner, whether as an ongoing managed service or a short, project-based engagement.
You deploy and operate the product yourself — cloud, on-premise, hybrid or fully offline. Inventory, tests and reports stay with you.
A service provider or partner runs Agonist for you — you just receive the results and reports. It can be continuous (a managed subscription, multiple sites from one console) or short-term for a specific need: a tabletop exercise, a vulnerability assessment or an attack simulation. The partner works with a license from the vendor; you don't own the product.
For IT / security teams: how it's built and where it runs. Click to expand.
Your organization deploys only two things: the Central Server that runs the management console, and the Field Agent on the industrial network. Both are fed by continuously updated OT threat intelligence in the background.
Two components fit into a familiar layout: the Central Server in the management layer (DMZ or IT), the Field Agent on the industrial network. For isolated OT segments that can't be reached directly, agents are chained master–slave — without breaking isolation at all.
When you run the product yourself, the capabilities are the same in every scenario. The only thing that changes is where the Central Server runs and where your data sits. Four alternatives based on your cloud policy, critical-infrastructure and data-sovereignty requirements, and network:
“You stay in the field — we run the management.”
“Your data never leaves the building.”
“Control is yours, freshness is automatic.”
“No internet — no problem.”
| Criterion | Cloud-Managed | On-Premise | Hybrid | Fully Offline |
|---|---|---|---|---|
| OT data stays on site | no | yes | yes | yes |
| Internet connectivity need | continuous | limited | continuous | none (air-gap) |
| Critical infrastructure / data sovereignty | medium | high | high | highest |
| Who carries setup & maintenance | vendor | organization | shared | organization |
| Content freshness | automatic | via package | automatic | manual · you |
| Multi-site / service-provider mgmt | yes | single | optional | single |
If the OT network is reachable from the center, one agent is enough.
If the OT segment can't be reached directly, the master sits at the gateway and the slave in the isolated segment reaches out only via the master — without breaking isolation.
Virtual machine (VMware/OVA — zero-touch), Docker, or a locked-down hardware appliance.
A demo, a pilot, or a question — send a message, or email info@agonist.dev directly.