CMMC-Ready NDR for Industrial Infrastructure
ML detection on OT and IoT protocols. Built for compliance.
Built on the SIGMA Algorithm (patent pending) — predictive behavioral detection that catches what signatures miss. Air-gap native. No cloud. No telemetry. The plant's data stays at the plant. $999 perpetual per site. Buy once. Own forever.
Each card is an algorithm or engine. Arrows show how output feeds the next layer — no detector stands alone. Together they turn a stream of mystery scores into a single predictive alert.
An Isolation Forest — an unsupervised ML algorithm trained offline on representative traffic and applied to every flow. Catches what signatures don't: encrypted threats, novel malware, custom tooling.
anomaly_score in [0 .. 1] per flowHistogram-Based Outlier Score (Goldstein & Dengel, 2012) running online with Welford streaming per asset. Maintains a per-host baseline of expected feature ranges and flags windows that deviate — the same machinery catches network reliability issues and the early signal of host compromise.
Every 15 minutes, for every asset, SIGMA aggregates window stats and emits tokens — short labels representing observed behavior categories — each with a surprisal score in bits and an ATT&CK tactic. Translates raw drift into a security narrative an analyst can actually read.
Note: Rockfish's SIGMA is a behavioral tokenizer, not the public SIGMA-rules YAML grammar at sigmahq.io. Same name, different thing.
encrypted-ratio-high, unusual-port-mix, slow-handshake, …A Hidden Markov Model over the SIGMA token sequence per asset. Named for Occam's razor: when several attack paths could explain the observed sequence, pick the simplest. The Viterbi algorithm scores how strongly the recent sequence resembles a known attack path.
suppressed / investigate / present / elevatedThe Radial Sonar is the operator-facing view of the analytics stack. Every flow plotted by protocol (spoke) and by risk (radius). The radius is the compounded output of the four engines — a single visual where the layered prediction becomes obvious at a glance.
elevated. Outer-ring perimeter, where your eye lands first.The dashed threshold ring is the operator's risk-cutoff knob — everything outside it deserves attention. Time-window control replays the last 1–60 minutes so you can scrub through an unfolding incident frame by frame.
See a Sonar DemoDeploy Rockfish NDR in minutes. Single binary. No dependencies. Full pipeline.
Now we want to prove it.
We are looking for defense contractors and C3PAOs to deploy Rockfish NDR in a production environment at no cost. Slots are limited.
Requirements are simple: you run it, we support it, you tell us what you think. If that sounds like a fair trade, let's talk.