Guard Engine
Active scanning and detection for files, processes and suspicious events in industrial infrastructure.
OT Security · Industrial Antivirus
Control Soft & Automation solution for threat monitoring, gateway scanning and protection of SCADA stations and industrial nodes.

Protection designed for OT
In an industrial network, high telemetry volume does not automatically mean an attack. CSA Guard correlates source, gateway, policy and expected communication rhythm before raising an alert.
Active scanning and detection for files, processes and suspicious events in industrial infrastructure.
Monitor gateways and transition points between equipment, OT networks and higher-level services.
Visibility into threats, events and deviations with investigation, history and traceability.
Observe communications and network behaviour without turning normal repetitive traffic into an alarm.
Controlled isolation of suspicious elements and policies adapted to gateways, assets and segments.
Centralized status, history and threat-intelligence sources for detection databases and rules.
Fewer false alarms
Data readers, meters, PLCs and gateways may transmit repetitive packets at short intervals. CSA Guard allows known sources, expected cycles and communication policies to be defined.
Filtering is not a blanket ignore rule: the system tracks deviations from the configured profile, changes in source, timing or behaviour and raises an alert when traffic no longer matches the legitimate process.
Single control centre
Unified status of Guard Engine, gateways, detection databases and events.
Notifications, severity, reports and evidence for intervention, analysis and audit.
Monitor critical components and highlight changes that require verification.
Controlled integration of ClamAV, URLhaus, ThreatFox, MalwareBazaar and YARA rules.
Centralized logs for scans, updates, policies, alerts and administrative actions.
Rules adapted to the role of each station, industrial area and gateway.
TECHNICAL REFERENCE
SCADA stations, gateways and industrial computers must be protected according to their operational role. Security controls should be introduced only after their production impact is understood.
Start with an inventory of devices, operating systems, communications and existing access paths. Identify critical stations, backups and administration responsibilities. Active discovery methods should be used only after evaluating their impact on sensitive devices.
Segmentation limits flows between zones, while remote access should be restricted to authorized users and devices. Routers, industrial firewalls and VLAN rules should be documented and tested. A VPN protects the channel but does not replace authentication, authorization and monitoring.
No. Endpoint protection, patching, segmentation, backups and incident response are complementary controls. CSA Guard functions should be evaluated for the equipment and architecture in the project; they do not automatically create compliance or fit every PLC.
Technical reference
Applied industrial protection