endpoint detection for OT.

99% of attacker activity in industrial environments occurs on Windows and Linux endpoints. Most organizations cannot see any of it.

Galvanick Endpoint captures process, file system, and network telemetry from every monitored workstation and server through a fully passive sensor.

passive endpoint telemetry.

The Galvanick endpoint sensor is lightweight software installed on monitored Windows and Linux endpoints at Purdue Model Levels 2 through 3.5: engineering workstations, operator workstations, HMIs, process historians, jump hosts, DCS control servers, and SCADA servers.

  • User-mode only. Runs entirely above the kernel. Configures built-in OS APIs to produce EDR-style telemetry, then collects and forwards that data.

  • Telemetry-only by design. Once installed, the sensor does one thing: forward data. No control channel, no inbound command or attack path, no remote modification.

  • Minimal footprint. All analysis and detection happen off-endpoint. Telemetry terminates at a collector in your environment. Monitored endpoints do not need cloud connectivity.

L4/5L3.5L2–3ANALYTICS ENGINECLOUDON-PREMCOLLECTORENDPOINTHMIENDPOINT SENSORENDPOINTENG. WORKSTATIONENDPOINT SENSOR
SENSOR INSTALLED12 MO AGO6 MO AGO3 MO AGOTODAYFINDINGHIGHPROCESS INJECTIONFINDINGHIGHC2 BEACON TRAFFICFINDINGHIGHPERSISTENCE ← RETROACTIVE COVERAGE LIVE MONITORING →
Purpose-built OT detection.

The Galvanick endpoint sensor covers techniques that target industrial environments specifically, from living-off-the-land techniques to custom malware anchoring on proven behavior-based IoCs. Detections are modeled on historic OT attack campaigns and work immediately upon deployment.

On installation, the sensors not only start detecting for new threats, they also ingest historical logs and apply the full detection catalog retroactively. Attacker activity that occurred months or years before deployment surfaces immediately.

actionable findings.

Every Galvanick finding includes the affected endpoint, the user account, the specific process, and a complete timeline of related activity.

Findings include recommended next steps based on the specific threat detected and the observed behavior. Galvanick provides findings in our easy-to-use UI. It can also forward information to your existing SIEM or directly to messaging platforms like Slack, Teams, and Outlook.

Galvanick can also query your operations team directly through your messaging platform to validate observed activity in real time.

FINDINGHIGHTRIAGE CENTERHIGHAFFECTED ASSETSDC-01Domain ControllerEWS-02Engineering StationRECOMMENDED ACTIONS01QUARANTINE EWS-02 FROM LEVEL 3 NETWORK SEGMENT02REVOKE ALL ACTIVE SESSIONS ON DC-0103AUDIT DRSUAPI CALLS WITHIN LAST 2 HOURSVALIDATION QUERY DCSync from non-DC host EWS-02 · DRSUAPI GetNCChanges called 4× · No active replication schedule Was EWS-02 authorized to request directory replication? YESNO
Traditional EDR
Galvanick Endpoint
Primary telemetry
Process, file system, network
Process, file system, network
Kernel access
Kernel-level driver
User-mode only
Cloud connectivity
Required for full capability
Not required
Updates
Self-updating and bypasses change management by default
On your schedule, through your processes
Control channel
Inbound commands from management platform
None. Telemetry only by design
Autonomous actions
Can isolate, quarantine, or kill processes
Structurally impossible
Endpoint security without the risk.

EDR tools can deliver the endpoint telemetry OT environments need. The problem is these solutions are inherently risky,

We built the Galvanick endpoint sensor to accommodate any and all OT environments and risk profiles. It provides critical visibility and security coverage without introducing new points of failure.

Make your existing tools more effective.

Galvanick can connect your endpoint telemetry to the tools you already operate. This enriches network security alerts with user and process attribution, utilizes change management records for automated validation of observed activity, and transforms messaging platforms into interactive response channels.

  • Network security monitoring: Nozomi, Dragos, Forescout, Claroty, or use Galvanick’s own sensor

  • Infrastructure: Palo Alto Networks, Fortinet, Cisco, and others

  • Applications: ServiceNow, BMC Remedy, and others

  • Messaging: Slack, Microsoft Teams, and Outlook

EXAMPLE MULTI-SOURCE THREAT DETECTION14:23:07.441Unusual outbound connection from %TEMP%\update.exeprocess spawned without user interaction · parent: svchost.exe→ 185.220.101.47:443 · encrypted · no prior DNS resolution for destinationGALVANICK14:23:07.892Destination flagged as Tor exit node via network sensor4.2 MB outbound · session still active · no return traffic observedNOZOMI14:23:08.201No maintenance window found for EWS-070 records returned · connection flagged unauthorizedSERVICENOW14:23:12.558HIGH: compiled finding dispatched to #security-alerts3 enrichment sources · on-call analyst notifiedMS TEAMS
LEVEL4–5Enterprise / IT NetworkExisting IT EDR (e.g. CrowdStrike)LEVEL3.5Industrial DMZJump Hosts · Remote Access ServersLEVEL3Site OperationsDCS Control Servers · SCADA Servers · Process HistoriansLEVEL2Supervisory ControlOperator Workstations · Engineering Workstations · HMIsLEVEL0–1Basic Control / FieldHardware endpoints with no software agent (sensors, actuators, PLCs)GALVANICK SENSOR COVERAGE
Deploy in hours. detect on day one.

Deploy the Galvanick analytics engine in the cloud or on-premises. Endpoint sensors install in seconds per host with no reboot or internet access required, and do not self-update: Galvanick adheres to your change management process.

Distribute sensor installs on Purdue 2-3.5 endpoints via GPO, SCCM, Intune, network share, or USB for air-gapped environments, and deploy the Galvanick collector as a container image, VM image, or physical appliance.

support for legacy and modern operating systems.

Galvanick's endpoint sensor supports a range of operating systems:

Windows XP and up

Windows Server 2008 and up

Windows IoT Enterprise 10/11

Linux (Kernel version 2.6.32 and up)

Running something we don't cover yet? We build and prioritize new OS support based on customer needs.


Protect your OT endpoints.