Photo Gallery
|
Group-IB Threat Hunting Framework
Additional Info
| Company | Group-IB |
| Company size | 500 - 999 employees |
| Website | https://www.group-ib.com/ |
NOMINATION HIGHLIGHTS
Group-IB Threat Hunting Framework (THF) is a single solution for complex protection of IT and OT segments in any organization. It is based on adversary-centric approach to detection and mitigation of targeted attacks and our patented technologies.
To detect attacks in the technology segment of an enterprise, Group-IB recently developed Group-IB THF Sensor Industrial module. Analyzing data packets of technological protocols with its own behavioral rules, Group-IB THF Sensor Industrial allows to detect the transfer of illegitimate control commands between the levels of the APCS, to detect the use of service commands of the APCS for the purpose of flashing the PLC, replacing the control program, stopping technological processes, and other violations.
The module supports both open protocols – CIP, DNP3, IEC 60870-5-104, IEC 61850-MMS, Modbus TCP, OPC-DA, OPC-UA, MQT, and some proprietary – Siemens, Schneider Electric, Rockwell Automation, Emerson. If the required protocol is not on the compatibility list, Group-IB experts are ready to add it within a few weeks.
THF Sensor Industrial does not affect technological processes, it works in a mirror mode. A good addition to the system is the use of Group-IB THF Huntpoint module on the workstation f operators and engineers, which will record actions on critical machines inside.
How we are different
• Control over the environment
Detects topology changes on the OT network and abnormal interaction that doesn’t comply with AI-built communication map. On top of protocol support, Industrial Sensor provides a configurable detection policy configuration tool to set up detection rules that fit specific client needs.
• Automated software integrity control
Controls the integrity of either firmware or software used in PLCs
• Broad protocol support
Modbus, S7comm, S7comm+, UMAS, OPCUA, OPCDA, IEC104, DNP3, DeltaAV, CIP, and others
Community Choice Award
Vote for This Nominee
Share this page on any platform above to cast your vote. Each completed social post counts as one vote for this nomination.
Voting closes July 18, 2026 — winners announced ahead of Black Hat USA
What is the Community Choice Award? →
The Community Choice Award is a separate recognition decided entirely by public votes — not by the judging panel. Every nominee is eligible for both.
