OT Network Monitoring Tools: 5 Free Options Compared

The short answer
OT network monitoring tools are passive sensors and analysers that watch industrial control traffic without sending a single packet to the process, and five free, open source tools cover most of what a plant needs: Wireshark for reading packets, Zeek with CISA's ICSNPP parsers for logging every industrial conversation, Suricata for rule-based alerts, Malcolm for putting them together behind dashboards, and Security Onion when an IT security team already runs one platform. Commercial OT visibility products add asset databases, vendor support and polished reports, but the method underneath is the same, and you can learn it on your own laptop with public capture files.
Versions, licences and hardware figures were checked on the projects' own pages on 11 October 2026 (October 2026). Tool names belong to their projects.
Why OT monitoring is passive
In an office network the first security job is often a vulnerability scan. In a plant it is not. Some PLCs, RTUs and safety controllers have stopped or rebooted when an ordinary scanner probed them, and a stopped controller is a stopped line. So industrial security programmes usually start with a sensor that receives a copy of the traffic from a switch's SPAN (mirror) port or a network TAP, and analyses it without ever transmitting on the control network.
A passive sensor answers the questions a plant manager cannot answer from drawings: which devices are really on the network, who programs the controllers, which conversations cross from the business network, and whether anything changed last night. It cannot see serial links such as Modbus RTU on RS-485, traffic that never crosses the mirrored port, or the payload of encrypted sessions, so know those blind spots before you trust a quiet sensor.
The five free tools at a glance
Tool | What it does | Best at in OT | Licence and host |
|---|---|---|---|
Wireshark | Opens and decodes packets one by one | Proving what an alert really saw | Free; any laptop |
Zeek + ICSNPP | Writes one log line per transaction, linked by a connection uid | Modbus, S7comm, EtherNet/IP, DNP3 and BACnet history you can search for months | BSD licences; Linux VM |
Suricata | Matches traffic against rules, writes alerts to EVE JSON | Known-bad commands, such as a write from the wrong host | GPL; Linux VM |
Malcolm | Packages Zeek, ICSNPP, Suricata, Arkime and OpenSearch with ICS dashboards | One browser front end for a small OT team | Apache 2.0; 8 cores and 24 GB minimum |
Security Onion | NSM, log management and case handling in one console | Sites whose IT SOC already runs it | Free; size from its own docs |
CISA's ICSNPP repository lists full Zeek parsers for BACnet, BSAP, EtherNet/IP and CIP, Omron FINS, OPC UA Binary, S7comm (with S7comm-plus and COTP), Profinet IO CM and others, plus logging extensions for Zeek's own DNP3 and Modbus analysers. Malcolm's system requirements page sets a minimum of 8 CPU cores and 24 GB of RAM on a dedicated host, with 16 or more cores and 32 GB or more recommended, so plan a lab server for it rather than a laptop.

Which tool answers which question
The tools are complementary rather than rivals, which is why Malcolm and Security Onion both run Zeek and Suricata side by side.
- "What exactly was sent?" Open the packets in Wireshark. Filter on the protocol name (modbus, s7comm, enip, dnp3, bacnet) rather than only the port, because a protocol on an unusual port is itself a finding.
- "Did any host other than the HMI write to PLC-2 last month?" Ask Zeek's logs. Zeek recorded every request with its function code, so you can ask a question nobody thought of when the traffic happened.
- "Tell me the moment a laptop writes to the recipe registers." Write a Suricata rule. One catch: in Suricata 8's default configuration the Modbus, DNP3 and EtherNet/IP parsers ship turned off, so OT rules stay silent until you enable them.
- "Show the whole plant to a small team." Malcolm's dashboards and Arkime let you click from a chart down to the sessions and the bytes.
The protocols a sensor should understand
Protocol | Usual port | Normal traffic | Messages that change something |
|---|---|---|---|
Modbus/TCP | TCP 502 | Reads on a fixed cycle | Writes (function codes 5, 6, 15, 16), diagnostics (8) |
S7comm | TCP 102 | Read var, cyclic data | Write var, block download, PLC stop |
EtherNet/IP and CIP | TCP 44818, UDP 2222 | Implicit I/O at the RPI | Set attribute, write tag, reset |
DNP3 | TCP 20000 | Class polls, unsolicited data | Select and operate, direct operate, restarts |
BACnet/IP | UDP 47808 | Who-Is, I-Am, ReadProperty | WriteProperty, reinitialise device |
Modbus has no authentication: any host that can reach port 502 can read or write. That is why the two most useful facts in any OT alert are the source address and the function code.
Worked example: sizing the SPAN port and the storage
A site wants one sensor on the cell switch and plans to mirror two 1 Gbit/s full-duplex uplinks onto a single 1 Gbit/s SPAN port. Measured averages are 180 Mbit/s in and 120 Mbit/s out on each uplink. The site also wants 30 days of full packet capture.
- Worst case on the SPAN port: 2 uplinks x 1,000 Mbit/s x 2 directions = 4,000 Mbit/s, four times the port's 1,000 Mbit/s. Bursts will be dropped.
- Average: 2 x (180 + 120) = 600 Mbit/s, which fits, but averages hide bursts. A TAP on each uplink, or two SPAN ports, avoids the loss.
- Storage at a measured 20 Mbit/s on the capture port: 20 / 8 = 2.5 MB/s; 2.5 MB/s x 86,400 s = 216 GB a day; 216 GB x 30 = 6.48 TB.
- Zeek logs at a measured 3% of capture size: 6,480 GB x 0.03 = 194.4 GB for the same 30 days.
The lesson is the one most plants reach: keep logs for months and full packets for days, and count both directions when you size a mirror port.
Point | SPAN port | Passive TAP |
|---|---|---|
Cost | Configuration only | Hardware per link |
Under load | Drops frames when sources exceed the port speed | Copies everything on that link |
Installation | A change on a live switch | A short outage to insert in the cable |
Coverage | Many ports or a VLAN at once | One link per TAP |
Configuring SPAN changes a live switch, so do it through the plant's change process with the controls engineer present, and check the switch CPU afterwards.
A safe 30-day rollout

Start in the lab, not on the plant. Run Zeek and Suricata on a Linux VM against public ICS captures, then place one sensor where the most critical conversations meet, usually the level 2 or level 3 switch. Prove it sees both directions of a known HMI poll. Build the asset inventory from traffic, baseline the conversations that should exist, and only then write alerts. Map each detection to MITRE ATT&CK for ICS, which had 12 tactics when we checked; for example an unplanned S7 block download is T0843 Program Download.
When an alert fires, triage it in a fixed order: what fired, where it is, who did it, and what it could do to the process. If the process could be affected, call the control room first and let operations choose the containment step. Never send commands to a controller as part of a security response.
Is this a good skill for engineers in India?
Indian refineries, power utilities, water boards, pharma and data-centre operators increasingly ask integrators and in-house teams to show OT visibility, and the people who can read a Modbus write in a capture and talk to the control room are scarce. For a controls, instrumentation or network engineer, passive monitoring is a natural step into OT security because it builds on what you already know about the plant. Our posts on IEC 62443 zones and conduits and on factory cyberattacks in 2026 give the wider picture.
Learn the tools free
The free OT Network Monitoring: Zeek, Suricata and Malcolm course teaches all of the above in fifteen modules: sensor placement, Wireshark on five industrial protocols, Zeek with ICSNPP, Suricata rules for OT, Malcolm and Arkime, baselines, ATT&CK for ICS and alert triage with operations. Every lab runs in your own virtual machines with public captures; nothing touches a live plant.
It is a free course with a verifiable certificate of completion, and anyone can check a certificate on our verification page. It is not a certification from CISA, MITRE or the open source projects. For the programme side, pair it with OT and ICS Cybersecurity with ISA/IEC 62443. Start with the OT network monitoring course.
If you would rather practise this on PLC training panels with an instructor, see our PLC course in Bangalore for the syllabus and duration.
Frequently asked questions
Q: What are the best free OT network monitoring tools?
A: Wireshark for packet analysis, Zeek with CISA's ICSNPP parsers for protocol logs, Suricata for rule-based alerts, Malcolm to combine them with ICS dashboards, and Security Onion where an IT SOC already runs it. All five are free and open source.
Q: Is passive OT monitoring safe on a running plant?
A: Yes, when it is done right. The sensor receives a copy of traffic from a SPAN port or TAP and never transmits on the control network. Configuring the SPAN port is still a change to a live switch, so it goes through the plant's change process.
Q: Can Zeek read industrial protocols?
A: Zeek understands Modbus and DNP3 out of the box. CISA's ICSNPP packages add full parsers for S7comm, EtherNet/IP and CIP, BACnet, OPC UA Binary, Profinet IO CM and others, and extend the Modbus and DNP3 logs.
Q: What hardware does Malcolm need?
A: Malcolm's documentation sets a minimum of 8 CPU cores and 24 GB of RAM on a dedicated host, and recommends 16 or more cores and 32 GB or more. Wireshark, Zeek and Suricata run on an 8 GB laptop for lab work.
Q: Why do my Suricata Modbus rules never fire?
A: Check that the Modbus app-layer parser is enabled in suricata.yaml. In Suricata 8 the Modbus, DNP3 and EtherNet/IP parsers ship disabled, so rules using those keywords cannot match until you turn them on.
Q: Is there a free OT network monitoring course with a certificate?
A: Yes. EDWartens' OT Network Monitoring: Zeek, Suricata and Malcolm is a free course with a verifiable certificate of completion, issued after the modules and a 15-question final passed at 60 percent.
Learn this, free
The courses that teach this
Every lesson, the written notes and the practice are free with an account. Only the certificate is optional and paid.





