OT + IT PCAP analysis

Surface threats in packet captures. No setup.

Drop a capture file. Get assets, conversations, MITRE ATT&CK findings, and Purdue topology in seconds — without standing up Wireshark, Zeek, or a SIEM.

No account needed for a 50 MB test scan. Results expire after 24 hours.

42
Detection rules
15+
OT protocols
ICS + Enterprise
ATT&CK matrices
L0–L4
Purdue levels inferred
Capabilities

Not just another PCAP viewer

MarlinSpike was built for the OT/ICS environment — where Wireshark is necessary but insufficient, and every unrecognized protocol could be a threat.

OT & IT protocol stack

Speaks the full stack, no config. OT protocols decoded alongside TCP/IP.

Modbus EtherNet/IP S7comm DNP3 OPC-UA BACnet IEC 60870

MITRE ATT&CK mapped

42 detection rules across Enterprise and ICS ATT&CK matrices. Every finding links to its technique — no interpretation layer required.

Purdue topology inference

Assets classified automatically to Purdue levels L0–L4. Network graph rendered per scan — no manual tagging, no CMDB import.

No data leaves your tenant

Uploads and reports are isolated per tenant. Retention schedules enforced automatically. Your captures are not pooled or analyzed cross-account.

Workflow

Three steps. No infrastructure.

01 — UPLOAD

Drop a PCAP

Drag in a .pcap, .pcapng, or .cap file. Anonymous scans need no account. Registered users get persistent history and larger caps.

02 — ANALYSE

Engine runs

MarlinSpike decodes every packet, identifies assets, classifies protocols, and evaluates 42 detection rules against your capture.

03 — REVIEW

Navigate the report

Interactive topology map, findings by severity, protocol distribution, ATT&CK technique index. Export as JSON for your SIEM or ticketing system.

Plans

Start free, scale when you need to

Free
Free
1.0 GB per upload

Full plan comparison →

Built on MarlinSpike — open source The analysis engine is open source and auditable. Cloudmarlin adds cloud hosting, multi-tenant isolation, and a managed workflow on top.
View on GitHub