One Pass. Every Industrial Protocol. Wire-Speed Enforcement.
TXODI: TXOne One-pass Deep Packet Inspection, purpose-built for OT traffic
TXODI (TXOne One-pass Deep Packet Inspection) is the single-pass packet inspection engine inside TXOne Edge and SenninRecon. It parses 180+ industrial protocols at the command level in one pipeline pass, delivering sub-500 microsecond latency, signature plus behavioral evaluation, and inline enforcement without multi-engine chaining that IT NGFWs rely on.
IT Firewalls See Ports. TXODI Sees Intent.
A Modbus write-coil command, an S7 stop-CPU request, or a DNP3 unsolicited response each carries meaning IT firewalls cannot parse. TXODI parses them.
Inspection for industrial protocols has to happen inline, at wire speed, without drop or reorder. Chained IT engines add latency and miss command context. TXODI runs one pass over the packet and executes signature matching, protocol validation, behavioral baseline evaluation, and policy enforcement in a single pipeline so inspection keeps up with the control loop and operations keep running.
WHAT IT IS

Capability
What is TXODI?
TXODI is the deep packet inspection engine that powers command-level enforcement on TXOne Edge appliances (EdgeIPS, EdgeFire) and informs asset discovery, protocol mapping, and baseline establishment on SenninRecon. It is purpose-built for industrial environments: deterministic performance, fail-safe behavior, protocol awareness across 180+ industrial protocols, and integration with CPSDR behavioral detection and 1,500+ OT-native signatures. TXODI is why a TXOne Edge device can distinguish a legitimate engineer reprogramming a PLC from an attacker issuing the same function codes, and why SenninRecon can map what an asset actually does on the network instead of guessing from ports.
KEY COMPONENTS
TXODI Challenges
Key challenges that TXODI addresses.
01 / 04
IT Firewalls Cannot Parse Industrial Protocols
Your IT next-gen firewall filters by port, IP, and application signature. It cannot parse a Modbus function code, validate an S7 block transfer, or detect an unauthorized DNP3 operation. Port 502 is either allowed or blocked; the commands inside are invisible.
IT Firewalls Cannot Parse Industrial Protocols
Your IT next-gen firewall filters by port, IP, and application signature. It cannot parse a Modbus function code, validate an S7 block transfer, or detect an unauthorized DNP3 operation. Port 502 is either allowed or blocked; the commands inside are invisible.
Key Components
Core components of the TXODI capability.
01 / 05
One-Pass Inspection Pipeline
TXODI processes each packet through signature matching, protocol validation, CPSDR behavioral evaluation, and policy enforcement in a single pipeline pass. No serialized multi-engine chains. Sub-500 microsecond latency across every EdgeIPS model.
Key Capabilities
One-Pass Inspection Pipeline
TXODI processes each packet through signature matching, protocol validation, CPSDR behavioral evaluation, and policy enforcement in a single pipeline pass. No serialized multi-engine chains. Sub-500 microsecond latency across every EdgeIPS model.
Key Capabilities
Outcomes
01 / 04
Inspection latency at wire speed
Inspection latency at wire speed
PROVEN RESULTS
WHY TXONE
Why TXODI for Industrial Packet Inspection
Built for OT traffic, OT latency budgets, and OT failure modes from the ground up.
IT NGFWs chain firewall, IPS, and DPI engines in sequence. TXODI runs signature, behavioral, and policy evaluation in one pass, holding latency under 500 microseconds so control loops keep running.
Legacy approach creates operational risk
180+ industrial protocols are inspected at the command level. IT firewalls see port 502; TXODI sees the Modbus function code, the coil address, and the value being written.
Legacy approach creates operational risk
Hardware bypass ensures traffic continues through the appliance even on power loss or device failure. Security must not become the cause of a line stoppage.
Legacy approach creates operational risk
1,500+ OT-native signatures, CPSDR behavioral baselines, and virtual patches run in the same pass. Known threats, unknown deviations, and exposed CVEs are prevented simultaneously.
Legacy approach creates operational risk
The same engine that enforces on Edge passively identifies assets on SenninRecon. One deep-inspection capability delivers both enforcement on the wire and operational asset intelligence.
Legacy approach creates operational risk
NEXT STEP
Prove TXODI on Your Own Traffic
Start with a 60-Minute Proof of Value. Deploy an Edge appliance on a mirror or inline segment and see command-level visibility, behavioral detection, and inline enforcement on your own OT protocols.