TXOne Networks
Hero background

Deep OT Expertise Protecting the World's Critical Operations

A global threat research team focused exclusively on cyber-physical systems, industrial protocols, and OT-native threats

The TXOne Threat Research Team investigates the adversaries, vulnerabilities, and malware families that target industrial control systems and operational technology. Our researchers discover zero-day flaws in ICS and SCADA products, reverse-engineer OT-targeting malware, contribute to coordinated disclosure programs including the Zero Day Initiative, and publish the intelligence that shapes our 1,500+ OT-native signatures and CPSDR behavioral models.

Research Focus Areas

OT Malware Analysis and Threat Intelligence

Reverse engineering of ransomware families targeting ICS and SCADA, living-off-the-land techniques observed in campaigns such as Volt Typhoon, and industrial-specific malware tracked across manufacturing, energy, and critical infrastructure sectors. Our analysts decode sample behavior, map it to MITRE ATT&CK for ICS, and translate findings into detection and prevention content shipped to customers.

Industrial Protocol Vulnerability Research

Dedicated research across the 180+ industrial protocols that run the world's operations, including Modbus, DNP3, OPC UA, PROFINET, EtherNet/IP, S7, Fieldbus, and IEC 61850. We analyze protocol implementations, document deviations from specification, and identify abuse patterns that allow attackers to issue unauthorized commands to controllers, drives, and field devices.

ICS and SCADA Zero-Day Discovery

Coordinated vulnerability disclosure with industrial vendors and CISA-aligned advisory programs. Our researchers discover zero-day flaws in OT products and participate in the Zero Day Initiative, driving CVE issuance, vendor patches, and virtual patch coverage for systems that cannot be patched in place. This work supports the 26% of 2025 CISA advisories that had no vendor patch (CISA data cited in TXOne CPS Vulnerability research, 2025).

Cyber-Physical Systems Detection Engineering

Development of the CPSDR methodology: behavioral detection grounded in the observed operational state of an industrial endpoint rather than the user context assumed by IT EDR. Our researchers study authorized machine behavior, build anomaly models for OT application execution, and write the signatures that allow Stellar to block living-off-the-land and fileless attacks before they execute.

OT-Native Signature Development

Active curation of 1,500+ OT-native threat signatures spanning industrial protocol exploits, ICS malware families, insecure protocol commands, and attack techniques documented in the wild. Unlike IT signature sets retrofitted for OT, every signature our team publishes is authored against the command-level behavior of industrial protocols and the operational reality of plant networks.

Annual OT/ICS Threat Landscape Research

Our flagship annual report combines field telemetry from global OT deployments with the iVOX industry survey to document how threats, asset postures, and defender practices are changing year over year. Findings include 100% prevalence of legacy Windows in OT environments, 43.1% of organizations reporting legacy Windows incidents in the prior year, and 83% citing replacement cost as the primary barrier to modernization (iVOX 2025, N=550).

Threat Intelligence Resources

Annual OT/ICS Cybersecurity Report

Our flagship yearly publication combining global OT field telemetry with the iVOX industry survey. Tracks the legacy OS footprint, threat actor behavior in industrial environments, defender maturity, and year-over-year shifts in incident patterns across manufacturing, energy, and critical infrastructure.

TXOne Threat Research Blog

Ongoing technical publications from the research team, including malware deep dives, protocol vulnerability write-ups, ICS incident analysis, and practitioner guidance for hardening industrial environments. Written for defenders who need depth rather than headlines.

Security Advisories and Coordinated Disclosure

Public advisories documenting vulnerabilities discovered by TXOne researchers, coordinated with affected vendors and aligned with CISA ICS-CERT disclosure practices. Includes CVE references, affected product ranges, mitigation guidance, and virtual patch availability for customers.

Zero Day Initiative Participation

TXOne researchers contribute to the Zero Day Initiative, the industry's leading bug bounty and coordinated disclosure program. Our submissions drive vendor patches for ICS and SCADA products and strengthen the CVE ecosystem that all OT defenders rely on.

Industry Conference Presentations

TXOne researchers regularly present at S4, DEF CON ICS Village, Black Hat, and regional OT security conferences. Talks span protocol exploitation, industrial malware analysis, CPSDR methodology, and lessons learned from active defense in manufacturing and critical infrastructure environments.

Joint Research with Industrial Vendors

Collaborative research with industrial control system vendors, asset owners, and ISAC communities. Joint publications document protocol hardening, secure-by-design practices, and defensive architectures informed by real-world attacker tradecraft against OT targets.

IoT/ICS Threat Atlas

Interactive map of threats targeting industrial and IoT devices with real-time intelligence updates curated by TXOne threat researchers.

Threat Encyclopedia

Comprehensive database of malware families, attack techniques, and threats targeting operational technology environments, maintained by the TXOne research team.

TXOne Research Library

Explore the full body of TXOne threat research: annual reports, technical blog entries, vulnerability advisories, protocol analyses, CPSDR methodology papers, and conference presentations. Research is written for OT defenders, IT security leaders bridging into OT, and the broader industrial cybersecurity community.