AXIOM BORDER

Local cybersecurity monitoring probe for the OT/IoT edge
Industrial OT/IoT devices monitored by the Axiom Border probe

The cybersecurity probe for the OT/IoT edge

Axiom Border is a non-intrusive, cost-efficient local monitoring probe focused on the cybersecurity of OT/IoT environments. It is deployed on the local infrastructure — plants, substations, stations — on industrial-grade hardware with built-in communications, ready to operate in demanding environments.

It works stand-alone, disconnected from the cloud, with an integrated GUI for local management; and connected to OpenGate it centralizes inventory, alarms and remote operations. It discovers and notifies new equipment appearing on the network, identifies ports and protocols, and runs automatic or on-demand vulnerability diagnostics.

The local probe, tool by tool

It can run stand-alone, disconnected from the cloud. Once connected to a local network it provides the following tools:

icon

Integrated GUI for local management

Allows local control of the probe without depending on the cloud, from an integrated web interface.

icon

Passive detection

Monitors network traffic in a non-intrusive way to identify devices and services in real time, providing full visibility without generating additional traffic or alerting perimeter security systems.

icon

Active detection

Periodic or on-demand scans, configured from OpenGate or locally: custom TCP/UDP scanner over ports and protocols, vulnerability scanner, and SNMP OID discovery and querying.

icon

Local rules engine and AI

Low-code JavaScript rules engine plus local execution of AI agents with MicroAI-Model Factory (trainferencers): threat patterns and anomalous behaviors detected with models trained on the probe's local data.

icon

Ports and access supervision

Monitoring of USB ports, SSH traffic and network interfaces — its own and those of other equipment — through a local monitoring agent optionally installable on the supervised hosts.

icon

Centralization and operation from OpenGate

Connected to the platform, the probe's data is centralized for querying — at a global level or per host — and operations are launched against the hosts through the connection with the local probe.

~6,050 templates · 7 scan vectors · extensible and customizable

Vulnerability catalog

Covered cycle: identify → enumerate → validate known flaws → detect active compromise, based on the data collected by the probe.

Vector Templates What it looks for
Known CVEs 3,422 RCE, SQLi, auth bypass, SSRF, XXE, path traversal, deserialization (2000–2025; 679 from the last 2 years)
Misconfigurations 702 Exposed admin panels, debug endpoints, missing headers, cloud metadata, lax proxies
Technology detection 777 Fingerprinting of CMS, frameworks, servers and cloud stacks — the basis to correlate exploits
Data exposure 593 APIs, backups, .env, .git, logs, tokens (118 providers: AWS, GitHub, Stripe…)
Network services 259 Network CVEs, unauthenticated Mongo/Redis/PSQL, backdoors, RATs and C2
Default credentials 257 186 technologies: routers, IoT, enterprise panels, databases
SSL/TLS 38 Expired/weak certificates, obsolete TLS, insecure ciphers

Templates are kept up to date with feeds from bodies such as MITRE, NIST and INCIBE (known CVEs per device and version under the SCAP specification), and can be extended and customized per deployment.

OT/ICS-specific templates

Generic vulnerability scanners are built for IT and go blind on industrial segments. Axiom Border ships its own suite of 43 checks for five industrial protocols, installed with the product and available to every scan — with no internet access and no upstream template feed. The suite is organised in layers of increasing invasiveness (detection, exposure, recon, intrusive) and is read-only by default: write checks are gated behind a two-lock safety model and every intrusive execution is audited.

Protocol Port Checks Of which intrusive
Modbus/TCP 502/TCP 13 6
IEC 60870-5-104 2404/TCP 9 4
DNP3 20000/TCP 8 3
BACnet/IP 47808/UDP 8 1
OPC UA 4840/TCP 5 2
Total 43 16

Detection confirms the protocol and extracts device identity; exposure reports weaknesses reachable without credentials; recon reads process data without ever writing; and intrusive checks confirm writes with a read-then-write-back approach, always excluded from scheduled scans. Vendor CVE checks (Schneider Modicon, Delta enteliBUS, Contemporary Controls) run only where fingerprinting is reliable.

Hybrid architecture
with OpenGate

line dots

Axiom Border probes are deployed on each plant or local infrastructure and connect to the OpenGate IoT Platform, which centralizes assets inventory, monitoring, alarms management, data processing and analytics.

From OpenGate you can launch operations against the hosts through the local probe and automate security responses and policies: isolating compromised devices, secure remote firmware updates or blocking anomalous traffic. API-based integration with SIEM and corporate tools correlates the OT, IoT and IT worlds to reach root causes.

Hybrid deployment architecture diagram: Axiom Border probes on local plants connected to the OpenGate IoT Platform cloud services, with SIEM integration via APIs
Have a question?

Frequently asked questions about Axiom Border

line

Product

What is Axiom Border?

Axiom Border is a local cybersecurity monitoring probe for OT/IoT environments. Deployed at the edge on industrial hardware, it discovers and inventories the devices on the network, identifies vulnerabilities, detects threats and anomalous behaviors, and centralizes the information in the OpenGate IoT Platform.

Is it intrusive for the OT network?

No. In passive mode it monitors traffic without generating additional load or alerting perimeter security systems. Active scans are configurable — periodic or on demand — and run in a controlled way over the ports and protocols you define.

Does it work without cloud connectivity?

Yes. It operates stand-alone with an integrated GUI for local management: discovery, scanning, rules and local AI do not depend on the cloud. When connected to OpenGate, it adds centralized data, alarms and remote operations.

What hardware does it run on?

On industrial-grade embedded hardware, with built-in communications and suitable for installation in plants, substations and field cabinets. The probe is not tied to a specific manufacturer: ask us for the catalog of supported devices to choose the equipment that best fits your deployment.

Detection and compliance

What kinds of vulnerabilities does it detect?

Its catalog exceeds 6,000 templates across 7 vectors: known CVEs (RCE, SQLi, auth bypass…), misconfigurations, technology fingerprinting, data exposure, insecure network services, default credentials and SSL/TLS weaknesses. It also includes an OT/ICS-specific suite with checks for industrial protocols such as Modbus/TCP, IEC 60870-5-104, DNP3, BACnet/IP and OPC UA. It is extensible and customizable.

How does it use artificial intelligence?

It runs AI/ML models locally through MicroAI-Model Factory, trained on the probe's own data, to detect threat patterns and unusual behaviors and to automate responses such as isolating compromised devices.

Which regulations does it help comply with?

It supports continuous compliance with NIS2, CRA, ENS, IEC 62443 and ISO 27019, with up-to-date vulnerability information (CVEs) from MITRE, NIST and INCIBE under the SCAP specification.

How does it integrate with a SIEM?

Through the OpenGate APIs: events and inventory from the probes are correlated with corporate IT tools to reach root causes by crossing information from the OT, IoT and IT worlds.

How our customers use OpenGate

Remote configuration and upgrade, status alarms, operations and diagnostics from any element in the solution and much more. OpenGate IoT Platform keeps a secure bidirectional communication with all your devices and assets to work with your business information.
View all use cases
ADIF Railway Smart Grid

ADIF Railway Smart Grid

Digitalization and intelligent management of railway energy infrastructure.

View Project
Connected building site

Connected building site

Remote management and monitoring to reduce work accidents.

View Project
Electric power transmission network monitoring

Electric power transmission network monitoring

OpenGate IoT Platform integrates with our client’s systems to offer an “intelligent power transmision network”.

View Project
OpenGate IoT Platform for solar farm management

OpenGate IoT Platform for solar farm management

Monitoring and data analysis for all elements of a solar farm in Colombia.

View Project
OpenGate Smart Metering for Madrileña Red de Gas

OpenGate Smart Metering for Madrileña Red de Gas

Applying digital transformation with OpenGate to one of the most important gas distributors in Spain.

View Project
Teleservices supervision system for Endesa's electricity network

Teleservices supervision system for Endesa's electricity network

Centralized IoT, communications and process management automation for Endesa.

View Project
shap-4