AXIOM BORDER
Local cybersecurity monitoring probe for the OT/IoT edge
The cybersecurity probe for the OT/IoT edge
Axiom Border is a non-intrusive, cost-efficient local monitoring probe focused on the cybersecurity of OT/IoT environments. It is deployed on the local infrastructure — plants, substations, stations — on industrial-grade hardware with built-in communications, ready to operate in demanding environments.
It works stand-alone, disconnected from the cloud, with an integrated GUI for local management; and connected to OpenGate it centralizes inventory, alarms and remote operations. It discovers and notifies new equipment appearing on the network, identifies ports and protocols, and runs automatic or on-demand vulnerability diagnostics.
The local probe, tool by tool
It can run stand-alone, disconnected from the cloud. Once connected to a local network it provides the following tools:
Integrated GUI for local management
Allows local control of the probe without depending on the cloud, from an integrated web interface.
Passive detection
Monitors network traffic in a non-intrusive way to identify devices and services in real time, providing full visibility without generating additional traffic or alerting perimeter security systems.
Active detection
Periodic or on-demand scans, configured from OpenGate or locally: custom TCP/UDP scanner over ports and protocols, vulnerability scanner, and SNMP OID discovery and querying.
Local rules engine and AI
Low-code JavaScript rules engine plus local execution of AI agents with MicroAI-Model Factory (trainferencers): threat patterns and anomalous behaviors detected with models trained on the probe's local data.
Ports and access supervision
Monitoring of USB ports, SSH traffic and network interfaces — its own and those of other equipment — through a local monitoring agent optionally installable on the supervised hosts.
Centralization and operation from OpenGate
Connected to the platform, the probe's data is centralized for querying — at a global level or per host — and operations are launched against the hosts through the connection with the local probe.
~6,050 templates · 7 scan vectors · extensible and customizable
Vulnerability catalog
Covered cycle: identify → enumerate → validate known flaws → detect active compromise, based on the data collected by the probe.
| Vector | Templates | What it looks for |
|---|---|---|
| Known CVEs | 3,422 | RCE, SQLi, auth bypass, SSRF, XXE, path traversal, deserialization (2000–2025; 679 from the last 2 years) |
| Misconfigurations | 702 | Exposed admin panels, debug endpoints, missing headers, cloud metadata, lax proxies |
| Technology detection | 777 | Fingerprinting of CMS, frameworks, servers and cloud stacks — the basis to correlate exploits |
| Data exposure | 593 | APIs, backups, .env, .git, logs, tokens (118 providers: AWS, GitHub, Stripe…) |
| Network services | 259 | Network CVEs, unauthenticated Mongo/Redis/PSQL, backdoors, RATs and C2 |
| Default credentials | 257 | 186 technologies: routers, IoT, enterprise panels, databases |
| SSL/TLS | 38 | Expired/weak certificates, obsolete TLS, insecure ciphers |
Templates are kept up to date with feeds from bodies such as MITRE, NIST and INCIBE (known CVEs per device and version under the SCAP specification), and can be extended and customized per deployment.
OT/ICS-specific templates
Generic vulnerability scanners are built for IT and go blind on industrial segments. Axiom Border ships its own suite of 43 checks for five industrial protocols, installed with the product and available to every scan — with no internet access and no upstream template feed. The suite is organised in layers of increasing invasiveness (detection, exposure, recon, intrusive) and is read-only by default: write checks are gated behind a two-lock safety model and every intrusive execution is audited.
| Protocol | Port | Checks | Of which intrusive |
|---|---|---|---|
| Modbus/TCP | 502/TCP | 13 | 6 |
| IEC 60870-5-104 | 2404/TCP | 9 | 4 |
| DNP3 | 20000/TCP | 8 | 3 |
| BACnet/IP | 47808/UDP | 8 | 1 |
| OPC UA | 4840/TCP | 5 | 2 |
| Total | — | 43 | 16 |
Detection confirms the protocol and extracts device identity; exposure reports weaknesses reachable without credentials; recon reads process data without ever writing; and intrusive checks confirm writes with a read-then-write-back approach, always excluded from scheduled scans. Vendor CVE checks (Schneider Modicon, Delta enteliBUS, Contemporary Controls) run only where fingerprinting is reliable.
Hybrid architecture
with OpenGate
Axiom Border probes are deployed on each plant or local infrastructure and connect to the OpenGate IoT Platform, which centralizes assets inventory, monitoring, alarms management, data processing and analytics.
From OpenGate you can launch operations against the hosts through the local probe and automate security responses and policies: isolating compromised devices, secure remote firmware updates or blocking anomalous traffic. API-based integration with SIEM and corporate tools correlates the OT, IoT and IT worlds to reach root causes.
Have a question?
Frequently asked questions about Axiom Border
Product
Axiom Border is a local cybersecurity monitoring probe for OT/IoT environments. Deployed at the edge on industrial hardware, it discovers and inventories the devices on the network, identifies vulnerabilities, detects threats and anomalous behaviors, and centralizes the information in the OpenGate IoT Platform.
No. In passive mode it monitors traffic without generating additional load or alerting perimeter security systems. Active scans are configurable — periodic or on demand — and run in a controlled way over the ports and protocols you define.
Yes. It operates stand-alone with an integrated GUI for local management: discovery, scanning, rules and local AI do not depend on the cloud. When connected to OpenGate, it adds centralized data, alarms and remote operations.
On industrial-grade embedded hardware, with built-in communications and suitable for installation in plants, substations and field cabinets. The probe is not tied to a specific manufacturer: ask us for the catalog of supported devices to choose the equipment that best fits your deployment.
Detection and compliance
Its catalog exceeds 6,000 templates across 7 vectors: known CVEs (RCE, SQLi, auth bypass…), misconfigurations, technology fingerprinting, data exposure, insecure network services, default credentials and SSL/TLS weaknesses. It also includes an OT/ICS-specific suite with checks for industrial protocols such as Modbus/TCP, IEC 60870-5-104, DNP3, BACnet/IP and OPC UA. It is extensible and customizable.
It runs AI/ML models locally through MicroAI-Model Factory, trained on the probe's own data, to detect threat patterns and unusual behaviors and to automate responses such as isolating compromised devices.
It supports continuous compliance with NIS2, CRA, ENS, IEC 62443 and ISO 27019, with up-to-date vulnerability information (CVEs) from MITRE, NIST and INCIBE under the SCAP specification.
Through the OpenGate APIs: events and inventory from the probes are correlated with corporate IT tools to reach root causes by crossing information from the OT, IoT and IT worlds.
How our customers use OpenGate
Remote configuration and upgrade, status alarms, operations and diagnostics from any element in the solution and much more. OpenGate IoT Platform keeps a secure bidirectional communication with all your devices and assets to work with your business information.
View all use cases





