Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Asset Inventory

Passive device discovery from observed network traffic.

Overview

Rockfish builds an asset inventory by analyzing network flow patterns, extracting DHCP metadata, and inferring device roles — all without agents or active scanning.

Capabilities

FeatureDescription
IP TrackingAll observed IPs with communication patterns and protocol usage
DHCP MetadataMAC address, hostname, vendor class ID extraction
Device Role InferenceAutomatic classification based on traffic patterns
New Device DetectionFlags IPs not present in baseline
OT Protocol AwarenessIdentifies industrial protocol usage
Inventory SnapshotsPeriodic snapshots written to Parquet

Inferred Device Roles

RoleDetection Criteria
PLCModbus, DNP3, EtherNet/IP, or S7comm traffic
HMIMixed OT and standard protocols
SensorRead-only OT protocol patterns
Engineering WorkstationOT + administrative protocols
ServerListening on well-known ports
ClientOutbound-initiated connections

OT Protocol Support

ProtocolDescription
ModbusIndustrial serial communication
DNP3Distributed Network Protocol
MQTTIoT message queuing
BACnetBuilding automation
EtherNet/IPIndustrial Ethernet
S7commSiemens S7 communication
OPC UAOpen Platform Communications
IEC 104Telecontrol protocols

Report Integration

The Inventory report page displays:

  • Device list with inferred roles and protocol usage
  • New/unknown device alerts
  • OT protocol traffic summary
  • First-seen and last-seen timestamps
  • Communication pattern metrics (connection count, bytes)