Platform · How it Works

We've got you covered.
Here's how.

Every endpoint found. Every threat surfaced. Every issue is explained with a direct fix provided. Here's exactly what happens.

Step 01
Endpoint Detection

Every device.
Known and unknown.

Spotlight begins with a comprehensive sweep of your entire infrastructure — cataloging every endpoint across IT and OT environments, including devices that were never formally inventoried. Rogue hardware, forgotten assets, and shadow devices all surface here. You can't defend what you don't know exists.

With an agent: laptops, desktops, servers, workstations, and any device with a shell — Linux-based PLCs and edge controllers, Windows or Linux HMIs, IP cameras and IoT devices on ARM. Discovered and assessed from the network: firewalls, switches, RTUs and controllers with no host OS, building systems.
Agent coverage on Windows, macOS, Linux (x86_64 and ARM), FreeBSD and QNX · everything else discovered and identified from the network

🖥️
Server
🔥
Firewall
❓
Unknown
⚙️
PLC
📡
Sensor
🔌
Switch
❓
Unknown
🖥️
HMI
📦
RTU
❓
Unknown
◻️
Scanning
☁️
Cloud
🔐
Controller
◻️
Scanning
📟
Router
Known Endpoint Newly Discovered Scanning
Agent deployment
🖥️ PROD-SERVER-01 · Linux• Agent Live
🖥️ ENG-WKS-07 · Windows• Agent Live
💻 OPS-MBP-03 · macOS• Agent Live
🖥️ WORKSTATION-14 · WindowsDeploying...
⚙️ SCADA-NODE-04 · Linux ARM• Agent Live
📦 RTU-PUMP-STN-7Discovered · no agent
🔥 FW-PERIMETER-01Discovered · no agent
Agents Deployed412 of 847 devices
Agent BinarySingle static binary · no runtime dependencies
Step 02
Deploy Agents

Lightweight agents.
Right on the attack surface.

Spotlight deploys ultra-lightweight agents directly onto each device. They sit at the source, rather than monitoring traffic from a distance. Our agents not only visualize the attack surface, they also inhabit it. A single static binary with no runtime dependencies. All AI analysis runs upstream, never on the device; nothing heavy touches your controllers, and no model sits inside your control network. No new hardware required. The same binary runs on a Linux-based controller or an ARM camera as on a server. Devices with no host OS to install on — bare PLCs, RTUs, switches, building systems — are discovered and assessed from the network instead: passively by default, and excluded from active scanning when they look industrial.

Windows · macOS (Intel and Apple Silicon) · Linux (x86_64 and ARM, .deb or raw binary) · FreeBSD · QNX
Cloud SaaS · multi-tenant · dedicated per-customer gateway

Step 03
Issue Detection

Scheduled. Thorough. Unblinking.

Agents check in on a schedule you control, so drift surfaces without anyone going to look. New listening ports, new privileged accounts, missing security patches, weak password policy, logging switched off — and firewall rules that no longer match the traffic actually hitting them.

Misconfigurations · exposed services · privilege drift · missing patches · logging gaps
Firewall config vs. live traffic · policy drift · MITRE ATT&CK tactic mapping

Scheduled check-in
✓ WORKSTATION-03 ............ cleanClear
✓ PROD-SERVER-01 ............ cleanClear
✓ FW-PERIMETER-01 .......... cleanClear
⚠ RTU-PUMP-STN-7 ....... policy driftWarn
✓ SWITCH-FLOOR-2 ........... cleanClear
🚨 SCADA-NODE-04 ..... unauthorized IPCritical
✓ HMI-CONTROL-01 .......... cleanClear
✓ SENSOR-ARRAY-12 ......... cleanClear
Raw Log Output
Jun 1 05:37:49 SCADA-NODE-04 kernel: [UFW BLOCK] IN=eth0 OUT= MAC=00:18:ae:c7:dd:48 SRC=10.0.20.11 DST=10.0.30.52 LEN=1552 TOS=0x00 PREC=0x00 TTL=64 ID=54321 DF PROTO=TCP SPT=45231 DPT=502 WINDOW=65535 RES=0x00 SYN URGP=0 · Source IP/VLAN mismatch detected · DHCP lease conflict · CHILD_SA net-2-0[4190] established SPIs c9eb0d9d (inbound) c2f19100 TS=172.30.1.242/32
Spotlight Explains it in Plain English

An unknown device at IP 10.0.20.11 is attempting to connect to your SCADA control system on port 502 — the Modbus control protocol. This traffic should not be happening. The device is not recognized on your network and appears to be probing your industrial control systems. Risk: unauthorized access to operational technology.

Step 04
Plain English Communication

No PhD required to understand the threat.

Spotlight's LLM reads every alert and translates it into plain language — what happened, why it matters, and how serious it is. Context, severity, and impact. In sentences, not syntax.

Every alert includes: plain-English explanation · severity · affected systems · recommended next steps

Step 05
Recommended Solutions

Here's the problem.
Here's how to fix it.

Spotlight generates precise, ranked remediation options — from the fastest one-command fix to more thorough hardening approaches. Each recommendation explains what it does and why. You decide. Spotlight executes.

Validated against containerised attack scenarios with scored checkpoints — a reproducible benchmark, not a claim

Recommended Actions — SCADA-NODE-04
Recommended

Block all inbound traffic from IP 10.0.20.11 at the firewall level, immediately isolating the unauthorized device from your OT network segment.

sudo iptables -A INPUT -s 10.0.20.11 -j DROP

Also consider

Segment the SCADA network to prevent any IT-side device from reaching Modbus port 502 without explicit allowlist approval.

Long-term

Review and tighten DHCP lease policies to prevent unauthorized IP assignments in the OT VLAN. Implement network access control (NAC).

CriticalActive Threat — SCADA-NODE-04

Unauthorized device 10.0.20.11 is actively probing Modbus port 502. Blocking is recommended immediately. Spotlight will push the remediation command directly to the affected node.

⚡ Take Action with Spotlight AI
Remediation pushed · Resolved43 seconds

What Spotlight executed

sudo iptables -A INPUT -s 10.0.20.11 -j DROP

All inbound traffic from 10.0.20.11 is now blocked. The unauthorized connection has been severed. Event logged for audit trail.

Step 06
One-Click Implementation

From identified to resolved. In under a minute.

A single click pushes the remediation command directly to the affected agent, which executes it on the device. No remote desktop. No vendor call. No driving to site. Other tools alert. Spotlight acts.

On-device execution · full audit log · no mandatory deployment engagement

Step 07
Generate Reports

Prove your value.
Every single month.

Every threat detected, every issue resolved — logged automatically and compiled into clear reports. Send them to leadership, attach them to audits, share them with clients. Everything Spotlight does becomes documented evidence of the work being done.

Executive summary · audit-ready findings export · board report · MSP client report · custom date ranges
These reports double as the documented evidence cyber-insurance carriers now demand.

Monthly Security Report

January 2026 · Sample Utility Customer

0Threats blocked
0Issues resolved
0%Uptime

Security posture score · 94/100

Executive SummaryFindings ExportBoard ReportMSP Client Report
Ready to see it live?

One demo.
See it live.

Book a live demo and watch our agents find and fix a real exposure on your network — in under a day.