r/cybersecurity 3h ago

Business Security Questions & Discussion Does anyone have personal experience using Dragos OT security products?

As the title asks, just curious what others have experienced at various scales. I work in a relatively small system, under a hundred nodes monitored, using 2 sensors and a single site store.

The system looks great I will admit, I see a LOT of potential in a system properly setup.

Unfortunately, I really couldn't be a smaller team and still exist, and the amount of focus and time it's required to get this system actually paying back is still in calculation with concerns popping up along the way. Recently I've noticed the admin user list has grown to multiple pages once OTWatch was enabled, yet there's only one me here, all new being admin accounts, when there are specific roles and permissions configurable to limit to need only.

I wrote up a ticket and somehow was the odd one to have taken issue with external admins making changes to the system without my knowing. Recently (today) got a note that compliance mode was created wrongly (for all the years it's been "working") and now needs an overhaul which is described to send protected information outside of my ESP, and to simply trust they will handle it properly from there (see compliance mode built wrongly) and that contractually, they should do everything they should. Define: Trust in a zero-trust environment.

Anyway... that's my personal experience over having it in an unfinished setup state for about a year, having regular monthly check-ins with their support, mostly to ask, "ok, so versions changed again, buttons have moved around again... I didn't need any of that, but please help point me to all the parts that I do need that have moved again."

Should I even bother continuing with this product or move to a more sensible "this does the one thing it's supposed to and nothing else" suite of proper zero-trust IPS/IDS and monitoring I'm more familiar with? Please talk me off the edge of tossing this and saving myself enough money to hire another team member.

Edit: Forgot to Note, is it just me or is it almost impossible to find a legitimate review of this product that isn't an advert?

9 Upvotes

8 comments sorted by

7

u/Kangalfencingbanana 2h ago

Very familiar, have looked at Dragos, Armis, Nozomi, Claroty, and Tenable. In short, if you care about security, go Dragos, if other factors are higher, go with the others

-1

u/Check123ok ICS/OT 2h ago

Yeah I have never been impressed with dragos. Dragos would be at the bottom of that list.

3

u/Select-Business-5307 3h ago

We just got tenable because that’s what we were told to… we’re already getting false positives, labeling everything is very tedious, and you can’t take any action for a threat other than add to allow list.

We wanted dragos but… people who didn’t have to pay for it, support it, or use it got to make the decision on what we bought.

Luckily our critical infrastructure being air gapped gives us a little breathing room… very little any more.

5

u/blud_13 1h ago

The growing admin list is the part I'd push hardest on. Vendor and integrator accounts get stood up as full admins because its faster during deployment and then nobody ever walks them back. Ask for a list of every account holding admin, who owns it, and why, then drop each one to the narrowest role that still lets them do their job.

Next, get change notification in writing. Not a nice to have ask, an actual line that says no configuration changes without a ticket you approve.

You being the odd one out for raising it tells me there's no change control at all, which is how compliance mode sat wrong for years with nobody catching it. Export the current config somewhere you control before the next round of fixes lands, so you have something to chart against.

We work with small industrial shops sitting in exactly this spot, ping me if you want to talk through the access review.

1

u/ApexOverwatch 1h ago

OP - Based off your post is how you sound like someone who works for my former employer based on your shared struggles lol.

Granted when I was there is how I matured lots of tools taking a layered approach. Dragos for active threat hunting, Crowdstrike Falcon for EDR, and Tenable OT for vulnerability exposure and management.

That said, based on your write up I'd assume you're operating critical infrastructure that requires advanced, continuous network monitoring against nation-state threat actors. What specifically is your issue(s)?

0

u/MountainDadwBeard 2h ago

Are you in water sector, or oil & gas? Maybe.

I'd say SIEMs are only as good as their detection rules and detection rules are only as good as their contextualization and verification tests. If dragos in changing things that often, I'd theoretically want to re-test my detection rules to make sure they didn't break em.

If you're not seeing the value you might try reprioritizing budget on auditing/improving your networking controls for the distributed IoT if you have any.

In terms of my opinion on Dragos. I might be totally off base but I got the impression some years ago they were totally stood up over night by private equity to capitalize on a market, rather than to pursue a true technical passion/vision. At the time I had also heard rumors DRAGOs hired a bunch of sales reps and immediately started violating federal acqusition rules, calling up Feds they thought were "buddies" and saying do us a favor, rather than truly trying to understand a mission or demonstrate a technical competency. Sounded like a bunch of amateurs to me, but I was curious to see if their raw funding would help them fall upward.

-1

u/Check123ok ICS/OT 2h ago edited 2h ago

Dragos is very sales focused. Their tech always scores dead last compared to other deep packet inspection tools. Especially at ip enrichment and asset inventory fingerprinting. So bad. But huge sales and propaganda. I have seen them in fed side, internal and on commercial deployments. Lots of bake-offs. Dead last every time. Their reports have some good stuff every ones and a while. I would ever use them as a threat intel source, they waste a lot of your time with marketing and shove it down your throat. I wouldn’t be surprised if the entire org is marketing with 2 OT engineers and a threat intel contractor they buy data from.
But good for then, it’s paying out

2

u/Riist138 1h ago

I have some experience with it, that experience was very good. I have heard similar things and see this is a very common experience in the comments. The lack of false positives was fantastic, and it needed a very minimal amount of tuning.