What you are evaluating
This profile covers Guardian and its local analyst functions. Vantage cloud management, Central Management Console, Arc host sensors, Threat Intelligence and Asset Intelligence subscriptions must be scoped separately.
A useful evaluation context
Industrial teams studying network baselines, asset changes and evidence-led OT investigations.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Asset and network views describe communicating devices and their relationships.
- N2QL queries let analysts filter and investigate collected information.
- Time machine compares saved states; results depend on the snapshots and fields available.
Where it fits in the work
- Validate that the mirrored traffic includes both sides of the process-cell communications.
- Inspect the asset record and related alerts, then use N2QL to test a specific hypothesis.
- Compare relevant saved snapshots and explain the change to the site owner before proposing remediation.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
Create two authorized lab snapshots around a maintenance change and compare them with Time machine. Identify a meaningful configuration change and a routine traffic-counter change.
Evidence to look for
Record snapshot times, excluded fields and the maintenance approval. Explain why a difference warrants investigation rather than automatically labeling it an attack.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which sensors, subscriptions and central-management options are included?
- What snapshot schedule and storage capacity preserve the required investigation window?
- Which device details require approved Smart Polling instead of passive observation?