Industrial Asset Management Built Around Trustworthy Evidence

OTserver keeps discovery evidence, human decisions, and access boundaries together in one self-hosted inventory.

OTserver asset inventory with industrial device details

Inventory that survives network changes

Every asset is identified by its normalized MAC address, not an IP address, device name, or serial number. Records without a usable MAC are skipped instead of being attached to the wrong device.

  • Track vendor, model, firmware, protocols, ownership, location, status, criticality, and custom fields.
  • Search with the graphical filter builder or the supported Lucene query syntax.
  • Define asset classes and automatic manufacturer/model classification rules.

OTserver asset classes with classification rule counts, priorities, and links to matching assets

Evidence-aware imports

OTserver accepts three discovery formats:

SourceFormatWhat it preserves
OTserver OtterSchema-version-2 JSONObservations, interfaces, ports, topology, warnings, and field quality
Siemens PRONETAXML topology exportHigh-quality Siemens-oriented device and topology data
NmapXML produced with -oXExisting generic discovery workflows

Field values follow an explicit quality order:

1
human > high > medium > low

Stronger evidence can improve weaker data. Weaker evidence cannot overwrite stronger data, and manual edits remain authoritative.

Network topology

Inspect the selected site’s assets and connections in the network topology view. Solid links show recorded connections; dotted links distinguish inferred membership.

OTserver network topology showing a router, switch, industrial assets, recorded links, and inferred network membership

Sites, roles, and accountability

OTserver site hierarchy

Build a hierarchy with the site types and depth your organization uses. Grant users read-only or read/write permission at any site; access applies to its descendants. The protected Admin role retains unrestricted access.

Every registered collection is audited. The immutable audit log records inventory and authentication changes while redacting fields that resemble passwords, secrets, tokens, hashes, or sessions.

OTserver immutable audit log

Native read-only discovery

The scanner is called OTserver Otter — a Rust CLI and GUI that runs on Windows, Linux, and headless AArch64 Linux and exports evidence directly for OTserver. It uses fixed identity requests and does not perform configuration writes, SNMP SET, DCP Set, brute force, exploits, vulnerability scripts, or Modbus requests. Every protocol can be turned on and off independently. Otter is developed alongside the application on GitHub: OTserver and OTserver Otter.

Explore the protocol discovery guides, read the Otter guide, or deploy OTserver.