Cybersecurity Architecture

Where each Yellow Cube product sits on the network — from the OT bus and PLCs, through the air gap, into enterprise IT, cloud and internet. Pairs with our Product Matrix, which weighs the same portfolio by contribution to your security posture.

Click any product below for what it is and why it sits there. Dashed boxes are third-party platforms already common in the estate (identity providers, etc.) — not part of the Yellow Cube portfolio.
See the full Product Matrix →

Purdue Model — What Goes Where

Product placement across the whole stack, read bottom-up: OT buses and PLCs at the base, through the air gap, into enterprise IT, out to the internet and cloud. Each network is drawn as one L2 segment; the spine on the left is how they interconnect. Click any product for what it is and why it sits there.

Yellow Cube portfolio
Your existing provider — not ours
or Equivalent options — choose one
L2 segment · hosts hang off it
Routed north ↑
{{ row.level }}
{{ row.domain }}
{{ row.icon }}
{{ row.name }}
{{ row.note }}
{{ row.busLabel }}
{{ h.icon }}{{ h.name }}
{{ slot.icon }}
{{ slot.label }}
{{ slot.choiceNote }}
{{ it.sep }}
{{ row.icon }}
{{ row.level }}
{{ row.name }}
{{ row.note }}
{{ slot.icon }}
{{ slot.label }}
{{ slot.choiceNote }}
{{ it.sep }}
Across every layer
Cutout · L4 Office network

Where the agents actually sit

The same host stack twice — a virtualised server and a user workstation — opened up. Highlighted rows are where a Yellow Cube component is installed or where telemetry is taken. The workstation carries the full agent; the server carries it per guest, never on the hypervisor fabric.

{{ iconServer }}
IT server (virtualised)
Rack
HW
Server hardware · NIC · BMC
Virt
Hypervisor · vSwitch — no agent on the fabric
Kernel
Guest OS kernel — EDR kernel driver / ETW hooks
OS
OS services — EDR/XDR agent + log forwarder
Apps
App · DB · file shares — Varonis reads the shares
{{ iconUp }}Agent telemetry and syslog leave to the XDR collector, then the 24×7 SOC.
{{ iconTap }}Switch SPAN mirrors this host's traffic to the NDR sensor — nothing installed for it.
{{ iconMonitor }}
IT workstation
Desk
HW
Laptop · TPM · USB ports
Kernel
Windows kernel — EDR driver + USB device control
OS
OS services — EDR/XDR agent, insider-risk agent, DNS client
Apps
Browser · mail client · line-of-business apps
User
Sign-in — SSO, MFA, badge tap
{{ iconUp2 }}Same agent, same console as the server — one policy, two host classes.
{{ iconTap2 }}DNS is filtered at the resolver before the packet leaves the segment.
Server NIC
Workstation NIC
{{ iconNet }}
The wire between them
L2 segment
Switch
Core switch — SPAN / mirror port or in-line TAP
Mirrored copy
NDR sensor — a copy of the traffic, nothing installed
{{ s.sep }}
{{ iconTap3 }}The sensor is passive: it never sits in the path, so it cannot drop a packet or stop a line.
Both feeds land in the same XDR case: the agent says what ran on the host, the sensor says what crossed the wire. The SOC needs both to close a case.
{{ iconEye2 }}
The gap the agents leave
{{ b.t }}
Purdue levels are indicative — real zone boundaries follow the customer's segmentation, not the model.
Yellow Cube Cyberdefense · Full product matrix
{{ sel.vendor }}
{{ sel.name }}
{{ sel.icon }} {{ sel.cat }}

{{ sel.what }}

Sits at
{{ sel.where }}
Complementary vendor — not part of the Yellow Cube portfolio.
Vendor site ↗

Let’s Build Smarter Cyber Defenses Together

Partnerships are the foundation of everything we do — built on trust, expertise, and shared success. Whether you’re looking to grow your business, strengthen your cybersecurity offerings, or bring innovative solutions to new markets, Yellow Cube is ready to be your committed, long-term ally.