A 48-service, 19-agent platform for cyber-physical reverse engineering — built on 30+ industry frameworks, running on dual Tesla P40 GPUs.
--
Lines of Code
--
Services
--
AI Agents
--
Web Apps
--
REST APIs
--
MCP Servers
--
LLM Models
--
Source Files
Architecture
ARKONA is built on the FS-RE Meta-Model v2.0 — a full-stack reverse engineering framework with three axes: 8 vertical layers (L0-L7), 8 analytical viewpoints, and 6 process phases. Every tool maps to a specific layer in the stack.
FS-RE Layers
Each layer in the stack maps to a specific domain of reverse engineering — from the physics of industrial processes up through firmware, protocols, and user interfaces. Analysis is bottom-up: every finding at a lower layer informs the layers above it.
L0Physical Process
The actual physics the OT system controls — process dynamics, SIL levels, P&ID elements, environmental conditions, and safety constraints. Where cyber meets physical.
Process ProfilerP&ID AnalysisIEC 61508
L1Sensing & Actuation
Hardware reverse engineering — PCB analysis, component identification, signal tracing, schematic extraction. AI vision identifies components from board photos and generates KiCad schematics.
KiCad AgentHardware RESpec Sheet Agent7 MCP Tools
L2Control Logic
Firmware extraction, emulation, and analysis. The System Emulation Foundry (SEF) supports three modes: Autopilot (AI-driven), Copilot (AI-assisted), and Manual. Ghidra headless bridge for binary analysis.
SEFGhidraQEMUbinwalk
L3Communication
Industrial protocol analysis — 8 ICS protocol signatures, Modbus deep inspection, PCAP topology discovery with Purdue model classification, OT asset inventory with Graphviz export.
IT/OT boundary discovery, DMZ topology mapping, trust zone classification per IEC 62443, REST/ICS endpoint discovery, and attack surface enumeration.
Boundary MapperAPI Analyzer8 MCP ToolsIEC 62443
L6Data & Evidence
Digital evidence vault with chain of custody, SHA-256 hashing, AI summarization. Auto-generates Wiki.js articles from ingested artifacts. NIST SP 800-86 compliant.
VAULTWiki.jsEvidence ChainNIST 800-86
L7User Interface
The human-facing layer. COMET provides AI governance with 5-level delegation classification across 816+ task definitions. FORGE orchestrates 7 AI agents for autonomous software development.
COMETFORGEARKONA HUD5 Delegation Levels
Operational Domains
The ecosystem is organized into six operational domains, each with its own services, APIs, and web applications. CoreOps is the primary domain containing the full FS-RE reverse engineering stack.
30+ Source Frameworks
The meta-model synthesizes established frameworks from systems engineering, OT security, architecture, threat intelligence, risk quantification, and forensics into a unified ontology.