Minerva

Everything you operate takes orders. Make sure they're yours. Minerva detects threats inside the system it protects — spacecraft, defence platforms, and enterprise networks — and flags them before they can act.

Talk to our experts

The problem

Detection that lives somewhere else always arrives late.

Modern systems are networked by default and trusted by default. A spacecraft executes what the uplink tells it. An uncrewed platform acts on what its sensors report. An enterprise network permits what a valid credential requests.

Each of those assumptions is now an attack surface. Links get spoofed. Traffic gets injected. Firmware arrives from suppliers you don't control. Credentials get borrowed by people who shouldn't have them.

The common failure is that the thing capable of noticing sits somewhere else — on the ground, in a SOC, at the end of a link — and by the time it notices, the command has been obeyed.

The approach

It sees what no one else does.

Signatures catch the attacks the industry has named. Behavioural analysis catches the ones no one has seen yet by learning how the system normally operates and flagging what departs from it. Both run locally, in real time.

It sits where the commands pass.

Minerva operates at the boundary every instruction has to cross. That position is what makes real-time inspection possible and what lets security policy be updated without touching anything else.

It fits what you already run.

Hardware module, embedded software, or ground-side companion. Standard interfaces, standard APIs, integration with the SIEM and SOC you already operate.

Three domains

  • Space

    A spacecraft has no perimeter and no analyst on shift. Minerva runs on board, between the communication system and the on-board computer, inspecting traffic before the systems that would act on it ever see it.

    • MINERVA-H — dedicated hardware module. Ethernet, SpaceWire, UART, CAN.
    • MINERVA-S — embedded software on the existing OBC.
    • MINERVA-GSC — ground-segment companion for forensics, policy and model updates.
    • Adapts to single-string, dual-redundant, supervised dual-redundant and distributed architectures.
  • Defence

    Modern defence equipment is no longer purely mechanical. Vehicles, uncrewed systems and armoured platforms are built from components sourced across global supply chains, running software from dozens of vendors.

    Minerva continuously monitors every connected component — sensors, subsystems, firmware, data links, operators — to detect anomalous or malicious behaviour, including from sources the system is supposed to trust.

    When a UGV operates autonomously in the field, or a drone swarm receives a command, the question is whether the source is legitimate. Minerva answers it on the platform, without a link home.

  • Enterprise

    Software only, no hardware change. Minerva learns the normal shape of your network — the traffic patterns, the entities on it, the way they usually behave — and flags what doesn't fit.

    That means catching the activity that is technically permitted but genuinely wrong: the lateral movement, the unusual access pattern, the account behaving unlike itself. Findings go into the SIEM and SOC workflow you already have.

Minerva's origin

Built where the constraints are hardest.

Minerva began as research under the European Space Agency, solving for a system that has to defend itself with no operator intervention, limited compute, and no guaranteed link home.

Those constraints produced something broadly useful. A defence platform in contested conditions faces the same problem. So does any network where the response has to be faster than a human shift pattern.

Learn more about the development of Minerva

Let's talk

Minerva adapts to the architecture you already have. The fastest way to find out what that looks like is a technical conversation with the people who built it.

Sander Valvas

Head of Cybersecurity Department

sander.valvas@cyber.ee