Turn hostile traffic into controlled paths.
PacketSpear delivers precision defense for every packet path. Self-hosted microsegmentation with visibility, enforcement, and policy-as-code — from mobile to server.
PacketSpear delivers precision defense for every packet path. Self-hosted microsegmentation with visibility, enforcement, and policy-as-code — from mobile to server.
How it works
PacketSpear Node agents collect flow telemetry from every endpoint. The Gate enforcement engine applies firewall rules on Linux hosts. Command gives operators a single dashboard across all devices.
Ship the Node agent to each endpoint with the standard installer. Nodes use mTLS to authenticate to PacketSpear Core and begin exposing rich flow telemetry and process context.
Express network boundaries in structured JSON. The policy engine evaluates decisions in real time, auto-prioritized: Deny rules first, then Allow, then the global default.
The Gate enforcement engine applies native firewall rules on every host using policy bundles signed by Core. macOS endpoints stay in safe visibility-only mode.
PacketSpear Command (Overwatch, Scope, Watch surfaces) gives operators full visibility into flows, telemetry, alerts, and audit trails — all in a single interface.
Free tier shows every connection, process, and TLS fingerprint with zero cost. Unlimited devices, free forever.
Pro tier unlocks full L3/L4/L7 enforcement with process-level kernel probes and L7 TLS fingerprinting. Honeyports deploy decoy listeners that alert on unauthorized access attempts.
Command UI
PacketSpear Command gives operators one place to define boundaries, observe flows, enforce policy, and validate rollout across endpoints, workloads, gateways, and relays. Overwatch, Scope, and Watch provide observability, exploration, and live operational pulse.
Deployment & Control
PacketSpear runs on your hardware, in your network. No cloud dependency, no data exfiltration. You own the CA, the keys, the flows, and the audit trail.
Policy and API server. Single binary with embedded static dashboard, OpenAPI spec, and systemd/launchd service files.
Endpoint agent installed on every protected device. Collects flow telemetry and enforces policy locally.
Enforcement engine for every host. Applies native firewall rules from Core policy bundles. (Pro and Enterprise tiers)
Background worker for event processing. Delivers webhooks, manages JIT access grants, processes audit events, and handles MFA challenge flows.
Security & Provenance
Every security decision in PacketSpear is signed, verifiable, and auditable.
All inter-component communication is mutual TLS with a self-managed internal CA. Certificate chains and identity binding enforce true peer confidence.
Policy bundles and license entitlements are cryptographically signed by Core. Nodes verify every bundle before applying enforcement rules.
No cloud dependency. All telemetry stays on your infrastructure. Phone-home is opt-in and limited to install ID, version, and device count only.
All webhook payloads include HMAC-SHA256 signatures for integrity verification. Scope per-policy, per-device, or per-account.
Prometheus metrics ship with the standard installer. Grafana dashboards and AlertManager rules are included out of the box. Policy bundles are versioned, signed, and tracked.
Visibility is never disabled by licensing logic. Grace periods degrade to visibility_only mode only — never to full deny, preserving baseline monitoring.
Deploy deceptive TCP ports that appear open to scanners. Every access attempt is captured with remote address and surfaced as an alert in the Command Watch dashboard. Rate-limited to prevent alert fatigue.
Pricing
Free visibility forever. Add enforcement, JIT, and enterprise features as your needs grow.
Download PacketSpear, deploy Nodes across your fleet, and start building policy-as-code today.