How it works

Enforce boundaries that move with workloads.

PacketSpear Node agents collect flow telemetry from every endpoint. The Gate enforcement engine applies firewall rules on Linux hosts. Command gives operators a single dashboard across all devices.

1

Deploy Node agents

Ship the Node agent to each endpoint with the standard installer. Nodes use mTLS to authenticate to PacketSpear Core and begin exposing rich flow telemetry and process context.

2

Define policy-as-code

Express network boundaries in structured JSON. The policy engine evaluates decisions in real time, auto-prioritized: Deny rules first, then Allow, then the global default.

3

Enforce at the Gate

The Gate enforcement engine applies native firewall rules on every host using policy bundles signed by Core. macOS endpoints stay in safe visibility-only mode.

4

Observe & iterate

PacketSpear Command (Overwatch, Scope, Watch surfaces) gives operators full visibility into flows, telemetry, alerts, and audit trails — all in a single interface.

Visibility only

Free tier shows every connection, process, and TLS fingerprint with zero cost. Unlimited devices, free forever.

Fully enforced

Pro tier unlocks full L3/L4/L7 enforcement with process-level kernel probes and L7 TLS fingerprinting. Honeyports deploy decoy listeners that alert on unauthorized access attempts.

Command UI

One plane. Every endpoint.

PacketSpear Command gives operators one place to define boundaries, observe flows, enforce policy, and validate rollout across endpoints, workloads, gateways, and relays. Overwatch, Scope, and Watch provide observability, exploration, and live operational pulse.

Deployment & Control

Self-hosted. Always yours.

PacketSpear runs on your hardware, in your network. No cloud dependency, no data exfiltration. You own the CA, the keys, the flows, and the audit trail.

PacketSpear Core

Policy and API server. Single binary with embedded static dashboard, OpenAPI spec, and systemd/launchd service files.

  • REST API + HMAC webhook signing
  • Ed25519-signed policy bundles
  • PostgreSQL persistence
  • mTLS for Node connectivity

PacketSpear Node

Endpoint agent installed on every protected device. Collects flow telemetry and enforces policy locally.

  • mTLS-encrypted to Core
  • Process-level kernel probes
  • Cross-platform (Linux, Windows, macOS)
  • Prometheus /metrics exposed

PacketSpear Gate

Enforcement engine for every host. Applies native firewall rules from Core policy bundles. (Pro and Enterprise tiers)

  • Platform-native enforcement
  • Node-supplied rules, Core-verifiable
  • Dry-run and apply workflows
  • CLI: gate apply, gate clear

PacketSpear Relay

Background worker for event processing. Delivers webhooks, manages JIT access grants, processes audit events, and handles MFA challenge flows.

  • JIT firewall grants with TTL expiry
  • Multi-factor auth: TOTP, Duo, OIDC, RADIUS
  • Wildcard relay enforcement
  • Alarm relay & shared identity management

Security & Provenance

Built for serious operators.

Every security decision in PacketSpear is signed, verifiable, and auditable.

mTLS everywhere

All inter-component communication is mutual TLS with a self-managed internal CA. Certificate chains and identity binding enforce true peer confidence.

Ed25519 signatures

Policy bundles and license entitlements are cryptographically signed by Core. Nodes verify every bundle before applying enforcement rules.

Self-hosted by design

No cloud dependency. All telemetry stays on your infrastructure. Phone-home is opt-in and limited to install ID, version, and device count only.

HMAC webhook verification

All webhook payloads include HMAC-SHA256 signatures for integrity verification. Scope per-policy, per-device, or per-account.

Audit & provenance

Prometheus metrics ship with the standard installer. Grafana dashboards and AlertManager rules are included out of the box. Policy bundles are versioned, signed, and tracked.

Zero-brick invariant

Visibility is never disabled by licensing logic. Grace periods degrade to visibility_only mode only — never to full deny, preserving baseline monitoring.

Honeyports (Decoy Listeners)

Deploy deceptive TCP ports that appear open to scanners. Every access attempt is captured with remote address and surfaced as an alert in the Command Watch dashboard. Rate-limited to prevent alert fatigue.

Pricing

Start free. Enforce when ready.

Free visibility forever. Add enforcement, JIT, and enterprise features as your needs grow.

Free

$0 /month
Unlimited devices
Full TCP/UDP/Process visibility
TLS fingerprinting
Command dashboard with Overwatch
Prometheus /metrics
Community support
Start free

Team

$5.99 /device/month
30-day free trial — full enforcement
Everything in Free
L3/L4 enforcement
Policy-as-code (JSON + CLI)
Email support
Up to 50 devices
Start free trial

Enterprise

Custom
Everything in Pro
Process-level kernel probes
JIT access with MFA
MSSP multi-tenancy
SOC 2 readiness
Dedicated support + SLA
Custom integrations
On-prem / air-gapped deploy
Contact sales

Ready to pierce lateral movement?

Download PacketSpear, deploy Nodes across your fleet, and start building policy-as-code today.

Get started free Download white paper