PacketSpear is a self-hosted microsegmentation platform with free visibility, graduated enforcement, and a control plane you own. From flow monitoring to L7 firewall to JIT access — one platform, every endpoint.
Enforce network policy at the endpoint, not the switch. PacketSpear's enforcement engine runs directly on your hosts — no network fabric changes, no hypervisor lock-in.
Most microsegmentation stops at IP:port. PacketSpear goes deeper — inspect TLS handshakes, filter by URL path, and identify applications by their cryptographic fingerprint.
Detect lateral movement before it succeeds. Honeyports are decoy listeners on unused ports — any connection attempt triggers an alert and can isolate the source device.
Treat microsegmentation like infrastructure. Policies are JSON documents — store them in Git, deploy them with a CLI, and manage them with our Terraform provider.
No more permanent firewall holes. Just-in-Time access grants expire automatically after a configurable TTL — and every grant requires MFA challenge before the connection is allowed.
Connect PacketSpear to your security workflow. Webhooks fire on device enrollment, policy changes, threat detection, JIT grants, and flow anomalies — with HMAC signing for integrity.
Ingest STIX/TAXII threat feeds and automatically block known malicious indicators. Define custom indicators with TTL-scoped rules that integrate directly with the policy engine.
Manage microsegmentation for dozens of customers from a single control plane. Parent accounts define global policy templates; child accounts receive tenant-isolated policies and flows.
A single pane of glass for your entire deployment. Device inventory, flow heatmaps, policy status, enrollment management, and audit events — all from an embedded web dashboard.
Prometheus metrics, Grafana dashboards, and Alertmanager rules ship in the standard installer. No extra agents, no separate monitoring stack — observability is built in.
| Platform | Server (Core/Relay) | Agent (Node) | Enforcement |
|---|---|---|---|
| Linux (kernel 5.15+) | ✓ Full | ✓ Full | ✓ Native controls |
| macOS | ✓ Full | ✓ Full | Visibility mode (safe, no kernel panics) |
| Windows | — | Future contract | Future: native firewall integration |
| iOS | — | Future contract | Future: Network Extension |
| Android | — | Future contract | Future: VpnService/firewall |
Start with unlimited devices and full visibility — free, forever. Upgrade to Team or Pro for enforcement when you're ready.