PacketSpear

Everything you need to control every packet path

PacketSpear is a self-hosted microsegmentation platform with free visibility, graduated enforcement, and a control plane you own. From flow monitoring to L7 firewall to JIT access — one platform, every endpoint.

See Pricing Download

Microsegmentation Engine

Enforce network policy at the endpoint, not the switch. PacketSpear's enforcement engine runs directly on your hosts — no network fabric changes, no hypervisor lock-in.

  • ✓ Host-native enforcement on Linux (kernel 5.15+)
  • ✓ Process-level probes for deep flow context
  • ✓ Safe visibility-only mode on macOS (no kernel panics)
  • ✓ Gate CLI for dry-run, apply, and clear workflows
  • ✓ Policy bundles with Ed25519 cryptographic signing
🛡️
Enforcement Engine
Native controls
Linux enforcement · macOS visibility
🔍
L7 Inspection
TLS / HTTP / SNI
JA3/JA4 fingerprinting · URL path filtering · HTTP method restriction

L7 Firewall That Actually Works

Most microsegmentation stops at IP:port. PacketSpear goes deeper — inspect TLS handshakes, filter by URL path, and identify applications by their cryptographic fingerprint.

  • ✓ TLS fingerprinting (JA3/JA4) — identify applications by handshake
  • ✓ URL/path filtering — allow, block, or redirect by path
  • ✓ SNI inspection — control TLS connections by server name
  • ✓ HTTP method restriction — POST, GET, DELETE, etc.
  • ✓ All L7 predicates are policy-as-code — no GUI-only config

Honeyport Decoys

Detect lateral movement before it succeeds. Honeyports are decoy listeners on unused ports — any connection attempt triggers an alert and can isolate the source device.

  • ✓ Configurable decoy listeners on any port
  • ✓ Real-time alerts on connection attempts
  • ✓ Automatic source device quarantine option
  • ✓ Webhook integration for SIEM/SOAR workflows
  • ✓ Audit trail for every decoy trigger
🍯
Honeyport Detection
Zero False Positives
Any connection = adversary behavior
📋
Policy as Code
JSON + Terraform
Git-managed · Ed25519 signed · CLI-driven

Policy-as-Code & Terraform

Treat microsegmentation like infrastructure. Policies are JSON documents — store them in Git, deploy them with a CLI, and manage them with our Terraform provider.

  • ✓ JSON policy format — human-readable, machine-verifiable
  • ✓ Terraform provider for day-1 infrastructure-as-code
  • ✓ Policy bundles with Ed25519 cryptographic signing
  • ✓ Snapshot, rollback, and dry-run validation
  • ✓ Real-time policy evaluation engine

JIT Access with MFA

No more permanent firewall holes. Just-in-Time access grants expire automatically after a configurable TTL — and every grant requires MFA challenge before the connection is allowed.

  • ✓ Temporary firewall grants with configurable TTL
  • ✓ MFA challenge flow: TOTP, Duo, OIDC, RADIUS
  • ✓ Device certificates with identity binding
  • ✓ Identity predicates in policy rules
  • ✓ Full audit trail for every access grant
🔐
JIT + MFA
TOTP · Duo · OIDC
Auto-expiring grants · Full audit trail
⚡
Webhook Automation
12+ Event Types
HMAC signed · SIEM/SOAR ready

Webhooks & Automation

Connect PacketSpear to your security workflow. Webhooks fire on device enrollment, policy changes, threat detection, JIT grants, and flow anomalies — with HMAC signing for integrity.

  • ✓ Event-driven webhooks on 12+ event types
  • ✓ Automation actions: quarantine, notify, custom payload
  • ✓ HMAC-SHA256 payload signing for integrity
  • ✓ Scoped to policy, device, or account
  • ✓ Relay worker for async event processing

Threat Intelligence

Ingest STIX/TAXII threat feeds and automatically block known malicious indicators. Define custom indicators with TTL-scoped rules that integrate directly with the policy engine.

  • ✓ STIX/TAXII feed ingestion
  • ✓ Custom threat indicator management
  • ✓ TTL-scoped automatic block rules
  • ✓ Integration with policy engine for real-time blocking
  • ✓ Audit trail for every indicator match
🎯
Threat Intel
STIX/TAXII
Custom indicators · Auto-blocking
🏢
MSSP Multi-Tenancy
Parent/Child
Global templates · Tenant isolation

MSSP Multi-Tenancy

Manage microsegmentation for dozens of customers from a single control plane. Parent accounts define global policy templates; child accounts receive tenant-isolated policies and flows.

  • ✓ Parent/child account hierarchy
  • ✓ Global policy templates with selective child rollout
  • ✓ Tenant-safe policy bundles — sibling isolation guaranteed
  • ✓ Inherited policy visibility for parent operators
  • ✓ Designed for managed security service providers

Command Operator Dashboard

A single pane of glass for your entire deployment. Device inventory, flow heatmaps, policy status, enrollment management, and audit events — all from an embedded web dashboard.

  • ✓ Device inventory with real-time topology
  • ✓ Flow heatmaps for traffic analysis
  • ✓ Policy status and enforcement coverage
  • ✓ Enrollment management with pairing codes
  • ✓ Audit event viewer with filtering
  • ✓ Responsive design for desktop, tablet, and phone
📊
Command Dashboard
Embedded
No extra install · Ships with Core
📈
Default Observability
Prometheus + Grafana
Bundled dashboards · Alertmanager rules

Default Observability

Prometheus metrics, Grafana dashboards, and Alertmanager rules ship in the standard installer. No extra agents, no separate monitoring stack — observability is built in.

  • ✓ Prometheus-compatible /metrics endpoint
  • ✓ Bundled Grafana dashboards for device health, flows, enforcement
  • ✓ Alertmanager rules for heartbeat loss, policy violations
  • ✓ Device counts, flow rates, enforcement status
  • ✓ No external monitoring stack required

Platform Compatibility

PlatformServer (Core/Relay)Agent (Node)Enforcement
Linux (kernel 5.15+)✓ Full✓ Full✓ Native controls
macOS✓ Full✓ FullVisibility mode (safe, no kernel panics)
Windows—Future contractFuture: native firewall integration
iOS—Future contractFuture: Network Extension
Android—Future contractFuture: VpnService/firewall

Ready to control every path?

Start with unlimited devices and full visibility — free, forever. Upgrade to Team or Pro for enforcement when you're ready.

View Pricing Download