Executive Summary
Modern networks have dissolved the perimeter. Every endpoint — laptop, server, mobile device, cloud instance — is a potential entry point. Traditional network segmentation tools are expensive, complex, and tied to specific hardware or cloud vendors.
PacketSpear is a self-hosted microsegmentation platform that gives every team free visibility, operator-owned enforcement, and cross-platform coverage from mobile to server — without the enterprise price tag.
Platform Components
| Component | What It Does | Runs On | Available In |
|---|---|---|---|
| Core | Central API server: manages device enrollment, policy storage, certificate authority, flow ingestion, and the Command dashboard. This is the control plane. | Linux, macOS (server) | All tiers |
| Node | Endpoint agent: collects flow telemetry from every device, sends heartbeats, and carries the enforcement boundary. One Node per protected device. | Linux, macOS | All tiers (visibility always free; enforcement requires Pro) |
| Gate | Enforcement engine: reads policies from Core, generates and applies native firewall rules. Supports dry-run, apply, and clear workflows. | Linux (kernel 5.15+) | Pro, Enterprise |
| Relay | Background worker: processes flows and audit events, handles JIT access grants, MFA challenges, and webhook delivery. | Linux, macOS (server) | All tiers |
| Command | Operator dashboard (Overwatch / Scope / Watch): device inventory, flow topology maps, policy status, audit viewer, honeyport alerts. Embedded in Core. | Browser (any) | All tiers |
System Overview
How It Works
Deploy Core on a server — one command, Docker or systemd.
Install Node agents on every endpoint you want to protect.
Nodes authenticate to Core via mTLS with device certificates.
Define policies as JSON (policy-as-code) — what can talk to what.
Core signs policy bundles with Ed25519 and delivers them to Nodes.
Gate applies enforcement rules (free tier: visibility-only; Pro: full enforcement).
Command dashboard shows flows, alerts, honeyport access attempts, and policy status.
Honeyports — Decoy Ports
PacketSpear honeyports are deceptive TCP listeners deployed on protected endpoints. They appear as open services to network scanners but expose no real application. Any connection attempt is immediately captured — remote address, targeted port, timestamp — and surfaced as an alert in the Command dashboard.
Key Features
- Rate-limited to 10 events/second to prevent alert fatigue during scans.
- Configurable per device via API or policy bundle.
- Alerts appear in the Command Watch panel alongside other security events.
Key Capabilities
Microsegmentation Enforcement
L3/L4/L7 enforcement with process-level kernel probes and TLS/URL/SNI filtering. Cross-platform across Linux, Windows, and macOS — using each platform's native security framework with graceful degradation to visibility mode when kernel enforcement isn't available.
Process-level visibility (Enterprise). Every connection is mapped to its owning process, binary path, and user across Linux, Windows, and macOS. Same capability, different native engines — and it enriches, never replaces, each platform's native firewall.
Policy-as-Code
JSON format, CLI-driven, Terraform provider, Ed25519-signed bundles, snapshot/rollback.
JIT Access + MFA
Time-bound firewall grants, TOTP/Duo/OIDC/RADIUS, device certificates, identity predicates.
Honeyports
Decoy TCP listeners, access alerts with remote address capture, rate-limited event generation.
Webhook Automation
Event-driven, HMAC-SHA256 signed, per-policy/device/account scoping.
Threat Intelligence
STIX/TAXII ingestion, custom indicators, TTL-scoped blocks.
MSSP Multi-Tenancy
Parent/child accounts, global templates, tenant-safe bundles.
Observability
Operator dashboards, metrics, and alerting rules — all in the standard installer.
Competitive Positioning
Illumio, Guardicore, Cisco
90% of the value, self-hosted, cross-platform, affordable.
Zero Networks
Deeper process/TLS context, mobile coverage, self-hosted ownership.
Tailscale, NetBird
Full visibility of all traffic paths including LAN, process-level, with enforcement.
Elisity, NSX
No hardware lock-in; every endpoint carries its own boundary.
Pricing
Free
- Full visibility
- Command dashboard
- Observability dashboards
- Community support
Team
- L3/L4 enforcement
- Policy-as-code
- Email support
- Up to 50 devices
Pro
- L3/L4/L7 enforcement
- Policy-as-code
- Terraform provider
- Webhooks
- Honeyports
- Standard support
Enterprise
- Process-level kernel probes
- JIT + MFA
- MSSP multi-tenancy
- Threat intel
- Dedicated support + SLA
Roadmap
Current: All capabilities above, including honeyports, JIT access, webhook automation, threat intel.
Cloud/container awareness, compliance templates, SIEM integrations.
Multi-site federation, OT/IoT protocols.