DRAFT — PUBLIC PREVIEW

PacketSpear White Paper

Self-Hosted Microsegmentation — Technical Overview

▶ Read Now

Executive Summary

Modern networks have dissolved the perimeter. Every endpoint — laptop, server, mobile device, cloud instance — is a potential entry point. Traditional network segmentation tools are expensive, complex, and tied to specific hardware or cloud vendors.

PacketSpear is a self-hosted microsegmentation platform that gives every team free visibility, operator-owned enforcement, and cross-platform coverage from mobile to server — without the enterprise price tag.

PacketSpear gives every team free visibility, operator-owned enforcement, and cross-platform coverage from mobile to server — without the enterprise price tag.
Platform Architecture

Platform Components

Component What It Does Runs On Available In
Core Central API server: manages device enrollment, policy storage, certificate authority, flow ingestion, and the Command dashboard. This is the control plane. Linux, macOS (server) All tiers
Node Endpoint agent: collects flow telemetry from every device, sends heartbeats, and carries the enforcement boundary. One Node per protected device. Linux, macOS All tiers (visibility always free; enforcement requires Pro)
Gate Enforcement engine: reads policies from Core, generates and applies native firewall rules. Supports dry-run, apply, and clear workflows. Linux (kernel 5.15+) Pro, Enterprise
Relay Background worker: processes flows and audit events, handles JIT access grants, MFA challenges, and webhook delivery. Linux, macOS (server) All tiers
Command Operator dashboard (Overwatch / Scope / Watch): device inventory, flow topology maps, policy status, audit viewer, honeyport alerts. Embedded in Core. Browser (any) All tiers

System Overview

Core Gate 1 Gate 2 Gate 3 ┌─────────┐ ┌────────┐ ┌────────┐ ┌────────┐ │ Command │ ───▶ │ Linux │ │ Linux │ │ Linux │ │ [Web UI] │ └─────────┘ │ │ │││││ │ │ │ │││││ │ │ ││││││ ││││ ││││ │ ││││││ ││││ ││││ ┌─────────┐┌────────┐ ┌────────┐ ┌────────┐ │ Core ││││││ ││││ Node │ │ Node │ │ [API+CA││││││ ││││ [Agent] │ │ [Agent] │ │ Relays] ││││││ ││││ └────────┘ │ └────────┘ └─────────┘└────────┘ │ │ │ │ │ │ │ │ └─────────┐ [Node] │ │ │ ┌────────┐ │ │ Node │ │ │ [Agent] │ │ └────────┘ NAT / Firewall / Router Device \u2194 Core: mTLS Policy Bundle: Ed25519 signed
Deployment Flow

How It Works

Deploy Core on a server — one command, Docker or systemd.

Install Node agents on every endpoint you want to protect.

Nodes authenticate to Core via mTLS with device certificates.

Define policies as JSON (policy-as-code) — what can talk to what.

Core signs policy bundles with Ed25519 and delivers them to Nodes.

Gate applies enforcement rules (free tier: visibility-only; Pro: full enforcement).

Command dashboard shows flows, alerts, honeyport access attempts, and policy status.

Deceptive Security

Honeyports — Decoy Ports

PacketSpear honeyports are deceptive TCP listeners deployed on protected endpoints. They appear as open services to network scanners but expose no real application. Any connection attempt is immediately captured — remote address, targeted port, timestamp — and surfaced as an alert in the Command dashboard.

Deploy decoy ports on any endpoint: SSH (22), RDP (3389), databases (5432, 3306), HTTP (80, 443). Every access attempt generates an audit event with full details.

Key Features

  • Rate-limited to 10 events/second to prevent alert fatigue during scans.
  • Configurable per device via API or policy bundle.
  • Alerts appear in the Command Watch panel alongside other security events.
Feature Set

Key Capabilities

Microsegmentation Enforcement

L3/L4/L7 enforcement with process-level kernel probes and TLS/URL/SNI filtering. Cross-platform across Linux, Windows, and macOS — using each platform's native security framework with graceful degradation to visibility mode when kernel enforcement isn't available.

Process-level visibility (Enterprise). Every connection is mapped to its owning process, binary path, and user across Linux, Windows, and macOS. Same capability, different native engines — and it enriches, never replaces, each platform's native firewall.

Policy-as-Code

JSON format, CLI-driven, Terraform provider, Ed25519-signed bundles, snapshot/rollback.

JIT Access + MFA

Time-bound firewall grants, TOTP/Duo/OIDC/RADIUS, device certificates, identity predicates.

Honeyports

Decoy TCP listeners, access alerts with remote address capture, rate-limited event generation.

Webhook Automation

Event-driven, HMAC-SHA256 signed, per-policy/device/account scoping.

Threat Intelligence

STIX/TAXII ingestion, custom indicators, TTL-scoped blocks.

MSSP Multi-Tenancy

Parent/child accounts, global templates, tenant-safe bundles.

Observability

Operator dashboards, metrics, and alerting rules — all in the standard installer.

90% of the value of enterprise microsegmentation, self-hosted, cross-platform, affordable.
Market Comparison

Competitive Positioning

Enterprise Platforms

Illumio, Guardicore, Cisco

90% of the value, self-hosted, cross-platform, affordable.

Zero Networks

Zero Networks

Deeper process/TLS context, mobile coverage, self-hosted ownership.

Overlay Networks

Tailscale, NetBird

Full visibility of all traffic paths including LAN, process-level, with enforcement.

Switch-Based

Elisity, NSX

No hardware lock-in; every endpoint carries its own boundary.

Plans

Pricing

Free

$0/month
Unlimited devices
  • Full visibility
  • Command dashboard
  • Observability dashboards
  • Community support

Team

$5.99/device/month
Everything in Free, plus
  • L3/L4 enforcement
  • Policy-as-code
  • Email support
  • Up to 50 devices

Enterprise

Custom
Everything in Pro, plus
  • Process-level kernel probes
  • JIT + MFA
  • MSSP multi-tenancy
  • Threat intel
  • Dedicated support + SLA
Free tier includes unlimited devices and full visibility. Start protecting your network today with zero cost.
Future

Roadmap

v1

Current: All capabilities above, including honeyports, JIT access, webhook automation, threat intel.

v1.x

Cloud/container awareness, compliance templates, SIEM integrations.

Later

Multi-site federation, OT/IoT protocols.