Resources

Threat intelligence, research, and everything you need to understand preemptive security.

All resources

Press Enter to search or Esc to close

Vendor Comparison

PacketViper vs. Acalvio ShadowPlex

A dated, source-cited comparison of inline AMTD and enforcement with projected, agentless deception.

Last reviewed: October 2026. Vendor information was accessed on 2026-10-09 from the public sources listed at the end of this page. Vendor capabilities change; confirm current details with each vendor. Where a fact could not be found in public material, this page says “Not publicly documented”.

Summary

Acalvio ShadowPlex and PacketViper both use deception, but they sit in different places. Acalvio describes ShadowPlex as an agentless deception platform whose decoys are “projected” into the network, and states that deception “does not sit inline”.[1] PacketViper is an inline platform: Automated Moving Target Defense (AMTD), deception and enforcement all run in the packet path.

Both are agentless on the network side. The practical difference is what happens at first contact with a decoy: with ShadowPlex, response is carried out through integrations; with PacketViper, enforcement is part of the same inline system.

Comparison

DimensionAcalvio ShadowPlexPacketViper
Deception approachAutonomous deception. Decoys are generated and managed inside the ShadowPlex service and only “projected” into the network; OT decoys represent HMIs, PLCs and controllers across the levels of the Purdue reference architecture.[1]Deceptive responders on the network path, delivered as one capability within AMTD rather than as the whole product.
AMTDNot publicly documented in the sources reviewed.Yes. Network-layer AMTD continuously changes what an attacker can map (addresses, ports, banners, service signatures). An optional AMTD Agent applies the same approach to Windows and Linux hosts.
Inline enforcementNo. Acalvio states that deception “does not sit inline, does not scan and does not disrupt normal OT operations”. ShadowPlex supports automated isolation of a compromised endpoint through pre-built integrations, and sends incidents to SIEM and SOAR.[1]Yes. Enforcement runs in the packet path (block, redirect, throttle or tarpit) without a separate orchestration step.
AgentlessYes. Acalvio states “ShadowPlex is agentless”.[1]Yes for the network platform: nothing is installed on protected devices. The AMTD Agent is a separate, optional endpoint component.
OT protocol supportModbus, BACnet, EtherNet/IP and S7 are named in the OT brief;[1] Acalvio’s OT page names Modbus and DNP3 as examples.[2]Native, inline support for Modbus, DNP3, BACnet and S7COMM, with more than 20 OT protocols recognized.
Deployment modelAcalvio states its solutions deploy on-premises, in the cloud or through managed service providers.[1] Cloud deployment is described as agentless through cloud-native APIs.[3]Inline nodes (bridge mode) on commodity server hardware, managed as a federation. Nodes keep enforcing when disconnected from central management.

When to choose Acalvio ShadowPlex

You want detection-first deception across a large IT, OT and cloud estate with nothing in the data path. Acalvio states ShadowPlex does not sit inline.
Policy forbids inline devices, even in bridge mode, or you prefer to keep enforcement in the controls you already own (firewalls, EDR, NAC) and have deception feed them through integrations.
Cloud and identity deception is a priority. Acalvio describes honeytokens and fake accounts for IAM and cloud-native services in ShadowPlex Cloud Security.
You want incidents mapped to MITRE ATT&CK for ICS; Acalvio states ShadowPlex OT incidents are mapped to that framework.

When to choose PacketViper

You need action at first contact in the packet path, not after an alert reaches a SIEM or SOAR workflow.
You want the attack surface itself to change (AMTD), not only a set of decoys placed in it.
You protect OT sites that must keep enforcing when the link to central management is down.
You want deception, AMTD and contextual traffic control from one platform rather than a deception layer plus separate enforcement tools.

Can they be used together?

Nothing in either vendor’s public material rules it out: a projected-decoy platform and an inline enforcement platform address different points in the path. Whether the two products integrate directly is Not publicly documented.

PacketViper statements on this page come from PacketViper’s own published pages: Deception and AMTD, AMTD Agent, Performance Benchmarks and PacketViper vs Claroty.

Sources

  1. Acalvio, ShadowPlex for OT/ICS Security solution brief (PDF, (c) 2024) Accessed 2026-10-09.
  2. Acalvio, OT/ICS Security solutions page Accessed 2026-10-09.
  3. Acalvio, ShadowPlex Cloud Security Accessed 2026-10-09.
What is the main difference between PacketViper and Acalvio ShadowPlex?

Acalvio describes ShadowPlex as agentless deception that does not sit inline, with response carried out through integrations. PacketViper is an inline platform that combines AMTD, deception and enforcement in the packet path.

Does Acalvio ShadowPlex require agents?

Acalvio states that ShadowPlex is agentless. PacketViper’s network platform is also agentless; PacketViper separately offers an optional AMTD Agent for Windows and Linux endpoints.

Does ShadowPlex block traffic itself?

Acalvio states that deception does not sit inline. It describes automated isolation of a compromised endpoint through pre-built integrations rather than in-path blocking by ShadowPlex.

Can PacketViper and ShadowPlex be used together?

Nothing in the public material rules it out, but a direct integration between the two is Not publicly documented. Ask both vendors during evaluation.

See inline enforcement in your environment

Book a demonstration of PacketViper’s AMTD and inline enforcement, or request a proof of concept.