Resources

Threat intelligence, research, and everything you need to understand preemptive security.

All resources

Press Enter to search or Esc to close

Buyer Guide

AMTD Vendors: Network vs Endpoint Moving Target Defense

Two meanings of the same acronym, and why they protect different layers.

Last reviewed: October 2026. Vendor statements are from the public pages listed under Sources (accessed 2026-10-09). PacketViper statements are from PacketViper’s own published pages.

The short answer

“Automated Moving Target Defense” is used for two different things. Network-layer AMTD continuously changes the surface a network exposes, so that what an attacker scans and maps keeps changing, and it is enforced in the network path without installing anything on protected devices. Endpoint memory moving target defense morphs the memory and runtime of processes on a host, so that exploits and in-memory attacks do not find what they expect. They protect different layers and are complementary. For the underlying concept, see What is Automated Moving Target Defense (AMTD)?

Network-layer AMTD

Network AMTD works on what an attacker can observe from the outside of a host: addresses, open ports, service banners and signatures. PacketViper rotates these continuously, so a scan returns different results each time, and any interaction with a deceptive responder triggers enforcement in the packet path (block, redirect, throttle or tarpit). It is agentless on the network side, which is what makes it usable for PLCs, RTUs and other devices that cannot run software.

Endpoint memory moving target defense

Endpoint MTD works inside the host. Morphisec describes it this way: “As an application loads to the memory space, Morphisec morphs the process structures, making the memory constantly unpredictable to attackers.”[1] Morphisec states that exploits and in-memory attacks “hit a target that is not where they expect and fail deterministically”.[2] It runs as a single lightweight agent on Windows, Windows ARM, macOS and Linux, alongside existing EDR.[2]

Side by side

DimensionNetwork-layer AMTD (PacketViper)Endpoint memory MTD (Morphisec)
What movesThe network surface: addresses, ports, banners and service signatures that an attacker can scan and map.Process structures and runtime memory on the host.[1]
Where it runsIn the network path, inline.On the endpoint or server, as an agent.
Agent requiredNo for the network platform. An optional AMTD Agent covers Windows and Linux hosts.Yes. A single lightweight agent.[2]
Typical threat addressedReconnaissance, scanning, lateral movement and probing of network services.Exploits, fileless and in-memory attacks, and ransomware execution on the host.
Devices it can protectAnything on the protected network segment, including OT and IoT devices that cannot host software.Hosts that can run the agent (Windows, macOS, Linux).
OT / ICSNative inline OT protocol support. Native, inline support for Modbus, DNP3, BACnet and S7COMM, with more than 20 OT protocols recognized.Not publicly documented in the sources reviewed.

When each fits

Network-layer AMTD fits when

Assets cannot run an agent: PLCs, RTUs, legacy hosts, IoT devices and medical equipment.
You want to deny reconnaissance and contain probing before it reaches a host.
You need enforcement across a segment regardless of what each device runs.
Sites may be air-gapped or intermittently connected and must keep enforcing locally.

Endpoint memory MTD fits when

Your priority is stopping memory-based attacks and ransomware on managed endpoints and servers.
You already run EDR and want a prevention layer beneath it.
Assets are Windows, macOS or Linux machines that can host a lightweight agent.

Why they are complementary

An attacker has to find something, reach it and then run something. Network AMTD works on the first two steps: it makes the reconnaissance data unreliable and contains probes at first contact. Endpoint memory MTD works on the last: if code does run on a host, the memory it expects to exploit is not where it expects. A defense that covers only one of those steps leaves the others to other tools.

PacketViper also offers an AMTD Agent for Windows and Linux hosts. It applies PacketViper’s approach at the host’s network surface (rotating decoy services on free ports, with full attribution of anything that touches them), not in process memory, so it is a different mechanism from memory morphing.

Vendor-by-vendor detail: PacketViper vs Morphisec. For deception products that are not AMTD, see Network Deception Vendors: How to Choose.

Sources

  1. Morphisec, Automated Moving Target Defense Accessed 2026-10-09.
  2. Morphisec, home page Accessed 2026-10-09.
What is the difference between network AMTD and endpoint MTD?

Network AMTD changes the surface a network exposes, such as addresses, ports and banners, and enforces in the network path. Endpoint MTD changes memory and runtime on a host, using an agent.

Do I need both network and endpoint moving target defense?

They protect different steps of an attack. Network AMTD works on reconnaissance and reaching targets, and endpoint MTD works on code execution on a host. Many environments benefit from both.

Can endpoint MTD protect OT devices?

Endpoint MTD needs an agent on the device. PLCs, RTUs and similar devices generally cannot run one, which is why network-layer AMTD is used for them.

Is PacketViper an endpoint MTD product?

PacketViper’s core product is network-layer AMTD with inline enforcement. Its optional AMTD Agent works at a host’s network surface, not in process memory.

See network AMTD in your environment

Book a demonstration or request a proof of concept.