AMTD Vendors: Network vs Endpoint Moving Target Defense
Two meanings of the same acronym, and why they protect different layers.
Last reviewed: October 2026. Vendor statements are from the public pages listed under Sources (accessed 2026-10-09). PacketViper statements are from PacketViper’s own published pages.
The short answer
“Automated Moving Target Defense” is used for two different things. Network-layer AMTD continuously changes the surface a network exposes, so that what an attacker scans and maps keeps changing, and it is enforced in the network path without installing anything on protected devices. Endpoint memory moving target defense morphs the memory and runtime of processes on a host, so that exploits and in-memory attacks do not find what they expect. They protect different layers and are complementary. For the underlying concept, see What is Automated Moving Target Defense (AMTD)?
Network-layer AMTD
Network AMTD works on what an attacker can observe from the outside of a host: addresses, open ports, service banners and signatures. PacketViper rotates these continuously, so a scan returns different results each time, and any interaction with a deceptive responder triggers enforcement in the packet path (block, redirect, throttle or tarpit). It is agentless on the network side, which is what makes it usable for PLCs, RTUs and other devices that cannot run software.
Endpoint memory moving target defense
Endpoint MTD works inside the host. Morphisec describes it this way: “As an application loads to the memory space, Morphisec morphs the process structures, making the memory constantly unpredictable to attackers.”[1] Morphisec states that exploits and in-memory attacks “hit a target that is not where they expect and fail deterministically”.[2] It runs as a single lightweight agent on Windows, Windows ARM, macOS and Linux, alongside existing EDR.[2]
Side by side
| Dimension | Network-layer AMTD (PacketViper) | Endpoint memory MTD (Morphisec) |
|---|---|---|
| What moves | The network surface: addresses, ports, banners and service signatures that an attacker can scan and map. | Process structures and runtime memory on the host.[1] |
| Where it runs | In the network path, inline. | On the endpoint or server, as an agent. |
| Agent required | No for the network platform. An optional AMTD Agent covers Windows and Linux hosts. | Yes. A single lightweight agent.[2] |
| Typical threat addressed | Reconnaissance, scanning, lateral movement and probing of network services. | Exploits, fileless and in-memory attacks, and ransomware execution on the host. |
| Devices it can protect | Anything on the protected network segment, including OT and IoT devices that cannot host software. | Hosts that can run the agent (Windows, macOS, Linux). |
| OT / ICS | Native inline OT protocol support. Native, inline support for Modbus, DNP3, BACnet and S7COMM, with more than 20 OT protocols recognized. | Not publicly documented in the sources reviewed. |
When each fits
Network-layer AMTD fits when
Endpoint memory MTD fits when
Why they are complementary
An attacker has to find something, reach it and then run something. Network AMTD works on the first two steps: it makes the reconnaissance data unreliable and contains probes at first contact. Endpoint memory MTD works on the last: if code does run on a host, the memory it expects to exploit is not where it expects. A defense that covers only one of those steps leaves the others to other tools.
PacketViper also offers an AMTD Agent for Windows and Linux hosts. It applies PacketViper’s approach at the host’s network surface (rotating decoy services on free ports, with full attribution of anything that touches them), not in process memory, so it is a different mechanism from memory morphing.
Vendor-by-vendor detail: PacketViper vs Morphisec. For deception products that are not AMTD, see Network Deception Vendors: How to Choose.
Sources
- Morphisec, Automated Moving Target Defense Accessed 2026-10-09.
- Morphisec, home page Accessed 2026-10-09.
Network AMTD changes the surface a network exposes, such as addresses, ports and banners, and enforces in the network path. Endpoint MTD changes memory and runtime on a host, using an agent.
They protect different steps of an attack. Network AMTD works on reconnaissance and reaching targets, and endpoint MTD works on code execution on a host. Many environments benefit from both.
Endpoint MTD needs an agent on the device. PLCs, RTUs and similar devices generally cannot run one, which is why network-layer AMTD is used for them.
PacketViper’s core product is network-layer AMTD with inline enforcement. Its optional AMTD Agent works at a host’s network surface, not in process memory.
See network AMTD in your environment
Book a demonstration or request a proof of concept.
Explore further
The AMTD primer and the vendor comparisons.