A network control your team does not have to babysit.
PacketViper is an agentless inline control that enforces on the first hostile packet, rotates the surface attackers map, and needs no rule base, no change queue, and no person watching a console.
What actually fails in real networks.
Nobody gets breached because a product lacked a feature. They get breached because of what happens to controls after deployment.
Firewall rule bases rot
Exceptions accumulate, nobody owns the old ones, and the attacker finds them before the audit does.
EDR needs an agent on every box
The box that matters is the one that cannot take one. The appliance, the old Windows server, the thing nobody will touch.
NDR gives your team another queue
An alert is a request for a human to act. The time between the alert and the action belongs to the attacker.
Training assumes the right call every time
The person on shift will not make it every time. That is a design problem, not a training problem.
“The firewall prevents the packet. It ignores the attempt. The attempt is the signal.”
Francesco Trama, Founder and CEO, PacketViper
Attackers now run the same play with autonomous tooling. It does not get tired, it does not skip steps, and it does not care that you have a SOC. It maps your network and moves. The question is whether your network is mappable.
Four things, all on the wire, none waiting on a person.
Enforce on the first hostile packet
Most of a typical enterprise /24 holds nothing. PacketViper learns which addresses are live from ARP and traffic, so the rest is dark by definition. A packet sent to an address that should not exist is not a scoring decision and not a false positive candidate. It is reconnaissance, and the source is enforced inline on that packet. No decoy interaction, no analyst review, no ticket.
Rotate the surface the attacker is mapping
Automated Moving Target Defense changes the perceived network surface on a schedule, so the map built in the first hour is wrong in the second. An attacker acting on stale intelligence walks into a sensor. Your real assets never move, and no change request is filed.
Act on the attempt, not just the packet
Dropping a packet only tells the attacker to send a different one. PacketViper treats the attempt itself as the event and closes the actor at the source or the session, which is why there is no second attempt to drop.
Stay independent of the things that fail
The control does not sit behind an endpoint agent, a SOC noticing an alert in time, a vendor cloud being correct, or the person on shift. Everything in that list fails eventually. The enforcement decision is outside all of them.
Tested against the thing you are actually worried about.
AI agent containment, March 2026
An autonomous attack agent using AutoGen orchestration and a GPT-4o model was run against a PacketViper protected segment across four independent runs. Every run ended at the first sensor the agent touched. Zero hosts reached. Read the containment results.
Deployment record
Thousands of installations and deployments over 15 years. No breach of a PacketViper protected segment.
Published research
Denying the World Model: Automated Moving Target Defense as an Architectural Countermeasure to Autonomous AI Agents. DOI 10.5281/zenodo.21347479. All PacketViper preprints are collected on the research page.
See it. Prove it. Keep it.
The control is why PacketViper exists. The rest is there so you can see what it did, prove it, and keep the record where you own it.
Asset context
Every device on the wire is learned, placed in a zone and location, and tracked over time. Inventory is a side effect of running the control, not a prerequisite. No discovery scan, no agent, no spreadsheet.
Live map
Flows by location, group, and device. Zoom sets the scope: country, WAN, site, LAN. Every node and every PacketViper is clickable to its traffic logs. Federated nodes across sites appear on one map. Nothing on the map is fabricated. Every placement traces to a real address or a real GeoIP hit.
Long term archiving
Scheduled export, hourly, daily, weekly, or an operator window, in OCSF 1.9.0, Parquet or NDJSON, to S3 compatible storage, a mounted volume or removable media, or on appliance staging. Resumable, chunked, tamper evident audit trail, and resource ceilings so export never competes with protection. Your data exports. PacketViper threat intel, licensed data, and defensive configuration never do.
Filtering and reach
DNS and application filtering at the same layer. Threat Reach shows which internal assets an external actor touched and which external actors an internal asset reached.
Analytics and federation
Built in analytics, SIEM ingest via OCSF 1.9.0 or syslog over TCP or TLS, and executive dashboards. Multiple nodes across sites and regions under one view.
Compliance mapping
30 frameworks and 692 controls mapped. The evidence behind each mapped control is an enforcement record. The financial services page carries the full compliance story.
Almost nothing. That is the point.
Sizing. Runs on the PV Edge i3, i5, and i7 DIN rail units, the PV150 and PV240 in 1U, and the PV350 in 2U. Also deploys as a virtual machine on VMware or Proxmox, and on bare metal.
Where to put it first.
Integration. OCSF export to your data lake or SIEM, syslog over TCP or TLS, and a REST API over HTTPS with API key authentication scoped to a source CIDR.
Coexistence. Works alongside your existing NGFW, EDR, and NDR. It is not a replacement for those. It is the layer that acts when they have not yet, and the record they ingest afterward.
What it does not do.
Off network attacks
It does not see an attacker who never touches the network, such as USB, physical console, or serial access.
Patching
It does not replace patching. Remediation is still necessary. It buys the time patching takes.
Your SIEM and SOC
It does not replace them. It reduces what they have to catch.
Human configuration
Allowlists for known cross segment flows are still configured by humans. The design keeps that surface small. It does not eliminate it.
Frequently asked
Nothing. PacketViper is agentless and deploys as an inline bridge between segments. It installs no software on servers, workstations, appliances, or any device that cannot take an agent.
No. PacketViper learns which addresses are live from ARP and traffic, and everything else is dark by definition. There is no rule base to write, review, or age out for address space where nothing exists.
It depends on the mode you select. There are four: bypass when powered down, which is the default, disconnect when powered down, force bypass, and force disconnect. Hardware bypass NICs on the appliance line hold the selected mode through power loss.
No. It runs alongside them. It is the layer that acts inline when those tools have not yet, and it produces an enforcement record they can ingest afterward.
Bring us your segment diagram.
A technical briefing runs against your architecture, not a slide deck.
Explore further
Related PacketViper capabilities and the research behind them.