Named by Gartner in “Coolest Vendor Innovations in Cyber-Physical Systems Security, 2026” (14 September 2026)

Resources

Threat intelligence, research, and everything you need to understand preemptive security.

All resources

Press Enter to search or Esc to close

Financial Services

Security that does not depend on who is on shift.

PacketViper is an agentless network layer control that enforces on the first hostile packet, rotates the surface attackers map, and does not require your people to notice anything.

15 Years
Thousands of installations and deployments
Zero
Breaches across the installed base
0 of 4
Runs where an autonomous AI attack agent reached a host, March 2026
The Problem

Your stack is built to notice. It is not built to stop.

Banks and large IT environments have spent a decade buying detection, training people, and staffing SOCs. Breaches still happen the same way: initial access, internal reconnaissance, lateral movement, then the alert that someone gets to after the damage.

Three reasons that does not change with the next tool.

Detection produces alerts

An alert is a request for a human to act. The time between the alert and the action is attacker time.

Firewalls stop the packet and forget the actor

The attacker keeps probing until they find the rule exception. Every rule base has one.

Training assumes the right call every time

The person on shift will not make it every time. That is not a training problem, it is a design problem.

“The firewall prevents the packet. It ignores the attempt. The attempt is the signal.”

Francesco Trama, Founder and CEO, PacketViper

Attackers are increasingly automated. An autonomous agent does not get tired, does not skip steps, and does not care that you have a SOC. It maps your network and moves. The question is whether your network is mappable.

Mechanism

Four things, all at the network layer, none of them waiting on a person.

Enforce on the first hostile packet

Every network has address space nothing legitimate lives in. In a typical /24, most of it. PacketViper knows which addresses are live from ARP and traffic. Anything that touches an address that should not exist is not a false positive candidate. It is reconnaissance. The source is enforced inline on that packet. No decoy interaction required, no analyst review, no ticket.

Rotate the surface the attacker is mapping

Automated Moving Target Defense changes the perceived network surface on a schedule. The map an attacker builds in the first hour is wrong in the second. Stale intelligence walks into a sensor. Rotation happens without touching your real assets and without a change request.

Act on the attempt, not just the packet

A blocked packet tells the attacker to try a different one. PacketViper treats the attempt as the event and closes the actor at the source or the session, so the second attempt does not happen.

Stay independent of the things that fail

No agent on the endpoint. No dependency on the SOC seeing an alert in time. No dependency on a vendor cloud being right. No dependency on the operator on shift. The control sits outside the hands of the people who make the mistakes.

Proof

Tested against the thing you are actually worried about.

AI agent containment, March 2026

An autonomous attack agent using AutoGen orchestration and a GPT-4o model was run against a PacketViper protected segment in four independent runs. In every run the agent was stopped at the first sensor it touched. Zero hosts reached. Read the containment results.

Deployment record

Thousands of installations and deployments over 15 years. No breach of a PacketViper protected segment in the installed base.

Published research

Denying the World Model: Automated Moving Target Defense as an Architectural Countermeasure to Autonomous AI Agents. DOI 10.5281/zenodo.21347479. All PacketViper preprints are collected on the research page.

The Platform

See it. Prove it. Keep it.

The control is the reason PacketViper exists. Everything else is there so you can see what it did, prove it to an examiner, and keep the record where you own it.

Asset context

Every device on the wire is learned, placed in a zone and location, and tracked over time. Inventory is a side effect of running the control, not a prerequisite. No discovery scan, no agent, no spreadsheet.

Live map

Flows by location, group, and device. Zoom sets the scope: country, WAN, site, LAN. Every node and every PacketViper is clickable to its traffic logs. Federated nodes across sites appear on one map. Nothing on the map is fabricated. Every placement traces to a real address or a real GeoIP hit.

Compliance mapping

30 frameworks and 692 controls mapped. The evidence behind each mapped control is an enforcement record.

Long term archiving

Scheduled export, hourly, daily, weekly, or an operator window, in OCSF 1.9.0, Parquet or NDJSON, to S3 compatible storage, a mounted volume or removable media, or on appliance staging. Resumable, chunked, tamper evident audit trail, and resource ceilings so export never competes with protection. Your data exports. PacketViper threat intel, licensed data, and defensive configuration never do.

Filtering and reach

DNS and application filtering at the same layer. Threat Reach shows which internal assets an external actor touched and which external actors an internal asset reached.

Analytics and federation

Built in analytics, SIEM ingest via OCSF 1.9.0 or syslog over TCP or TLS, and executive dashboards for board reporting. Multiple nodes across sites and regions under one view.

For IT and Network Operations

What it costs you to run. Almost nothing.

Agentless. Nothing installed on servers, workstations, or ATMs.
Inline on the wire. Deploys as a bridge in the path. No re-addressing, no VLAN redesign, no re-architecture.
No rule base to maintain. Live hosts are learned from ARP and traffic. Everything else is dark by definition. Your team does not write, review, or age out rules.
No change queue for rotation. Automated Moving Target Defense runs on its own schedule inside its own space. Your CAB never sees it.
Telemetry out in OCSF 1.9.0, or syslog over TCP or TLS on port 6514. Tools that read OCSF, including Amazon Security Lake, Splunk, and Snowflake, ingest the export without a custom parser.
Fails how you tell it to. Four modes: bypass when powered down, which is the default, disconnect when powered down, force bypass, and force disconnect. Hardware bypass NICs on the appliance line hold the selected mode through power loss. Software bypass does not, and the interface says so.

Sizing. Runs on the PV Edge i3, i5, and i7 DIN rail units, the PV150 and PV240 in 1U, and the PV350 in 2U. Also deploys as a virtual machine on VMware or Proxmox, and on bare metal.

For Compliance and Examiners

Maps to what your examiner asks about.

PacketViper is a control, not a certification. It supports your program and produces evidence for it.

Segmentation and lateral movement

Supports the network segmentation and lateral movement control objectives in the FFIEC IT Handbook, PCI DSS segmentation requirements, and the GLBA Safeguards Rule.

Detection and response timing

Provides evidence for the detection and response timing expectations in NYDFS Part 500 and the FFIEC Cybersecurity Assessment Tool domains.

Evidence of enforcement, not just logging

Every enforcement event is a record with source, target, and action. Examiners get proof a control acted, not proof a dashboard existed.

Independence from personnel

A control that does not depend on staff judgment is a stronger answer to the human factors line of questioning than another training completion report.

See the full compliance mapping.

Deployment

Where to put it first.

Between user segments and core banking or data center segments
In front of shared services such as AD, DNS, file, and print that every lateral movement path crosses
At branch to core boundaries
Around legacy and unpatchable systems, including mainframe adjacent hosts, older Windows servers, and appliances
In front of ATM and payment networks

Integration. OCSF export to your data lake or SIEM, syslog over TCP or TLS, and a REST API over HTTPS with API key authentication scoped to a source CIDR.

Coexistence. Works alongside your existing NGFW, EDR, and NDR. It is not a replacement for those. It is the layer that acts when they have not yet.

Straight Answers

What it does not do.

Off network attacks

It does not protect against an attacker who never touches the network, such as USB, physical console, or serial access.

Patching

It does not replace patching. Remediation is still necessary. It buys the time patching takes.

Your SIEM and SOC

It does not replace them. It reduces what they have to catch.

Human configuration

Allowlists and policy are still configured by humans. The design minimizes how much of that there is. It does not eliminate it.

Questions

Frequently asked

Does PacketViper require an agent on servers or ATMs?

No. PacketViper is agentless. It deploys inline on the wire as a bridge and installs nothing on servers, workstations, or ATMs.

How is this different from a next generation firewall?

A firewall stops the packet and forgets the actor, so the attacker keeps probing until they find a rule exception. PacketViper treats the attempt as the event and closes the actor at the source or the session. It also runs without a rule base, because live hosts are learned from ARP and traffic and everything else is dark by definition.

Does PacketViper make my institution compliant?

No product makes an institution compliant. PacketViper is a control that supports segmentation, lateral movement, and detection and response timing objectives, and produces an enforcement record as evidence for them.

What happened when PacketViper was tested against an autonomous AI attack agent?

In four independent runs in March 2026, an autonomous attack agent using AutoGen orchestration and a GPT-4o model was stopped at the first sensor it touched. Zero hosts were reached.

Next Step

Bring us your segment diagram.

A technical briefing walks your architecture, not a slide deck.