One agent. Every device. Network visibility, endpoint protection, reputation grading, and fleet analytics — all from a single lightweight background process that uses less than 1% CPU.
Hover Packetman to hear the technical bit.
Every capability below started as a method our founding team used at the packet level to take a breach apart. We productized the methods — the features are what they look like shipped.
An agent is an endpoint — your computers, servers, and workstations. Your own admins manage every agent in the fleet, and you can be your own managed-service provider or hand the account to an MSSP later without re-deploying a thing.
For every connection, we resolve the full program path on disk — not just a process number. Malware tends to announce itself by its own filename, and the same method surfaces lateral movement by which executable fanned out, not just which device.
Every IP you reach — and every IP that tries to reach you — is scored through a 12-plus-stage pipeline. Every executable is graded against large known-good and known-bad corpora, per operating system. A grade, not a guess.
Most of the modern web now speaks QUIC on UDP port 443, and the kernel socket table doesn’t expose those remote endpoints — so most tools see none of it. We read it at the packet layer and pull the destination name per session.
The moment a process opens a connection to a known-bad destination, the OS drops the packet before it transmits. No proxy, no redirect, no middlebox — enforcement at the source.
91.108.4.182Not just "which IP" — the executable that opened the session, its full path on disk, its signer, and how many bytes moved each direction. This is the answer network engineers used to need a $20,000 analyzer for.
cdn.example.com, not 185.13.22.9, pulled from the OS resolver cache at flow timeEach grade is a verdict from a 12-stage investigation pipeline running from our own separate probing node — independent from what your agents see — so we can compare two perspectives on the same destination and flag inconsistencies.
IP reputation tells you which Microsoft IP your agent is talking to. Source of Authority Vetting tells you who actually controls the name that resolved to it — and during the SolarWinds breach, those two answers were "Microsoft Azure" and "a domain whose authoritative nameserver had been re-pointed to a Shadowserver sinkhole." One layer told the cover story. The other told the truth. We walk the DNS authority chain above every destination domain your fleet observes and flag four classes of mismatch — confirmed sinkholes, authority-versus-IP inconsistencies with name corroboration, hyperscaler-impersonating domains on cheap registrar NS, and suspicious zone admin contacts. The technique comes from our team's forensic analysis of the SolarWinds breach; we built the running version of it into the platform.
microsoft-update.com on Namecheap NS instead of Azure DNS is flagged independently; the name claim alone is a phishing signal even without IP corroborationWhere this came from. Source of Authority Vetting is the productized form of an analytical technique our team developed during packet-capture forensic analysis of the SolarWinds C2 channel. That work — part of a deep, multi-part SolarWinds breach analysis — is where the authority/IP attribution mismatch was first identified as a generalizable detection class. We carried the technique forward into the platform.
sunburst-ns-b.sinkhole.shadowserver.orgIssue a diagnostic command from the dashboard; it rides the next outbound heartbeat to the agent. The agent runs it locally and posts the result back. No remote shell, no elevated inbound access — just a controlled, logged, result-returning command channel.
Every TCP session your device runs gets a quality reading from the kernel. We roll thousands of those readings into one verdict per device, one per app, and a 24-hour timeline you can read at a glance. Then we rank your whole fleet so the slowest machines surface immediately.
Every 60 seconds: CPU, RAM, and disk. Every 24 hours: OS build, hardware, network interfaces, installed apps, USB devices, and your full security posture — all in the Host tab of any agent's detail page.
When you have 50 agents, each one is a data point. The fleet is a corpus. Patterns that are invisible on one machine become obvious when you can compare it to 49 others.
Threat detection wired directly into the agent's connection table. No separate scanner, no scan window, no "discovered on the next scheduled sweep."
node.exe · PID: 4812 · C:\apps\api\node.exeSound security assumes something eventually gets through. DataStun is built for that moment: the agent records what reaches the machine, not just what it sends — so an intrusion has a name, a source, and a timeline instead of a blank space.
When something gets onto one machine, it reaches out to your others — the path malware uses to spread. We tie every one of those connections to the executable that opened it, and we already know which programs are trusted — so a backup tool fanning out stays silent and an unknown program spreading shows up by name.
Not a chatbot you email. Not a help article you search. Not a ticket that waits until morning. Packetman is an expert who already knows your network — your fleet’s baseline, your alerts, the program behind every flow — and answers the moment something looks wrong. Every answer explains the why, so your team gets sharper while they use it.
Weekend at midnight, a new hire’s first hour, the moment an alert fires — Packetman answers. Nobody gets woken up, nothing queues until morning. Every enrolled device has an expert on call, always.
Click Help and Packetman already has that machine open — retransmission grade, blocked IPs, agent version. So the answer is “your retransmission rate is 8.4%, grade D — here’s the exact fix,” not a link to go read. Specific, every time.
“Why is this blocked?” — source, reason, dispute link. “What’s grade D?” — the cipher breakdown with evidence. “Slow internet?” — the 24-hour retransmit chart, cause named. Answered in the dashboard, in minutes — no admin interrupted.
When Packetman can’t close it, one click hands the whole thread — what was reported, what he tried, the live device context — to your admin’s dashboard inbox. Admins get email only for the critical stuff (grade-F, agent offline, exposed service). A break-glass email covers genuine lockouts — not routine questions.
Hover any Packetman head for a deep-dive on that feature. All tiers run the same agent binary — tier determines scale, retention, and advanced features only.
| Feature | Individual | Tribe | Business | Enterprise |
|---|---|---|---|---|
| Capacity & retention | ||||
| Agents | 3 | Up to 10 | 20+, no cap | Unlimited |
| History retention | 30 days | 30 days | 90 days | 365 days |
| Seats / team members | 1 | 3 | 10 | 25 |
| Endpoint protection | ||||
| Global blocklist enforcement | ✓ | ✓ | ✓ | ✓ |
| Threats-we-caught dashboard + IP lookup | ✓ | ✓ | ✓ | ✓ |
| Public threat intel feeds | ✓ | ✓ | ✓ | ✓ |
| Commercial-derived threat data | — | — | ✓ | ✓ |
| Tenant custom blocklist overrides | — | — | ✓ | ✓ |
| Exposed infrastructure detection | ✓ | ✓ | ✓ | ✓ |
| Server-grade protection | — | — | +$15/server/mo | ✓ |
| Network visibility | ||||
| Per-flow process & PID attribution | ✓ | ✓ | ✓ | ✓ |
| TCP kernel-level health (RTT, retransmission, MSS) | ✓ | ✓ | ✓ | ✓ |
| Performance verdict (Excellent / Good / Fair / Poor) | ✓ | ✓ | ✓ | ✓ |
| 24-hour connectivity quality timeline | ✓ | ✓ | ✓ | ✓ |
| Per-app performance grading | ✓ | ✓ | ✓ | ✓ |
| Fleet health page (ranked top/bottom 10) | ✓ | ✓ | ✓ | ✓ |
| QUIC / UDP/443 session visibility | ✓ | ✓ | ✓ | ✓ |
| DNS name correlation | ✓ | ✓ | ✓ | ✓ |
| Throughput per session and per port | ✓ | ✓ | ✓ | ✓ |
| Internet uptime probes | ✓ | ✓ | ✓ | ✓ |
| Destination reputation & grading | ||||
| A+ to F security grade | ✓ | ✓ | ✓ | ✓ |
| TLS / cert / cipher / SAN inspection | ✓ | ✓ | ✓ | ✓ |
| GeoIP + ASN + service classification | ✓ | ✓ | ✓ | ✓ |
| AI-assisted verdict | ✓ | ✓ | ✓ | ✓ |
| Multi-engine malware DB lookup | — | ✓ | ✓ | ✓ |
| Content-category classification | ✓ | ✓ | ✓ | ✓ |
| Fleet analytics & insights — Business and Enterprise | ||||
| AI Governance dashboard | — | — | ✓ | ✓ |
| Fleet SBOM (inventory + usage + data-flow) | — | — | ✓ | ✓ |
| First-seen radar | — | — | ✓ | ✓ |
| Per-machine deviation score | — | — | ✓ | ✓ |
| Patch-lag scoreboard | — | — | ✓ | ✓ |
| SaaS license reconciliation | — | — | ✓ | ✓ |
| Location-aware network health | — | — | ✓ | ✓ |
| Vendor concentration map | — | — | ✓ | ✓ |
| Org-wide executable analysis (outliers, LotL) | — | — | — | ✓ |
| Beaconing detector | — | — | — | ✓ |
| Data-sovereignty rollup | — | — | — | ✓ |
| Diagnostics & operations | ||||
| Remote diagnostic commands | — | ✓ | ✓ | ✓ |
| Live resource gauges (CPU, RAM, disk) | ✓ | ✓ | ✓ | ✓ |
| Host inventory snapshot | ✓ | ✓ | ✓ | ✓ |
| Hardware identity (manufacturer / model / SKU / serial / BIOS) | ✓ | ✓ | ✓ | ✓ |
| Storage / memory / CPU runtime / NIC PCIe link state | ✓ | ✓ | ✓ | ✓ |
| GPU / graphics adapter inventory | ✓ | ✓ | ✓ | ✓ |
| Security posture check | ✓ | ✓ | ✓ | ✓ |
| Power plan & sleep visibility | ✓ | ✓ | ✓ | ✓ |
| Alerts & SIEM export | — | — | ✓ | ✓ |
| In-app support (AI triage + human escalation) | AI only | AI + human | AI + human | AI + human priority |
| Identity & access | ||||
| SAML / OIDC SSO | — | — | — | ✓ |
| Per-tenant dashboard subdomain | — | — | ✓ | ✓ |
| Compliance reports (SOC 2, HIPAA) | — | — | — | ✓ |
Hover any Packetman head for a one-paragraph deep-dive. All tiers use the same agent binary; tiers gate scale, retention, and advanced features only.
Start on the Individual tier — up to 10 agents with 30 days of history. Every plan includes a generous 30-day trial; you’re not charged until it ends.