Skip to main content

Product · See & secure the network

When a Policy Deny Breaks Production, Know Which Process Caused It.

Network visibility for teams running Cilium on Kubernetes — see the exact process behind every connection, not just the pod. Every packet gets a process identity, so security and SRE teams can answer "why did this get denied" in seconds instead of a war room.

Download PM overview PDF

Process-to-network attribution15 intelligence modulesVisual web consoleCilium-native eBPFAutoPolicy learningAsk Zyra copilotSecures our own internal network

PacketWolf · live flows · silent loop preview

Want a walkthrough first? Schedule a demo

How it works

From kernel event to enforced policy

1

Read the kernel, not just Hubble

NetPredator reads /proc and Cilium conntrack, policy, and drop maps directly — attributing every socket to a PID and process name, no sidecar probes.

2

Correlate flows and policy in real time

A fast internal messaging layer instantly connects every signal — Hubble flows, DNS lookups, TCP resets, and Cilium policy denies — into one live map of how your services actually talk to each other.

3

Explain the incident in one query

`netpred explain <service>` — or Ask Zyra — turns kernel connections and policy denies into a plain-English root cause.

4

Learn a least-privilege baseline

AutoPolicy scores observed traffic on seven features and proposes FlowPolicy CRDs ranked by confidence.

5

Simulate, then enforce safely

Simulator and Chaos validate the blast radius before rollout; Canary ships with automatic rollback on error budgets.

See it on a live namespace.

`netpred policy simulate` walks a real namespace end to end — flow capture, unattributed egress, and a drafted CiliumNetworkPolicy — before anything is enforced.

Read the PacketWolf docs

Why it exists

PacketWolf

Kernel-native network intelligence for Kubernetes. When a policy deny breaks production, security teams can't say which process made the call or why — they can only see that traffic stopped. PacketWolf gives every packet a process identity, so "why did this get denied" has an answer in seconds.

Feature pillars

What you get

Process attribution

Every connection is traced back to the exact process and container that made it, not just the pod — the fastest way to answer "who did this."

AutoPolicy

Watches real traffic and automatically writes tightly-scoped Cilium security policies for you — no manual YAML.

15 intelligence modules

Healer, RootCause, Simulator, Replay, Chaos, Canary, and more — each one automating a piece of network operations your team currently does by hand.

Console that fits how you work

Browser, terminal, or automation pipeline — same network intelligence, without bolting on another ops stack.

Differentiators

Built for production

Observe — network anchor for migration waves and KubeVirt day-2.

Why teams choose us

  • Reads network activity straight from the Linux kernel via Cilium — no performance-sapping sidecar probes to deploy alongside every pod
  • Works embedded inside the Zeus OS network center, or standalone as its own console — your choice
  • Optional deeper packet-level inspection (NetPredator) for teams that want kernel-level detail beyond the default view

When to choose

  • You run Cilium as your Kubernetes networking layer and need to see exactly which process made each connection
  • You want security policy generated from real traffic patterns, not hand-written spreadsheets and guesswork
  • You want to start free — Paqtra is the open-source community edition on the same Cilium-native foundation
FAQ

PacketWolf questions

How it flows

How it works

Migrate from the platforms you already run

  • Enterprise Hypervisors
  • HCI Platforms
  • AWS
  • Azure
  • Google Cloud
  • Windows Hypervisor
  • Oracle Cloud
  • Machina fleet cloud
  • KubeVirt
  • KVM
  • KVM-based Platforms
SOC2-ready postureRBAC + audit logging99.9% SLA targetAir-gap programs

Live lab captures — internet kill switch, firewall rules, pulse, flows, threats, and war room. See more on YouTube

Why PacketWolf

Pods are not enough

Hubble shows pod-to-pod flows. PacketWolf shows the process, socket, and policy story behind every connection.

Process-to-network attribution

Every active connection is mapped to the exact process and container that opened it — the detail SRE and security investigations usually have to guess at.

God Mode explain

`netpred explain <service>` stitches kernel connections, DNS, policy denies, and drops into one actionable narrative.

Graph engine

A live map of how every service in your cluster depends on every other, kept current from Hubble in real time — so tracing the shortest path between two services, or the blast radius of an outage, is a query, not a war room.

Cross-layer correlation

Automatically link TCP resets, Cilium denies, and policy CRDs — root cause in seconds, not war rooms.

Full netpred CLI and God Mode explain reference in the docs

Architecture

Three layers, one nervous system

Kernel intelligence, the NetPredator operator, and all fifteen automation modules share one real-time messaging and mapping layer — so the moment something happens anywhere in the cluster, every module knows and can react instantly.

Intelligence

Fifteen modules on one platform

Each module is production-oriented — not a demo checkbox.

AutoPolicyHealerRootCauseSimulatorReplayChaosCanaryMultiClusterPacketExplainerAnomalyDetectioneBPF AdvancedSecurity & ComplianceDevToolsOptimizerProfiler

Dashboard

One console for flows, policy, and response

One web console covering security, observability, intelligence, and live eBPF map viewers.

Overview

Dashboard, events, nodes, endpoints, cluster health, Cilium status

Observability

Flows, topology, service map, SLOs, DNS, latency, heatmaps

Security

VM/Pod Guard (internet kill switch), Policy Editor + Visual Apply, anomalies, RBAC, audit, incidents

Intelligence

Kernel intel, graph explorer, AutoPolicy, healer, root cause

Operations

Chaos, canary, replay, multi-cluster, BGP, node drain

eBPF data

Live conntrack, policy map, ipcache, LB map, drop analytics

Networking

Ingress, egress GW, service mesh, IPAM, cost analytics

Policy lifecycle

From observation to enforcement

AutoPolicy learns traffic, Simulator validates rules, Chaos proves resilience, Canary rolls out safely.

Observe & learn

  • Hubble flows + kernel attribution in one timeline
  • Behavioral fingerprints and anomaly detection per workload
  • Service map, topology, and SLO views for platform owners

Enforce & prove

  • AutoPolicy → FlowPolicy CRDs → Cilium enforcement
  • Replay historical traffic before policy changes land
  • Chaos inject latency/loss; Canary rollback on error budgets

Interfaces

Browser, terminal, and API parity

Visual web dashboard

Visual policy builder, incident mode, kernel intel page, graph explorer, and live eBPF map viewers.

Keyboard-first TUI

Keyboard-first netpred for bastion and air-gapped environments — same data plane as the web UI.

Automation-ready REST API

Automate policy, flows, chaos, and graph export — integrate with SOAR, ticketing, and GitOps pipelines.

Cilium native

Built on the stack you already run

Cilium CNI 1.14+

Reads conntrack, policy, LB, ipcache, and drop maps directly — no sidecar probe tax.

Hubble streaming

Live flow feed correlated to process-level kernel events for unified triage.

Prometheus & Grafana

Metrics exporter and dashboards for policy compliance and network health KPIs.

Ask Zyra

A network copilot that reasons over your cluster

Natural-language questions answered from live telemetry — with an agentic mode that calls read-only tools, shows its work, and fails open to a deterministic rule router.

Three engine modes

Rule router (deterministic keyword engine, no LLM needed), Hybrid (rule + LLM narrative), and Agent (the LLM selects read-only tools and synthesizes an answer with a full agent_trace). Every reply carries an Agent / Hybrid / Rule badge.

Tool-calling over your telemetry

Agent mode picks from 58 read-only tools — process lens, threat threads, attack graph, risk graph, DNS wolf, drop decoder, policy recommendation — inside a bounded loop with a per-answer tool and time budget.

Gated write tools

With write tools enabled, Zyra can propose actions — submit a policy for approval, run a playbook, preview a healer apply — but every cluster change needs explicit UI confirmation first.

Fails open, never blocks

On LLM timeout or failure, Zyra automatically falls back to the deterministic rule router, so an answer always comes back — the console never depends on an external model to stay useful.

Part of Zyra — see the same AI persona across the whole suite →

Full Ask Zyra network copilot API reference in the docs

Rule mode — no LLMHybrid narrativeAgentic tool-callingBounded tool budgetConfirmation-gated writes

Security posture

Detection, forensics, and compliance — not just flows

PacketWolf turns kernel and Hubble telemetry into attack stories, risk scores, and audit-ready evidence.

ThreatThread + AttackGraph

Correlated alerts become multi-stage attack narratives; unified attack paths link risky workloads to topology edges so you see lateral-movement routes, not isolated events.

RiskGraph + KubePosture

Per-workload and per-namespace risk scores, plus a segmentation score that surfaces default-deny gaps and workloads with unrestricted world egress.

One-click quarantine

Preview then apply admin-gated workload isolation — generate the CiliumNetworkPolicy that fences off a compromised pod, with a diff before anything lands.

ForensicPack + GeoThreat

Export an incident-response evidence bundle formatted as CEF (Common Event Format — a standard log format your SIEM, the security log system your ops team already uses, can read directly); enrich outbound traffic with ASN (which network or ISP owns that IP address), country, and reputation data (optional MaxMind, a widely used IP-geolocation database, plus threat-intel feeds).

ComplianceLens

Map live network posture to SOC2, PCI-DSS 4.0, HIPAA, and Zero Trust controls — continuous evidence instead of a point-in-time audit.

DNSWolf + RuntimeGuard

Per-workload DNS volume, failures, resolvers, and tunneling signals; runtime exec events correlated to flows with ThreatSense runtime alerts.

SOC2PCI-DSS 4.0HIPAAZero TrustCEF / SIEM export

Policy intelligence

Every suggestion is scored, explained, and simulated

AutoPolicy doesn't just emit YAML — it ranks each rule with a weighted ML confidence score and grades your posture against least privilege.

7-feature confidence score

Each learned rule is scored on temporal stability, traffic volume, port trust, protocol, namespace trust, label specificity, and traffic regularity — weighted so stable, high-volume flows rank highest.

Least-privilege scorecard

POST a policy to /policies/score for a least-privilege grade, or /policies/explain for a plain-English summary of exactly what a CiliumNetworkPolicy allows and denies.

Observe → simulate → approve

AutoPolicy Pilot and Zero-Trust Pilot forge a policy from natural language or observed traffic, simulate its blast radius, and hold it for approval before it enforces.

Container & workload consoles

Reach inside any workload from the browser

A Kubernetes pod, a KubeVirt VM, or a plain podman/docker container — inspect, expose, and contain it from one console.

In-browser shell — pods, VMs, containers

A PTY-bridged shell into any running pod, KubeVirt VM, or standalone podman/docker container, straight from the UI — no separate exec incantation per workload type.

VM serial console & VNC

Reach a KubeVirt VM's serial console or graphical VNC framebuffer in-browser, proxied through the VMI console/vnc subresources — recover a stuck boot with no external console tooling.

Non-Kubernetes container visibility

A lightweight node agent surfaces podman, docker, and standalone containerd containers as first-class workloads alongside k8s pods and VMs.

Expose and revoke ports on demand

Publish a workload port for SSH/RDP or generic TCP/UDP access, then tear it down cleanly — a NodePort for pods/VMs, an agent-run proxy for non-k8s containers.

One-click Guard: lock, quarantine, release

Graduated lockdown per workload — block internet, DNS, or web egress, full isolation, or release — enforced via CiliumNetworkPolicy for pods/VMs and nftables for standalone containers.

Multi-replica ready

Shell, expose, and enforce keep working when the API runs multiple replicas — a pub/sub bus routes each operation to whichever pod holds the workload's live connection.

Kubernetes podsKubeVirt VMsPodman / DockerIn-browser shellVNC console
Suite flagship

The suite flagship for network intelligence

Process-to-network attribution: see which process inside which container made which call — and why it failed.

AutoPolicy

Learn east-west baselines; emit least-privilege Cilium policies automatically.

Healer

Autonomous network remediation playbooks tied to live cluster state.

RootCause

Correlate kernel resets, policy denies, and Hubble drops into one narrative.

Simulator

Model policy impact before enforcement hits production traffic.

Replay

Time-travel historical flows for post-incident review and change validation.

Chaos

Inject latency, loss, and partition faults to prove resilience.

Canary

Roll policies gradually with automated rollback on error budgets.

MultiCluster

Single pane for observability and policy across fleets.

PacketExplainer

Natural-language explanations of complex flow failures (God Mode).

AnomalyDetection

Behavioral fingerprints per workload; alert on drift.

eBPF Advanced

Optional NetPredator BPF phases for TCP, DNS, drops, and anomalies.

Security & Compliance

Audit trails, encryption posture, RBAC, and compliance views.

DevTools

Capture, mirroring, and engineer-oriented flow export.

Optimizer

Bandwidth and path recommendations from live topology.

Profiler

Deep performance profiling hooks on hot services.

Kernel intelligence

Ten kernel modules, one correlation engine

Cilium-first eBPF datapath — no probe injection required for baseline visibility.

Process resolver

PID to pod/container identity

TCP lifecycle tracking and connection tables

TCP lifecycle tracking and connection tables

DNS intelligence with PID attribution

DNS intelligence with PID attribution

Behavioral fingerprinting (CPU, I/O, memory ratios)

Behavioral fingerprinting (CPU, I/O, memory ratios)

Cilium map reads

conntrack, policy, LB, ipcache, drops

Hubble flow streaming correlated to processes

Hubble flow streaming correlated to processes

Operator & interfaces

NetPredator control plane + netpred CLI

Native Kubernetes controllers

  • FlowPolicy · TrafficInsight · AutoPolicy · TraceSession · KernelInsight
  • Reconciles into Cilium policies, graph metrics, and kernel scan results
  • 4 WebSocket streams for live dashboard and automation consumers

CLI & dashboard

  • netpred — 18-tab TUI for live operations
  • netpred explain <service> — God Mode cross-layer debug
  • netpred kernel connections | dns | fingerprints
  • netpred policy suggest | apply — FlowPolicy CRDs
  • Operator console for flows, policy, and war-room response

30-Day Free Trial

Install in 30 seconds — no sign-up required

One Helm command. Trial starts automatically. No key, no account, no credit card.

Step 1 — Install

helm
helm install packetwolf ./charts/packetwolf \
  --namespace packetwolf-system \
  --create-namespace

Step 2 — Verify pods are running

kubectl
kubectl rollout status deployment/packetwolf-api \
  -n packetwolf-system --timeout=120s

kubectl get pods -n packetwolf-system
# NAME                              READY   STATUS    AGE
# packetwolf-api-xxxx               1/1     Running   30s
# packetwolf-traffic-client-xxxx    1/1     Running   30s
# packetwolf-traffic-echo-xxxx      1/1     Running   30s

Step 3 — Access the dashboard

port-forward
kubectl port-forward svc/packetwolf-api \
  -n packetwolf-system 9191:9191

# Open: http://localhost:9191

# Retrieve the auto-generated admin API key:
kubectl get secret packetwolf-secret -n packetwolf-system \
  -o jsonpath='{.data.PACKETWOLF_ADMIN_API_KEY}' | base64 -d && echo

Step 4 — Confirm trial is active

logs
kubectl logs -n packetwolf-system deployment/packetwolf-api \
  | grep -i 'trial\|licence'
# → PacketWolf trial licence: Trial — valid until YYYY-MM-DD

Step 5 — Apply a licence key (after trial)

helm upgrade
kubectl create secret generic packetwolf-license \
  --from-literal=license.key="<your-key>" \
  -n packetwolf-system

helm upgrade packetwolf ./charts/packetwolf \
  --reuse-values \
  --set license.existingSecret="packetwolf-license" \
  -n packetwolf-system

30-day full access, zero friction

All 15 modules: AutoPolicy, Healer, RootCause, Chaos, Canary, KernelIntel, MultiCluster, PacketExplainer, and more. Full 85-route dashboard + TUI — from the first helm install.

Single Helm chart

One Helm install deploys the operator and dashboard on your Cilium cluster. CRDs ship with the chart.

Automatic trial clock

Build date is baked into the binary. Trial runs for 30 days from image release. No activation step required.

After the trial

Contact [email protected] for a licence key. Apply it via a Kubernetes Secret — no reinstall needed.

Cilium 1.14+Kubernetes 1.28+Hubble enabledHelm 3.8+No account needed
Start here

PM & stakeholder path

Product overview and reference collateral for PacketWolf evaluations.

  1. Product overview (PM guide)
  2. Complete client guide
  3. Executive summary
  4. Architecture diagram
Resources

Signature deck

Download the h2kvm-format PDF or open the HTML preview for stakeholder reviews.

Overview

A4 portrait · purple cover · orange accent (h2kvm style)

Browse all 8 PacketWolf decks

Free trial

30-day free trial, no sign-up — PacketWolf

Network visibility for Cilium on Kubernetes — process identity behind every connection.

  • All 15 modules and the full dashboard + TUI from the first Helm install
  • Trial runs for 30 days from image release — no key, no account, no credit card
  • Licence key from [email protected] after the trial, applied via a Kubernetes Secret

After the trial window, it is completely up to you whether to continue. There is absolutely no pressure or obligation from our side.

See PacketWolf on your cluster

Walk through process attribution on a live namespace, then compare AutoPolicy output to your hand-written Cilium rules.