Want a walkthrough first? Schedule a demo →
How it works
From kernel event to enforced policy
Read the kernel, not just Hubble
NetPredator reads /proc and Cilium conntrack, policy, and drop maps directly — attributing every socket to a PID and process name, no sidecar probes.
Correlate flows and policy in real time
A fast internal messaging layer instantly connects every signal — Hubble flows, DNS lookups, TCP resets, and Cilium policy denies — into one live map of how your services actually talk to each other.
Explain the incident in one query
`netpred explain <service>` — or Ask Zyra — turns kernel connections and policy denies into a plain-English root cause.
Learn a least-privilege baseline
AutoPolicy scores observed traffic on seven features and proposes FlowPolicy CRDs ranked by confidence.
Simulate, then enforce safely
Simulator and Chaos validate the blast radius before rollout; Canary ships with automatic rollback on error budgets.
See it on a live namespace.
`netpred policy simulate` walks a real namespace end to end — flow capture, unattributed egress, and a drafted CiliumNetworkPolicy — before anything is enforced.
PacketWolf
Kernel-native network intelligence for Kubernetes. When a policy deny breaks production, security teams can't say which process made the call or why — they can only see that traffic stopped. PacketWolf gives every packet a process identity, so "why did this get denied" has an answer in seconds.
What you get
Process attribution
Every connection is traced back to the exact process and container that made it, not just the pod — the fastest way to answer "who did this."
AutoPolicy
Watches real traffic and automatically writes tightly-scoped Cilium security policies for you — no manual YAML.
15 intelligence modules
Healer, RootCause, Simulator, Replay, Chaos, Canary, and more — each one automating a piece of network operations your team currently does by hand.
Console that fits how you work
Browser, terminal, or automation pipeline — same network intelligence, without bolting on another ops stack.
Built for production
Observe — network anchor for migration waves and KubeVirt day-2.
Why teams choose us
- Reads network activity straight from the Linux kernel via Cilium — no performance-sapping sidecar probes to deploy alongside every pod
- Works embedded inside the Zeus OS network center, or standalone as its own console — your choice
- Optional deeper packet-level inspection (NetPredator) for teams that want kernel-level detail beyond the default view
When to choose
- You run Cilium as your Kubernetes networking layer and need to see exactly which process made each connection
- You want security policy generated from real traffic patterns, not hand-written spreadsheets and guesswork
- You want to start free — Paqtra is the open-source community edition on the same Cilium-native foundation
PacketWolf questions
How it works
Migrate from the platforms you already run
- Enterprise Hypervisors
- HCI Platforms
- AWS
- Azure
- Google Cloud
- Windows Hypervisor
- Oracle Cloud
- Machina fleet cloud
- KubeVirt
- KVM
- KVM-based Platforms
Live lab captures — internet kill switch, firewall rules, pulse, flows, threats, and war room. See more on YouTube →
Why PacketWolf
Pods are not enough
Hubble shows pod-to-pod flows. PacketWolf shows the process, socket, and policy story behind every connection.
Process-to-network attribution
Every active connection is mapped to the exact process and container that opened it — the detail SRE and security investigations usually have to guess at.
God Mode explain
`netpred explain <service>` stitches kernel connections, DNS, policy denies, and drops into one actionable narrative.
Graph engine
A live map of how every service in your cluster depends on every other, kept current from Hubble in real time — so tracing the shortest path between two services, or the blast radius of an outage, is a query, not a war room.
Cross-layer correlation
Automatically link TCP resets, Cilium denies, and policy CRDs — root cause in seconds, not war rooms.
Full netpred CLI and God Mode explain reference in the docs →
Architecture
Three layers, one nervous system
Kernel intelligence, the NetPredator operator, and all fifteen automation modules share one real-time messaging and mapping layer — so the moment something happens anywhere in the cluster, every module knows and can react instantly.
- CLI netpred
- TUI
- Web console
- REST API
- 10 WebSockets
- FlowPolicy · AutoPolicy · …
- /proc + Cilium maps + optional eBPF
- Event bus
- Graph engine
- Policy translator
- AutoPolicy
- Healer
- RootCause
- Chaos
- Canary
- …
Intelligence
Fifteen modules on one platform
Each module is production-oriented — not a demo checkbox.
Dashboard
One console for flows, policy, and response
One web console covering security, observability, intelligence, and live eBPF map viewers.
Overview
Dashboard, events, nodes, endpoints, cluster health, Cilium status
Observability
Flows, topology, service map, SLOs, DNS, latency, heatmaps
Security
VM/Pod Guard (internet kill switch), Policy Editor + Visual Apply, anomalies, RBAC, audit, incidents
Intelligence
Kernel intel, graph explorer, AutoPolicy, healer, root cause
Operations
Chaos, canary, replay, multi-cluster, BGP, node drain
eBPF data
Live conntrack, policy map, ipcache, LB map, drop analytics
Networking
Ingress, egress GW, service mesh, IPAM, cost analytics
Policy lifecycle
From observation to enforcement
AutoPolicy learns traffic, Simulator validates rules, Chaos proves resilience, Canary rolls out safely.
Observe & learn
- Hubble flows + kernel attribution in one timeline
- Behavioral fingerprints and anomaly detection per workload
- Service map, topology, and SLO views for platform owners
Enforce & prove
- AutoPolicy → FlowPolicy CRDs → Cilium enforcement
- Replay historical traffic before policy changes land
- Chaos inject latency/loss; Canary rollback on error budgets
Interfaces
Browser, terminal, and API parity
Visual web dashboard
Visual policy builder, incident mode, kernel intel page, graph explorer, and live eBPF map viewers.
Keyboard-first TUI
Keyboard-first netpred for bastion and air-gapped environments — same data plane as the web UI.
Automation-ready REST API
Automate policy, flows, chaos, and graph export — integrate with SOAR, ticketing, and GitOps pipelines.
Cilium native
Built on the stack you already run
Cilium CNI 1.14+
Reads conntrack, policy, LB, ipcache, and drop maps directly — no sidecar probe tax.
Hubble streaming
Live flow feed correlated to process-level kernel events for unified triage.
Prometheus & Grafana
Metrics exporter and dashboards for policy compliance and network health KPIs.
Ask Zyra
A network copilot that reasons over your cluster
Natural-language questions answered from live telemetry — with an agentic mode that calls read-only tools, shows its work, and fails open to a deterministic rule router.
Three engine modes
Rule router (deterministic keyword engine, no LLM needed), Hybrid (rule + LLM narrative), and Agent (the LLM selects read-only tools and synthesizes an answer with a full agent_trace). Every reply carries an Agent / Hybrid / Rule badge.
Tool-calling over your telemetry
Agent mode picks from 58 read-only tools — process lens, threat threads, attack graph, risk graph, DNS wolf, drop decoder, policy recommendation — inside a bounded loop with a per-answer tool and time budget.
Gated write tools
With write tools enabled, Zyra can propose actions — submit a policy for approval, run a playbook, preview a healer apply — but every cluster change needs explicit UI confirmation first.
Fails open, never blocks
On LLM timeout or failure, Zyra automatically falls back to the deterministic rule router, so an answer always comes back — the console never depends on an external model to stay useful.
Full Ask Zyra network copilot API reference in the docs →
Security posture
Detection, forensics, and compliance — not just flows
PacketWolf turns kernel and Hubble telemetry into attack stories, risk scores, and audit-ready evidence.
ThreatThread + AttackGraph
Correlated alerts become multi-stage attack narratives; unified attack paths link risky workloads to topology edges so you see lateral-movement routes, not isolated events.
RiskGraph + KubePosture
Per-workload and per-namespace risk scores, plus a segmentation score that surfaces default-deny gaps and workloads with unrestricted world egress.
One-click quarantine
Preview then apply admin-gated workload isolation — generate the CiliumNetworkPolicy that fences off a compromised pod, with a diff before anything lands.
ForensicPack + GeoThreat
Export an incident-response evidence bundle formatted as CEF (Common Event Format — a standard log format your SIEM, the security log system your ops team already uses, can read directly); enrich outbound traffic with ASN (which network or ISP owns that IP address), country, and reputation data (optional MaxMind, a widely used IP-geolocation database, plus threat-intel feeds).
ComplianceLens
Map live network posture to SOC2, PCI-DSS 4.0, HIPAA, and Zero Trust controls — continuous evidence instead of a point-in-time audit.
DNSWolf + RuntimeGuard
Per-workload DNS volume, failures, resolvers, and tunneling signals; runtime exec events correlated to flows with ThreatSense runtime alerts.
Policy intelligence
Every suggestion is scored, explained, and simulated
AutoPolicy doesn't just emit YAML — it ranks each rule with a weighted ML confidence score and grades your posture against least privilege.
7-feature confidence score
Each learned rule is scored on temporal stability, traffic volume, port trust, protocol, namespace trust, label specificity, and traffic regularity — weighted so stable, high-volume flows rank highest.
Least-privilege scorecard
POST a policy to /policies/score for a least-privilege grade, or /policies/explain for a plain-English summary of exactly what a CiliumNetworkPolicy allows and denies.
Observe → simulate → approve
AutoPolicy Pilot and Zero-Trust Pilot forge a policy from natural language or observed traffic, simulate its blast radius, and hold it for approval before it enforces.
Container & workload consoles
Reach inside any workload from the browser
A Kubernetes pod, a KubeVirt VM, or a plain podman/docker container — inspect, expose, and contain it from one console.
In-browser shell — pods, VMs, containers
A PTY-bridged shell into any running pod, KubeVirt VM, or standalone podman/docker container, straight from the UI — no separate exec incantation per workload type.
VM serial console & VNC
Reach a KubeVirt VM's serial console or graphical VNC framebuffer in-browser, proxied through the VMI console/vnc subresources — recover a stuck boot with no external console tooling.
Non-Kubernetes container visibility
A lightweight node agent surfaces podman, docker, and standalone containerd containers as first-class workloads alongside k8s pods and VMs.
Expose and revoke ports on demand
Publish a workload port for SSH/RDP or generic TCP/UDP access, then tear it down cleanly — a NodePort for pods/VMs, an agent-run proxy for non-k8s containers.
One-click Guard: lock, quarantine, release
Graduated lockdown per workload — block internet, DNS, or web egress, full isolation, or release — enforced via CiliumNetworkPolicy for pods/VMs and nftables for standalone containers.
Multi-replica ready
Shell, expose, and enforce keep working when the API runs multiple replicas — a pub/sub bus routes each operation to whichever pod holds the workload's live connection.
The suite flagship for network intelligence
Process-to-network attribution: see which process inside which container made which call — and why it failed.
AutoPolicy
Learn east-west baselines; emit least-privilege Cilium policies automatically.
Healer
Autonomous network remediation playbooks tied to live cluster state.
RootCause
Correlate kernel resets, policy denies, and Hubble drops into one narrative.
Simulator
Model policy impact before enforcement hits production traffic.
Replay
Time-travel historical flows for post-incident review and change validation.
Chaos
Inject latency, loss, and partition faults to prove resilience.
Canary
Roll policies gradually with automated rollback on error budgets.
MultiCluster
Single pane for observability and policy across fleets.
PacketExplainer
Natural-language explanations of complex flow failures (God Mode).
AnomalyDetection
Behavioral fingerprints per workload; alert on drift.
eBPF Advanced
Optional NetPredator BPF phases for TCP, DNS, drops, and anomalies.
Security & Compliance
Audit trails, encryption posture, RBAC, and compliance views.
DevTools
Capture, mirroring, and engineer-oriented flow export.
Optimizer
Bandwidth and path recommendations from live topology.
Profiler
Deep performance profiling hooks on hot services.
Ten kernel modules, one correlation engine
Cilium-first eBPF datapath — no probe injection required for baseline visibility.
Process resolver
PID to pod/container identity
TCP lifecycle tracking and connection tables
TCP lifecycle tracking and connection tables
DNS intelligence with PID attribution
DNS intelligence with PID attribution
Behavioral fingerprinting (CPU, I/O, memory ratios)
Behavioral fingerprinting (CPU, I/O, memory ratios)
Cilium map reads
conntrack, policy, LB, ipcache, drops
Hubble flow streaming correlated to processes
Hubble flow streaming correlated to processes
NetPredator control plane + netpred CLI
Native Kubernetes controllers
- FlowPolicy · TrafficInsight · AutoPolicy · TraceSession · KernelInsight
- Reconciles into Cilium policies, graph metrics, and kernel scan results
- 4 WebSocket streams for live dashboard and automation consumers
CLI & dashboard
- netpred — 18-tab TUI for live operations
- netpred explain <service> — God Mode cross-layer debug
- netpred kernel connections | dns | fingerprints
- netpred policy suggest | apply — FlowPolicy CRDs
- Operator console for flows, policy, and war-room response
30-Day Free Trial
Install in 30 seconds — no sign-up required
One Helm command. Trial starts automatically. No key, no account, no credit card.
Step 1 — Install
helm install packetwolf ./charts/packetwolf \ --namespace packetwolf-system \ --create-namespace
Step 2 — Verify pods are running
kubectl rollout status deployment/packetwolf-api \ -n packetwolf-system --timeout=120s kubectl get pods -n packetwolf-system # NAME READY STATUS AGE # packetwolf-api-xxxx 1/1 Running 30s # packetwolf-traffic-client-xxxx 1/1 Running 30s # packetwolf-traffic-echo-xxxx 1/1 Running 30s
Step 3 — Access the dashboard
kubectl port-forward svc/packetwolf-api \
-n packetwolf-system 9191:9191
# Open: http://localhost:9191
# Retrieve the auto-generated admin API key:
kubectl get secret packetwolf-secret -n packetwolf-system \
-o jsonpath='{.data.PACKETWOLF_ADMIN_API_KEY}' | base64 -d && echoStep 4 — Confirm trial is active
kubectl logs -n packetwolf-system deployment/packetwolf-api \ | grep -i 'trial\|licence' # → PacketWolf trial licence: Trial — valid until YYYY-MM-DD
Step 5 — Apply a licence key (after trial)
kubectl create secret generic packetwolf-license \ --from-literal=license.key="<your-key>" \ -n packetwolf-system helm upgrade packetwolf ./charts/packetwolf \ --reuse-values \ --set license.existingSecret="packetwolf-license" \ -n packetwolf-system
30-day full access, zero friction
All 15 modules: AutoPolicy, Healer, RootCause, Chaos, Canary, KernelIntel, MultiCluster, PacketExplainer, and more. Full 85-route dashboard + TUI — from the first helm install.
Single Helm chart
One Helm install deploys the operator and dashboard on your Cilium cluster. CRDs ship with the chart.
Automatic trial clock
Build date is baked into the binary. Trial runs for 30 days from image release. No activation step required.
After the trial
Contact [email protected] for a licence key. Apply it via a Kubernetes Secret — no reinstall needed.
PM & stakeholder path
Product overview and reference collateral for PacketWolf evaluations.
Signature deck
Download the h2kvm-format PDF or open the HTML preview for stakeholder reviews.
Free trial
30-day free trial, no sign-up — PacketWolf
Network visibility for Cilium on Kubernetes — process identity behind every connection.
- All 15 modules and the full dashboard + TUI from the first Helm install
- Trial runs for 30 days from image release — no key, no account, no credit card
- Licence key from [email protected] after the trial, applied via a Kubernetes Secret
After the trial window, it is completely up to you whether to continue. There is absolutely no pressure or obligation from our side.
PacketWolf · Observe
See PacketWolf on your cluster
Walk through process attribution on a live namespace, then compare AutoPolicy output to your hand-written Cilium rules.