Platform · Policy & Micro-Segmentation

Segment on understanding, not on guesswork.

WireTrace provides the intelligence, policy intent and continuous validation layer, while integrated network and security platforms execute enforcement.

WireTraceintelligence · intentvalidationMAPwho talks to whomBASELINEapprove normalPROPOSEsegmentation intentVALIDATEtest against trafficENFORCEvia your controlsMONITORviolations · driftENFORCEMENT STAYS WITH YOUR FIREWALL, NAC AND NETWORK TEAMS
1 · Why segmentation fails

Rules written without knowing the traffic.

Most segmentation projects stall for the same reason: nobody can say with confidence which devices exist, what they are, and which conversations the process actually depends on. Rules written from diagrams break production, so they get loosened until they protect nothing.

2 · Start with understanding

Identity and dependencies first.

WireTrace identifies and classifies each device, then maps observed communication between devices, groups and zones, by protocol and port. Segmentation decisions are made about known devices, not addresses.

EVIDENCE OBSERVEDDevice-stated identity recordDHCP options · hostnameSNMP system descriptionTLS certificate · SSH host keyLLDP / CDP neighbourProtocol behaviourENTITYControllervendor · model · firmwarerole · Purdue levelconfidence · sourcefirst / last seenDRIVESRiskexposure · CVEsDetectionbaselinesPolicyintent
3 · Baseline

Approve normal, explicitly.

Record a baseline window of observed traffic, review the communication pairs found, and approve, monitor or deny each one. For industrial protocols, WireTrace also learns which fields and values each protocol normally carries. Learning is operator-driven: nothing becomes normal without review.

4 · Define intent

Zones, conduits and allowed communication.

Declare which zones and devices may communicate, in which direction and over which services, and declare IEC 62443 zones, conduits and target security levels. Approved baseline patterns can seed the rules.

Packetaddresses · ports · volumesProtocolrecognised by namePayloadfields and operations decodedAssetdurable identity · type · roleIntelligencerisk · detection · policy intentTRADITIONAL DPI STOPS HERE ↑ PROTOCOLDPAI
5 · Validate before enforcement

Test the rules against real traffic.

Test proposed rules against observed traffic before relying on them, and simulate a policy against current assets and recent events before enabling it. Nothing is written during simulation, so you see what would break before anything does.

Validation uses a bounded window of observed traffic.

6 · Enforce through your controls

WireTrace understands. Your controls enforce.

Proposed rules can be exported as text for your firewall team (iptables, nftables, Cisco IOS and pf). Violations and decisions reach your existing tools through syslog, webhooks, email, ticketing (early access) and the REST API. A NAC can retrieve WireTrace asset identity, classification and risk through the API to enrich its own policy decisions.

CONTEXT IN · FINDINGS OUTYOUR CONTROLS ACTSIEM / SOARsyslog · CEF · LEEF · webhooksThreat intelligenceSTIX 2.1 · CSV · feedsNetwork infrastructureSNMP · LLDP/CDP · syslog inWireTraceunderstandsdecides · validatesFirewallsrule proposals · blocklistsNACidentity & risk via APIAPIs & automationREST · OAuth 2.0 · webhooks
7 · Governed decisions

Every policy runs in the mode you choose.

Every decision and action is recorded in an append-only activity log, and changes WireTrace makes can be time-bound and undone with a preview.

  1. 01

    Monitor only

    Observe and record; nothing else happens.

  2. 02

    Recommend

    Propose the action for a person to take.

  3. 03

    Require approval

    Four-eyes approvals that expire.

  4. 04

    Automatic

    Within limits: change freeze, maintenance windows, a maximum number of assets per action and an emergency stop.

8 · Continuous verification

Know the moment intent and reality diverge.

WireTrace continuously detects traffic that breaks segmentation intent, including IT-to-OT conduit crossings and large Purdue-level jumps, and detects drift against the approved baseline on the schedule you set. Segmentation controls in the compliance frameworks are evidenced from observed traffic.

415 CONTROLS · 7 FRAMEWORKS · EVERY CONTROL RATEDObservableevidenced from network trafficPartialnetwork evidence plus your inputManual assessmentclosed in the assessment workflowNot assessableoutside what a network can showNIST CSF 2.0 · ISO/IEC 27001 · HIPAA · IEC 62443-3-3 · NERC CIP · NCA OTCC · NCA ECC

Plan segmentation on evidence.

A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.