Segment on understanding, not on guesswork.
WireTrace provides the intelligence, policy intent and continuous validation layer, while integrated network and security platforms execute enforcement.
Rules written without knowing the traffic.
Most segmentation projects stall for the same reason: nobody can say with confidence which devices exist, what they are, and which conversations the process actually depends on. Rules written from diagrams break production, so they get loosened until they protect nothing.
Identity and dependencies first.
WireTrace identifies and classifies each device, then maps observed communication between devices, groups and zones, by protocol and port. Segmentation decisions are made about known devices, not addresses.
Approve normal, explicitly.
Record a baseline window of observed traffic, review the communication pairs found, and approve, monitor or deny each one. For industrial protocols, WireTrace also learns which fields and values each protocol normally carries. Learning is operator-driven: nothing becomes normal without review.
Zones, conduits and allowed communication.
Declare which zones and devices may communicate, in which direction and over which services, and declare IEC 62443 zones, conduits and target security levels. Approved baseline patterns can seed the rules.
Test the rules against real traffic.
Test proposed rules against observed traffic before relying on them, and simulate a policy against current assets and recent events before enabling it. Nothing is written during simulation, so you see what would break before anything does.
Validation uses a bounded window of observed traffic.
WireTrace understands. Your controls enforce.
Proposed rules can be exported as text for your firewall team (iptables, nftables, Cisco IOS and pf). Violations and decisions reach your existing tools through syslog, webhooks, email, ticketing (early access) and the REST API. A NAC can retrieve WireTrace asset identity, classification and risk through the API to enrich its own policy decisions.
Every policy runs in the mode you choose.
Every decision and action is recorded in an append-only activity log, and changes WireTrace makes can be time-bound and undone with a preview.
- 01
Monitor only
Observe and record; nothing else happens.
- 02
Recommend
Propose the action for a person to take.
- 03
Require approval
Four-eyes approvals that expire.
- 04
Automatic
Within limits: change freeze, maintenance windows, a maximum number of assets per action and an emergency stop.
Know the moment intent and reality diverge.
WireTrace continuously detects traffic that breaks segmentation intent, including IT-to-OT conduit crossings and large Purdue-level jumps, and detects drift against the approved baseline on the schedule you set. Segmentation controls in the compliance frameworks are evidenced from observed traffic.
Plan segmentation on evidence.
A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.