01 · Observe
The agent analyses traffic within the chosen scope, without blocking it during this phase.
Automated microsegmentation
Krakinsight learns your traffic patterns and automates your microsegmentation. Time to value: 30 days.
Swiss Made
· On-premise · Created by pentesters
A SAFERDIGITALOCEAN
A proven principle. Deployment made simpler.
Microsegmentation has been around for over 10 years. But mapping traffic manually is time-consuming, risky and involves several teams. The map and policies then need to be maintained as the IT environment evolves.
Krakinsight automates traffic learning and policy enforcement to make microsegmentation operational.
30 days
From observing traffic
to operational microsegmentation.
Observe. Learn. Protect.
An intelligent agent that automatically deploys
a Zero Trust security model at the network level.
During 30 days of learning, the agent analyses your infrastructure’s network traffic without blocking it. It then builds a microsegmentation policy from the observed communications and applies the protection rules.
Administrative interfaces (SSH, RDP, RPC…) and network exceptions are controlled through ZTRA — Zero Trust Request Access. Requests go to the right approver, without changing existing applications or protocols.
The agent analyses traffic within the chosen scope, without blocking it during this phase.
Observed communications become a network map and a filtering policy.
Rules are applied automatically to limit lateral movement paths.
Users keep their usual workflows. Learned business traffic remains accessible, without changing their applications.
Sensitive access requires ZTRA approval, regardless of the protocol, while keeping familiar tools.
No network redesign. No application changes. Processing stays on your premises.
An educational comparison of network architectures. Scenarios and access are simulated.
Open the full-size diagramExceptions remain controlled
ZTRA — Zero Trust Request Access — routes requests to the right approver based on their context.
Try an access requestAuthorised user · Limited duration · Logged decision
Simulation: the request is awaiting the approver’s decision.
If the request is denied or expires, the port remains closed.
Monitor changes in sensitive groups. The chosen policy determines the response: an alert, removal of the member or a request to the appropriate person. Legitimate privilege elevation can be authorised temporarily.
The LLMNR decoy reveals attempts to harvest credentials. Ghost Ethernet detection targets intrusions that bypass 802.1X network access control, including certificate-based or credential-based authentication. It covers Ethernet ghosting attacks, such as those carried out using a Basilisk.
View machine hardening levels and identify priorities for improvement. Use a central overview to track your security posture and guide your teams’ actions.
Krakinsight connects to your SOC through Windows Event Logs. Your collection tools can integrate Krakinsight events into your SIEM and investigation workflows.
Real-world use cases
Protocol-agnostic, Krakinsight controls access at the network level: SSH, RDP, RPC and your business protocols. Requests go to the right approver; the required port and privileges are granted for a limited time.
New member
Adding a member triggers the chosen policy: alert, remove the member or request approval.
Example: approval is requested from the responsible person.
Visibility · Customer use case
The traffic matrix helped support a machine decommissioning. It reveals communications and dependencies to review before removing a device from the fleet.
Traffic matrix · Network dependenciesSecurity validation
Prepare your infrastructure for penetration testing: reduce lateral movement paths, control sensitive access and identify machines that need stronger hardening.
Microsegmentation · Verifiable controlsGovernance & audit
Support your industry’s requirements with access controls, logged decisions and hardening monitoring. Provide tangible evidence of your security posture for auditors.
Traceability · Hardening monitoringNetwork protection
Limit propagation after an initial compromise. Microsegmentation restricts lateral movement by allowing only the communications defined by your policy.
Zero Trust · Reduced lateral movementIdentity, decision, action and duration: every step remains traceable.
Fleet visibility
Traffic, privileges and hardening. A clear view for your teams.
Simplified communication map · Illustrative 15-minute ZTRA access.
Hardening score: 52 / 100
A group request is awaiting a decision.
Network, groups, Deception and Ghost Ethernet.
| Machine | Score | Priority |
|---|---|---|
| DC-PROD-01 | 96 / 100 | Low |
| SRV-APP-02 | 74 / 100 | Needs hardening |
| WS-FINANCE-08 | 52 / 100 | High |
Configure local and Active Directory groups subject to JIT, and view local groups across the fleet.
| Group / Machine | Scope | JIT |
|---|---|---|
| AdministratorsSRV-APP-02 | Local | |
| Remote Desktop UsersWS-FINANCE-08 | Local | |
| AdministratorsWS-IT-03 | Local | |
| Domain AdminsActive Directory | AD |
Local simulation: settings do not change any real groups.
LLMNR decoys flag suspicious attempts in your environment.
Source IP: 10.0.3.42 · WS-RH-02
23 Sep 2026 · 09:42
Visibility into Ethernet ghosting intrusions, including those involving certificate-based or credential-based authentication.
Source IP: 10.0.1.87 · WS-OPS-04
23 Sep 2026 · 09:10
ZTRA requests and events
Read-onlyDecisions can be viewed here; requests cannot be approved from the logs.
| Type | Source IP | Resource | Status | Time |
|---|---|---|---|---|
| network | 10.0.1.24 | SRV-APP-02RDP · 15 min | Granted | 12:41 |
| group | 10.0.2.18 | Domain AdminsActive Directory | Pending | 11:28 |
| deception | 10.0.3.42 | WS-RH-02LLMNR decoy | Detected | 09:42 |
| ghost | 10.0.1.87 | WS-OPS-04Ethernet ghosting | Detected | 09:10 |
23 September 2026 · SOC integration through Windows Event Logs.
Our co-founders
Co-Founder & Pentester
Co-Founder & Pentester
With over 10 years of experience as ethical hackers (pentesters), Guillaume and Léa have carried out several thousand engagements across different countries, primarily in Europe and Switzerland.
Their work has covered a wide range of environments, from internal enterprise infrastructure (Windows Active Directory) to industrial systems (SCADA), as well as common audits: physical intrusion, web, mobile and software pentesting, payment terminals and more.
The finding was always the same: few, if any, solutions effectively blocked or detected the most common attack paths. Beyond perimeter protection, few clients could deploy network microsegmentation suited to their context while retaining sovereignty over their data.
Krakinsight was born from this need for innovation, tailored solutions and 100% on-premises deployment:
Software built by ethical hackers to stop those who are not.
Servers, business environments or pilot deployments: discover how Krakinsight fits your use cases.
Last updated: 23 September 2026
This statement describes the data processed when you visit our website or contact Krakinsight.
Krakinsight Sàrl, c/o Cospire SA, Rue de Genève 100, 1004 Lausanne, Switzerland. UID: CHE-400.801.686. You can contact us using the website form or by post at this address.
This website uses no cookies, audience analytics or advertising trackers. Your language choice is part of the page address and is not stored in your browser.
Your name, email address and any information you choose to provide (company, country and message) are sent to Krakinsight to respond to your request. This data is sent through the mail service configured for the website. It is not used for advertising or sold to third parties.
The server processes technical data such as your IP address, browser, requested pages and request date to operate and secure the website and limit abuse. A temporary security token protects the form without using cookies.
Data is accessible to the people handling your request and the technical service providers needed to deliver it. It is retained for as long as necessary to follow up on your request and meet any legal obligations.
You can contact us to request access to, correction or deletion of your personal data, within the limits of applicable law. Please use the form or write to our postal address.
The dashboard and interactive scenarios use fictional data. They do not provide access to any real IT environment. Images, fonts and scripts are loaded from this website.
Krakinsight company website.
This website is published by Krakinsight Sàrl, registered in the commercial register of the canton of Vaud.
The interactive demonstrations and dashboard data illustrate how the solution works. Text, visuals and trademarks remain subject to the rights of their respective owners. Any reuse must comply with applicable rights and licences.