A pirate ship with a skull on its sail crosses the sea between the purple tentacles of a kraken.

Automated microsegmentation

Limit lateral movement.
Keep your business traffic flowing.

Krakinsight learns your traffic patterns and automates your microsegmentation. Time to value: 30 days.

Swiss Made · On-premise · Created by pentesters

A SAFERDIGITALOCEAN

A proven principle. Deployment made simpler.

Microsegmentation is not the challenge.
Deploying and maintaining it is.

Microsegmentation has been around for over 10 years. But mapping traffic manually is time-consuming, risky and involves several teams. The map and policies then need to be maintained as the IT environment evolves.

Krakinsight automates traffic learning and policy enforcement to make microsegmentation operational.

Time to value

30 days

From observing traffic
to operational microsegmentation.

ObserveLearnProtect
Understand deployment

Observe. Learn. Protect.

How does Krakinsight work?

An intelligent agent that automatically deploys
a Zero Trust security model at the network level.

During 30 days of learning, the agent analyses your infrastructure’s network traffic without blocking it. It then builds a microsegmentation policy from the observed communications and applies the protection rules.

Administrative interfaces (SSH, RDP, RPC…) and network exceptions are controlled through ZTRA — Zero Trust Request Access. Requests go to the right approver, without changing existing applications or protocols.

01 · Observe

The agent analyses traffic within the chosen scope, without blocking it during this phase.

Filtering policy
  • Observed communications
  • Generated rules
  • Ready to apply

02 · Learn

Observed communications become a network map and a filtering policy.

03 · Protect

Rules are applied automatically to limit lateral movement paths.

For users

Users keep their usual workflows. Learned business traffic remains accessible, without changing their applications.

For administrators

Sensitive access requires ZTRA approval, regardless of the protocol, while keeping familiar tools.

No network redesign. No application changes. Processing stays on your premises.

Explore the technical diagram

An educational comparison of network architectures. Scenarios and access are simulated.

Open the full-size diagram

Exceptions remain controlled

Sensitive access?
A controlled decision.

ZTRA — Zero Trust Request Access — routes requests to the right approver based on their context.

Try an access request
Approver
Requester

ZTRA request

Resource
Server
Port
RDP · 3389
Duration
15 min (example)
Privileges
Temporary
Pending

Authorised user · Limited duration · Logged decision

Simulation: the request is awaiting the approver’s decision.

If the request is denied or expires, the port remains closed.

One agent.
Multiple risks covered.

Explore use cases
Sensitive groupsAlert, remove a member or request approval.

Monitor changes in sensitive groups. The chosen policy determines the response: an alert, removal of the member or a request to the appropriate person. Legitimate privilege elevation can be authorised temporarily.

DetectionCredential harvesting and 802.1X bypass.

The LLMNR decoy reveals attempts to harvest credentials. Ghost Ethernet detection targets intrusions that bypass 802.1X network access control, including certificate-based or credential-based authentication. It covers Ethernet ghosting attacks, such as those carried out using a Basilisk.

HardeningSee the protection level across your fleet.

View machine hardening levels and identify priorities for improvement. Use a central overview to track your security posture and guide your teams’ actions.

SOC / SIEMIntegration through Windows Event Logs.

Krakinsight connects to your SOC through Windows Event Logs. Your collection tools can integrate Krakinsight events into your SIEM and investigation workflows.

Real-world use cases

Controlled decisions.
Traceable actions.

Grant sensitive access

Protocol-agnostic, Krakinsight controls access at the network level: SSH, RDP, RPC and your business protocols. Requests go to the right approver; the required port and privileges are granted for a limited time.

  1. 1Request
  2. 2Approval
  3. 3Temporary access

Control a sensitive group

Adding a member triggers the chosen policy: alert, remove the member or request approval.

Example: approval is requested from the responsible person.

Visibility · Customer use case

Decommission a machine

The traffic matrix helped support a machine decommissioning. It reveals communications and dependencies to review before removing a device from the fleet.

Traffic matrix · Network dependencies

Security validation

Defense in depth

Prepare your infrastructure for penetration testing: reduce lateral movement paths, control sensitive access and identify machines that need stronger hardening.

Microsegmentation · Verifiable controls

Governance & audit

Industry-specific compliance

Support your industry’s requirements with access controls, logged decisions and hardening monitoring. Provide tangible evidence of your security posture for auditors.

Traceability · Hardening monitoring

Network protection

Limit the impact of ransomware

Limit propagation after an initial compromise. Microsegmentation restricts lateral movement by allowing only the communications defined by your policy.

Zero Trust · Reduced lateral movement

Identity, decision, action and duration: every step remains traceable.

Fleet visibility

Know where to act.

Traffic, privileges and hardening. A clear view for your teams.

  • Map communications
  • Control JIT access
  • Track ZTRA events

Network Access (ZTNA)

Demo data
8machines
7allowed flows
1temporary access
Simplified network map Eight machines, seven allowed flows, one temporary ZTRA access and one blocked flow. ZTRA · 15 min DC-PROD-01 SRV-APP-02 SRV-DB-01 SRV-FILES-01 WS-FINANCE-08 WS-IT-03 WS-RH-02 WS-OPS-04
AllowedTemporaryBlocked

Simplified communication map · Illustrative 15-minute ZTRA access.

Our co-founders

Born in the field.
Built by pentesters.

Guillaume Nuel, co-founder of Krakinsight

Guillaume Nuel

Co-Founder & Pentester

Léa Nuel, co-founder of Krakinsight

Léa Nuel

Co-Founder & Pentester

Our story

With over 10 years of experience as ethical hackers (pentesters), Guillaume and Léa have carried out several thousand engagements across different countries, primarily in Europe and Switzerland.

Their work has covered a wide range of environments, from internal enterprise infrastructure (Windows Active Directory) to industrial systems (SCADA), as well as common audits: physical intrusion, web, mobile and software pentesting, payment terminals and more.

The finding was always the same: few, if any, solutions effectively blocked or detected the most common attack paths. Beyond perimeter protection, few clients could deploy network microsegmentation suited to their context while retaining sovereignty over their data.

Krakinsight was born from this need for innovation, tailored solutions and 100% on-premises deployment:

Software built by ethical hackers to stop those who are not.

Swiss MadeOn-premiseNetwork Zero Trust

Unleash the Kraken
and defeat hackers.

Servers, business environments or pilot deployments: discover how Krakinsight fits your use cases.

Request a demo

Your contact details are used only to respond to your request.

Krakinsight