Segmentation that
writes itself.
The endpoint agent learns your network on its own, drafts the rules for you, shows you exactly what they would block — and only then, when you say so, enforces them. No VLANs. No ACL project. No downtime.
The same policy, three safe steps.
Nothing is ever blocked by surprise. Switch between the modes below to see exactly what the agent does to real traffic at each stage.
| Source | Destination | Service | Seen | Decision |
|---|---|---|---|---|
| FIN-PC-03 | SQL-PROD-01 | 1433 / MSSQL | 2,418× | Recording |
| ENG-PC-14 | GIT-SRV-01 | 22 / SSH | 1,902× | Recording |
| HR-PC-07 | FILE-SRV-02 | 445 / SMB | 874× | Recording |
| MKT-PC-02 | WEB-PROXY | 8080 / HTTP | 3,650× | Recording |
| FIN-PC-03 | ENG-PC-14 | 445 / SMB | 2× | Recording |
| QA-PC-09 | SRV-DC-01 | 3389 / RDP | 1× | Recording |
| SUP-PC-08 | HR-PC-07 | 5985 / WinRM | 3× | Recording |
| DEV-PC-07 | 10.0.9.14 | 5432 / Postgres | 1× | Recording |
No one writes the first rule.
The agent already sees every TCP connection the host makes. Segmentation is just what you do with that knowledge.
Observe flows
Every TCP connection is recorded with source, destination, port, process and frequency.
Cluster hosts
Machines with the same behaviour are grouped automatically — finance, engineering, servers.
Draft the rules
A first-match ruleset is generated with a confidence score and evidence for every line.
Keep adapting
New applications and servers are detected and proposed as amendments, not incidents.
You review. You approve. That's the work.
Every proposed rule arrives with the evidence behind it and a confidence score. Approve them one by one, or take the whole baseline in a click.
-
99%ALLOW FINANCE → SQL-PROD-01 tcp/1433Seen 2,418× from 14 hosts over 7 days • business application
-
97%ALLOW FINANCE → FILE-SRV-02 tcp/445Seen 874× from 14 hosts over 7 days • shared drive
-
99%ALLOW FINANCE → WEB-PROXY tcp/8080Seen 3,650× from 14 hosts over 7 days • outbound web
-
96%BLOCK FINANCE → FINANCE tcp/445, 3389, 5985Peer-to-peer traffic seen 2× in 7 days • no business use • lateral movement path
-
92%BLOCK FINANCE → ENG-* anyNo legitimate flow observed between these groups in 7 days
-
88%ALERT FINANCE → any new destinationAnything outside the baseline raises an alert instead of a silent drop
The same outcome, without the project.
Traditional segmentation
Months of work- Map the network by hand, or guess
- Re-architect VLANs and subnets
- Write and maintain ACLs per switch
- Change windows, downtime, rollback plans
- Break something and find out from the helpdesk
- Documentation goes stale the week it ships
ReviveSec micro-segmentation
A week, mostly waiting- The agent maps every flow automatically
- Nothing on the network changes — enforcement is on the host
- Rules are drafted for you with evidence and confidence
- No change window, no downtime, no reboot
- Observe mode shows the impact before anything is blocked
- The baseline keeps adapting as the estate changes
Host-level enforcement, done properly.
First-match TCP rules
Deterministic evaluation by IP, CIDR, port and direction — the same model your firewall team already thinks in.
Automatic host grouping
Machines are clustered by observed behaviour, so policy follows the role rather than the IP address.
Lateral movement blocking
SMB, RDP, WinRM and NetBIOS between peers closed by default once the baseline says they are unused.
Per-group policy
Finance, engineering and servers each get their own ruleset, versioned and rolled out on the next heartbeat.
Instant rollback
Every policy is versioned. If a rule bites, roll the group back to the previous version in one click.
Works anywhere the agent runs
Windows and Linux, on-premises, remote and cloud workloads — no dependency on where the machine sits.
Let it learn your
network first.
Seven days in silent mode, then look at what it drafted. You decide whether to enforce a single line of it.
Schedule a demo