Tessera Guard
PX-04
Capabilities
Thirteen screens, grouped by the job in front of you.
Discovery, inspection, response, and living with it. Every finding states the numbers that fired it, because a security tool nobody trusts gets muted inside a week.
Thirteen screens, grouped by what you are trying to do at the time.
Discovery
The map
Network map
A force-directed topology with the gateway at the centre, coloured by device type, with high-risk devices promoted the moment a finding attaches to them.
Device inventory
IP, hostname, OUI vendor, MAC, inferred type, open ports and first/last seen, filterable by eleven device types.
Per-device diagnostics
Ping, traceroute, port scan and HTTP probe from the device panel, plus one-click open web UI and copy RTSP/SMB URL.
Honest about limits
When the router is doing client isolation it says so in plain language, rather than quietly showing you wrong MAC addresses.
Inspection
The evidence
Packet inspector
A real capture surface on tcpdump: packet list, protocol tree and hex/ASCII pane, follow stream, apply as filter, save as standard .pcap.
Live connections
What your machine is talking to right now, with the seven-day view beside it.
Process monitor
PID, CPU, memory and connection count with a risk score that weighs network behaviour against signing status and path.
Activity analytics
Bandwidth, packet counts, protocol distribution, connection rate and top talkers over time.
Response
The fix
The detail panel
Description, the metrics that fired it, the MITRE ATT&CK technique, and ordered remediation steps tagged safe, caution or destructive.
Finding lifecycle
Active, Investigating, Mitigated, Dismissed — with bulk selection on the alert stream.
Quarantine
Isolate a device from one click on its card, and restore it as easily.
Reports
Totals by severity, top categories, most-targeted devices and recommendations generated from the findings actually present. Exports as JSON.
Everyday
Living with it
System health
CPU, memory, disk and network vitals with recommendations that name the process and offer to act.
WireGuard VPN
A client for your own tunnels — Cloudflare WARP, Mullvad, ProtonVPN or a .conf you already have — with stealth mode keeping DNS inside the tunnel.
Indicators-of-compromise scan
Six check families on macOS: XProtect flags, launch-agent persistence, code-signing status, suspicious paths, browser extensions and Downloads quarantine attributes. Complementary to your antivirus, not a replacement for it.
Pause
One pill in the corner drops monitoring to effectively zero CPU, which is what makes it polite enough to leave running.
Ten categories, all behavioural. A detection that cannot show its working gets muted within a week, so every one of these keeps its evidence.
What it looks for
10 engines
Automated attack patterns
Traffic whose packet-size variation is implausibly low across a large sample — what tooling looks like, and what a human never does.
Brute force and injection
Repeated authentication attempts and payload shapes aimed at services on the LAN.
Cryptojacking and malware
Process behaviour and destinations consistent with mining or known-bad infrastructure.
Exfiltration and denial of service
Outbound volume and timing that does not match how the process normally behaves.
Reconnaissance, lateral movement and spoofing
Sweeps, east-west connections and ARP behaviour that does not add up.
What a finding carries
Auditable
The numbers
The actual metric values that crossed the line, so you can disagree with the tool.
MITRE ATT&CK
The mapped technique, so the finding means something to anyone who has read a threat report.
Ordered remediation
Steps you can take, each tagged by how reversible it is.
Vulnerability scan
Extended port scan, service-version detection and OS fingerprinting, then 15 rules each with a fix and a source link.
Boring on purpose. Nothing here needs a service to be up for the app to work.
Application
Desktop
Electron + React + TypeScript
One codebase, native builds for macOS on Apple Silicon and Intel, and for Windows.
SQLite
A single local store for devices, findings, alerts and history. It is a file on your disk; you can delete it.
Force-directed rendering
The topology is a physics simulation over the scanner's own subnet inference, not a drawing.
Sampled telemetry
OS interface counters rather than a permanent capture, which is where the low CPU figure comes from.
Network and security
Under the hood
tcpdump / libpcap
Capture is the real thing, behind a one-time explicit administrator prompt that says what it is asking for and how long it lasts.
WireGuard
Kernel-grade tunnelling with your keys staying on the machine; stealth mode wraps the tunnel in WebSocket/TLS.
OUI vendor database
Local, so vendor lookup does not become a list of your devices sent to somebody else.
Model Context Protocol
A loopback-only server behind a bearer token that rejects non-loopback origins, with double-gating on every mutating tool.
Every screen, one at a time.
07 SCREENS · CLICKTAP TO ENLARGE
Tessera Guard
01 / 07
01
Dashboard
The network's security at a glance: devices online, active threats, new alerts and packets analysed.
Watch traffic in and out on a live chart.
See the threat breakdown by severity, and the network's health.
Jump straight to the most recent threats.
