Tessera Guard

PX-04

Capabilities

Thirteen screens, grouped by the job in front of you.

Discovery, inspection, response, and living with it. Every finding states the numbers that fired it, because a security tool nobody trusts gets muted inside a week.

Thirteen screens, grouped by what you are trying to do at the time.

Discovery

The map

Network map

A force-directed topology with the gateway at the centre, coloured by device type, with high-risk devices promoted the moment a finding attaches to them.

Device inventory

IP, hostname, OUI vendor, MAC, inferred type, open ports and first/last seen, filterable by eleven device types.

Per-device diagnostics

Ping, traceroute, port scan and HTTP probe from the device panel, plus one-click open web UI and copy RTSP/SMB URL.

Honest about limits

When the router is doing client isolation it says so in plain language, rather than quietly showing you wrong MAC addresses.

Inspection

The evidence

Packet inspector

A real capture surface on tcpdump: packet list, protocol tree and hex/ASCII pane, follow stream, apply as filter, save as standard .pcap.

Live connections

What your machine is talking to right now, with the seven-day view beside it.

Process monitor

PID, CPU, memory and connection count with a risk score that weighs network behaviour against signing status and path.

Activity analytics

Bandwidth, packet counts, protocol distribution, connection rate and top talkers over time.

Response

The fix

The detail panel

Description, the metrics that fired it, the MITRE ATT&CK technique, and ordered remediation steps tagged safe, caution or destructive.

Finding lifecycle

Active, Investigating, Mitigated, Dismissed — with bulk selection on the alert stream.

Quarantine

Isolate a device from one click on its card, and restore it as easily.

Reports

Totals by severity, top categories, most-targeted devices and recommendations generated from the findings actually present. Exports as JSON.

Everyday

Living with it

System health

CPU, memory, disk and network vitals with recommendations that name the process and offer to act.

WireGuard VPN

A client for your own tunnels — Cloudflare WARP, Mullvad, ProtonVPN or a .conf you already have — with stealth mode keeping DNS inside the tunnel.

Indicators-of-compromise scan

Six check families on macOS: XProtect flags, launch-agent persistence, code-signing status, suspicious paths, browser extensions and Downloads quarantine attributes. Complementary to your antivirus, not a replacement for it.

Pause

One pill in the corner drops monitoring to effectively zero CPU, which is what makes it polite enough to leave running.

Ten categories, all behavioural. A detection that cannot show its working gets muted within a week, so every one of these keeps its evidence.

What it looks for

10 engines

Automated attack patterns

Traffic whose packet-size variation is implausibly low across a large sample — what tooling looks like, and what a human never does.

Brute force and injection

Repeated authentication attempts and payload shapes aimed at services on the LAN.

Cryptojacking and malware

Process behaviour and destinations consistent with mining or known-bad infrastructure.

Exfiltration and denial of service

Outbound volume and timing that does not match how the process normally behaves.

Reconnaissance, lateral movement and spoofing

Sweeps, east-west connections and ARP behaviour that does not add up.

What a finding carries

Auditable

The numbers

The actual metric values that crossed the line, so you can disagree with the tool.

MITRE ATT&CK

The mapped technique, so the finding means something to anyone who has read a threat report.

Ordered remediation

Steps you can take, each tagged by how reversible it is.

Vulnerability scan

Extended port scan, service-version detection and OS fingerprinting, then 15 rules each with a fix and a source link.

Boring on purpose. Nothing here needs a service to be up for the app to work.

Application

Desktop

Electron + React + TypeScript

One codebase, native builds for macOS on Apple Silicon and Intel, and for Windows.

SQLite

A single local store for devices, findings, alerts and history. It is a file on your disk; you can delete it.

Force-directed rendering

The topology is a physics simulation over the scanner's own subnet inference, not a drawing.

Sampled telemetry

OS interface counters rather than a permanent capture, which is where the low CPU figure comes from.

Network and security

Under the hood

tcpdump / libpcap

Capture is the real thing, behind a one-time explicit administrator prompt that says what it is asking for and how long it lasts.

WireGuard

Kernel-grade tunnelling with your keys staying on the machine; stealth mode wraps the tunnel in WebSocket/TLS.

OUI vendor database

Local, so vendor lookup does not become a list of your devices sent to somebody else.

Model Context Protocol

A loopback-only server behind a bearer token that rejects non-loopback origins, with double-gating on every mutating tool.

Every screen, one at a time.

07 SCREENS · CLICKTAP TO ENLARGE

Tessera Guard

01 / 07

01

Dashboard

The network's security at a glance: devices online, active threats, new alerts and packets analysed.

Watch traffic in and out on a live chart.

See the threat breakdown by severity, and the network's health.

Jump straight to the most recent threats.

Tessera Guard is live.