PacketSafari

Analyzer overview

Explore a single capture with packets, dashboards, graphs, and AI helpers.

The analyzer workspace is organized around tabs and specialist views. The exact set depends on the protocols found in the capture, indexing progress, and the capabilities enabled for your account and deployment.

Core tabs

  • Packets: filter bar, packet list, packet hotspots, decode, hex, RFC context, follow stream, and decode overrides.
  • Connections: aggregated conversations, timelines, protocol mix, deep connection insights, selected-connection TCP quality, and capture-point pivots.
  • Stats: ranked rule matches, packet hotspots for bounded evidence ranges, correlated connection and call issues, endpoint and conversation summaries, protocol hierarchy, and exported objects.
  • Summary: capture metadata, ownership, comments, tags, upload/indexing context, and saved whole-capture activity with separate integrity warnings.

The workspace is also lifecycle-aware. A capture can be:

  • open ready, meaning packet view is available
  • refining, meaning background analysis is still running
  • complete, meaning all required work for the current generation is finished

Capture health and saved activity

The Summary tab can show a whole-capture health panel built from saved facts. It keeps capture activity and capture integrity separate:

  • Activity includes packet count, duration, average wire rate, observed peak rate, capture start/end, and a saved packet or throughput timeline when the exact activity preview is available.
  • Integrity reports available metadata for dropped packets, non-strict timestamp order, and packet slicing.

The activity badge distinguishes Complete activity, Complete · timestamp gaps, and Activity unavailable. Packets without usable timestamps remain part of the capture total but cannot be placed accurately on the timeline.

The saved preview does not start new background work just to draw the chart. If it is unavailable, use Open I/O graph when you intentionally want an interactive query.

No saved integrity warnings means the three displayed metadata checks did not report a warning. It does not prove that the capture saw every relevant packet, that the capture point was correct, or that upstream capture loss did not occur.

Specialist tabs

  • Security: Suricata-based alert summaries, severity counts, detector coverage, and IOC export.
  • Names: DNS-focused pivots for hostnames, resolver posture, and name-resolution behavior.
  • TLS: encrypted-traffic summaries, SNI/certificate context, and TLS-focused pivots.
  • Infrastructure: inferred hosts, roles, links, subnets, and service-role signals.
  • Files: extracted objects and related evidence artifacts when supported by the capture.
  • OT: industrial-protocol evidence, explicit coverage, semantic mapping, signal timelines, and OT event stories.
  • VoIP: RTP stream comparison, packet loss, jitter, packet pivots, and on-demand media detail.
  • Telco: telecom signaling evidence, grouped dialogs, call issues, packet pivots, and ladder views.
  • Wi-Fi and Multicast: protocol-specific dashboards that appear when the capture contains those signals.

AI helpers

  • Upload Insights: deterministic first-open processing state, packet evidence, and next actions without a background model call.
  • Copilot: capture-aware chat and guided pivots.
  • Agent: deeper automated investigation runs with evidence-backed findings.
  • AI Analyses: shared history of Agent and Copilot work across captures.
  • PacketSafari Triage: the non-AI evidence map that lets PacketSafari handle large PCAPs with right-sized rules, indexing, and derived artifacts.
  • Investigation Path Guide: how to choose Fast answer, Fast + verification, or Triage then report without confusing analysis depth with manual, Copilot, Agent, anoncap, or email choices.
  • Sample Agent report and Demo Captures: a completed evidence-backed investigation and scenarios for validating the workflow before using production traces.

Processing awareness

The analyzer is designed to stay useful while indexing continues.

  • The packet view can open before every heavy post-index step is done.
  • Packet hotspots can appear as soon as PacketSafari has localized evidence ranges, even while broader analysis continues.
  • Some dashboards can show provisional preview or sampled results before full coverage arrives.
  • Expensive artifacts can be served from persisted cache, materialized on demand, or queued as follow-up work depending on capture size.

For those runtime details, see:

The header also gives quick access to PacketSafari Agent, time-range changes, and specialist tabs. The Misc menu contains shortcuts for Decode as, profile settings, saving selected packets, column autosizing, and dark mode. The older walkthrough-style Analyses workspace menu entry is currently hidden while that feature is paused.

Decode As

When a protocol is on a non-standard port, use Decode as to override decoding (for example RTP on an unusual UDP port). Once applied, the packet list, decode, and graphs reflect the new interpretation.

Dark Mode

A dark theme is available from the action menu if you prefer low-glare viewing.