PacketSafari
Stack architecture

Azure packet investigation

Turn an Azure symptom into exact packet evidence.

Defender for Cloud, Microsoft Sentinel, Azure Monitor, and VNet Flow Logs help identify where and when to investigate. Network Watcher or a workload capture creates the packet record. PacketSafari explains what that record supports.

Vendor services provide signal, context, or packet acquisition. PacketSafari begins after an authorized packet capture exists.

Azure investigationOne incident · several evidence layers
Signal
Defender for Cloud
Microsoft Sentinel
Azure Monitor
VNet Flow Logs
Acquire
Network Watcher · workload capture
PCAP inSelected PCAP
PacketSafari investigates
Evidence
PacketSafariCore Engine
Reason
PacketSafariAgent
AI investigation

Analysis result out

  1. Preliminary
  2. Verification
  3. Final Report
Act
  • Sentinel case
  • Security team
  • Network owner
  • Service owner
Azure services provide security, incident, operational, and flow context. Network Watcher or workload capture produces a PCAP that PacketSafari investigates before evidence returns to the response owner.
  1. SignalFind the entity and time window
  2. Packet acquisitionCreate or retrieve the PCAP
  3. PacketSafariTest the question against frames

Evidence depth

Each source answers a different question.

Context and flow metadata are valuable, but they are not raw packet contents. The clean handoff is to use them to scope a capture, then investigate the capture itself.

Audit trail

Azure Activity Log

Subscription-level control-plane events that show what changed, by whom, and when.

context
Operations

Azure Monitor

Metrics and logs that expose timing, availability, saturation, and service symptoms.

context
Connection metadata

VNet Flow Logs

Virtual-network flow records used to scope communicating endpoints, directions, and traffic behavior, not packet contents.

metadata
Detection and case

Defender for Cloud / Sentinel

A security signal or correlated incident that defines the affected resources, entities, and investigation window.

metadata
Packet acquisition

Network Watcher Packet Capture

A filtered packet capture collected from a virtual machine and stored for packet-level investigation.

packets

Operator workflow

From cloud symptom to reviewable packet proof.

The workflow is intentionally bounded. PacketSafari does not poll the cloud account or replace the continuous control plane.

Scope

Start with the Azure symptom.

Record the resource, NIC, peer, ports, alert time, service path, and the question the operator needs answered.

resource · entity · time window
Acquire

Capture at the useful boundary.

Use Network Watcher Packet Capture on a supported VM, a workload capture, or an authorized network packet sensor.

authorized · filtered · bounded PCAP
Investigate

Test the cloud hypothesis.

PacketSafari maps the capture, follows the relevant flows, and separates preliminary direction from independent Verification.

frames · filters · flows · timing
Return

Send evidence to the owner.

Update the Sentinel case, change a control, repair the service, or escalate with explicit coverage and uncertainty.

reviewable report · next evidence

Investigation outcomes

Ask the question the packet record can settle.

A useful result is not another generic alert. It is an answer attached to frames, filters, flows, timestamps, decoded fields, coverage, and uncertainty.

Security

Does the packet record support the Sentinel incident hypothesis?

Evidence returned

Conversation timing, endpoints, protocol behavior, repeated sequences, payload-visible indicators, and the exact supporting frames.

Performance

Did the network or service cause the failed Azure transaction?

Evidence returned

Handshake timing, loss and recovery, resets, receiver behavior, request-to-response gaps, and where observed delay accumulates.

Ownership

Which Azure or application owner can act next?

Evidence returned

The observed boundary, peer behavior, protocol state, capture limitations, and a defensible next diagnostic action.

Data boundary

Move the smallest useful packet window.

Choose the resource and time window first. Apply capture filters, storage, and retention policy in the Azure environment. Then use the SaaS, dedicated, or on-premises path authorized for that packet data.

Review deployment boundaries
Scopeentity · time · boundary
Minimizefilter · trim · authorize
Investigateframes · coverage · report

Azure + PacketSafari

Keep the cloud controls. Add a packet-grounded investigation path.

Review the architecture