PacketSafari Desktop
Alpha · macOS · Windows TBD
Packet investigation. On your own machine.
Capture traffic, decrypt it with your keys, and ask an AI agent what went wrong. Every finding cites the frames behind it, and the capture is opened on your machine.
What it does
From live capture to cited finding.
Capture on the machine
Record live traffic with the built-in capture helper. macOS captures keep the process that sent each packet. Windows uses Packet Monitor, so Npcap is not required.
Decrypt with your keys
Use key logs or secrets embedded in the capture to read TLS 1.2 and 1.3, HTTP/2, QUIC and HTTP/3, DTLS 1.2, WireGuard, and IPsec ESP.
Ask with your model
Run Fast investigations with a ChatGPT subscription, an Anthropic or OpenAI API key, or an OpenAI-compatible local endpoint such as Ollama, LM Studio, or vLLM.
Inspect the evidence
Move between Overview, Flows, Apps, and Packets. Reported findings cite frames, and the app checks those citations against the capture.
Command line and MCP
The bundled psdesk CLI runs the same analysis from a terminal and can serve captures to coding agents over MCP.
Keys stay in the system store
API keys are stored in the macOS Keychain or Windows Credential Manager, not in project files.
Before you install
An early alpha.
Captures are opened and processed on your machine. When you choose a hosted model, the evidence the agent selects is sent to that provider. With a local endpoint it stays on your network.
Request a demoNeed to share a capture first? PacketSafari Anonymizer creates an anonymized copy locally. For team workflows, capture-wide Triage, and verification, see the Analyzer.
