PacketSafari

PacketSafari Desktop

Alpha · macOS · Windows TBD

Packet investigation. On your own machine.

Capture traffic, decrypt it with your keys, and ask an AI agent what went wrong. Every finding cites the frames behind it, and the capture is opened on your machine.

What it does

From live capture to cited finding.

Capture on the machine

Record live traffic with the built-in capture helper. macOS captures keep the process that sent each packet. Windows uses Packet Monitor, so Npcap is not required.

Decrypt with your keys

Use key logs or secrets embedded in the capture to read TLS 1.2 and 1.3, HTTP/2, QUIC and HTTP/3, DTLS 1.2, WireGuard, and IPsec ESP.

Ask with your model

Run Fast investigations with a ChatGPT subscription, an Anthropic or OpenAI API key, or an OpenAI-compatible local endpoint such as Ollama, LM Studio, or vLLM.

Inspect the evidence

Move between Overview, Flows, Apps, and Packets. Reported findings cite frames, and the app checks those citations against the capture.

Command line and MCP

The bundled psdesk CLI runs the same analysis from a terminal and can serve captures to coding agents over MCP.

Keys stay in the system store

API keys are stored in the macOS Keychain or Windows Credential Manager, not in project files.

Before you install

An early alpha.

Captures are opened and processed on your machine. When you choose a hosted model, the evidence the agent selects is sent to that provider. With a local endpoint it stays on your network.

Request a demo

Need to share a capture first? PacketSafari Anonymizer creates an anonymized copy locally. For team workflows, capture-wide Triage, and verification, see the Analyzer.