Infrastructure

Inspect inferred hosts, roles, links, subnets, and service signals for the current capture.

The Infrastructure tab turns packet evidence into a host and service-role model. Use it when you want to understand what the network looks like, not just which packets matched a filter.

Infrastructure signals view in PacketSafari

Infrastructure results can appear in stages:

  • a fast first pass can provide early host and role context
  • deeper infrastructure analysis can continue while the capture is refining
  • larger captures can defer the heaviest infrastructure work until it is actually needed

What it infers

  • Infrastructure entities such as hosts, appliances, or service roles
  • Links between entities observed in the capture
  • Subnet observations and environment hints
  • Confidence and source information for each inferred role

Typical use cases

  • Find likely servers, gateways, DNS resolvers, or controllers
  • Separate client activity from infrastructure behavior
  • Understand which subnets and roles appear in the capture
  • Pivot from name-resolution data into broader host context

Working with the table

  • Search by endpoint, name, role, source, or protocol
  • Filter by kind, confidence, role, source, and protocol
  • Sort by the strongest or most useful inferred signals first
  • Open row details to inspect why PacketSafari inferred that host or role

Reading provisional infrastructure

On larger captures, infrastructure can be:

  • sampled or preview first
  • later upgraded to full coverage

That means the tab may already be useful before every expensive supporting query has completed, but PacketSafari should still label non-authoritative states clearly.

Infrastructure is one of the clearest examples of adaptive analysis:

  • the analyzer can open before deep infrastructure modeling is complete
  • persisted infrastructure summaries are reused when they already exist
  • deeper reruns can be queued instead of blocking first open on large captures

See also:

This is the closest current equivalent to a host view. Use Stats for endpoint counts and protocol totals; use Infrastructure for inferred identity and role modeling.