PacketSafari Triage

How PacketSafari builds right-sized, evidence-backed context for small and huge PCAPs.

PacketSafari Triage is the non-AI evidence layer that turns a raw PCAP into a reusable map of connections, protocol signals, rule matches, security findings, and exact packet evidence. Agent, Copilot, dashboards, and analysts use that map without asking a model, a browser, or an analyst to read every packet as text.

What triage means

Triage is not a generic summary. PacketSafari organizes the capture, extracts metadata, runs rule and protocol analysis, ranks signals, and prepares reusable evidence outputs that remain tied to reproducible packet evidence.

Those outputs can include:

  • packet counts, timing, encapsulation, and open-ready metadata
  • endpoint, conversation, protocol, DNS, TLS, security, VoIP, Wi-Fi, OT, telco, file-object, and infrastructure signals when the capture supports them
  • PacketStats rule findings ranked by triage priority
  • packet hotspots and frame ranges that help an analyst pivot into evidence
  • Agent-ready context for Fast + verification follow-ups and Triage then deep runs

Why it matters for large captures

Large PCAPs fail when every workflow assumes the whole file must be fully scanned or converted into text before anything useful can happen. PacketSafari separates the work into right-sized stages:

StagePurpose
Open readyStore the PCAP, collect enough metadata, and open packet-level tools quickly.
PacketSafari TriageBuild the packet evidence map: rules, protocol landmarks, priorities, and reusable evidence outputs.
Refinement and on-demand workPrepare deeper evidence when policy, size, entitlement, and user action justify it.
Full scanRun every-packet PacketStats rule coverage when an owner or admin needs authoritative full-capture rule stats.

The upload policy gives small captures complete rule stats below 50 MiB. Larger captures use the first 1,000,000 frames for upload-time PacketStats rule coverage so analysts get useful triage context without blocking first use on very large files. A full scan can still be started later when every packet needs rule coverage.

How triage supports the Agent workflows

Triage then deep waits for triage context before Agent starts. Use it when the first answer needs broad correlation, priority flows, protocol context, or security signals.

Fast answer starts Agent as soon as the file is safely readable. Use it for urgent, bounded packet questions when speed matters more than complete triage context. It produces one preliminary report and does not automatically create an independent verification follow-up.

Fast + verification deliberately uses both paths: a bounded preliminary Agent starts while PacketSafari Triage runs, then a related verifier checks the strong preliminary candidates against the wider evidence map. See Investigation Path Guide.

Confidential analysis story

PacketSafari Triage is also part of the confidential-analysis model. Teams can choose the right evidence boundary for the case:

  • use hosted SaaS for lower-risk captures
  • use anoncap when an anonymized sibling capture is enough
  • use private AI paths or on-prem deployment when raw PCAP evidence must stay inside a controlled environment
  • use PacketSafari Triage to give Agent and analysts a consistent evidence map on PCAPs of many sizes

The practical goal is confidential PCAP analysis that is right-sized for the capture: anonymized or private where needed, evidence-backed by PacketSafari Triage, and not limited to traces small enough for manual review.