Tool comparison
How PacketSafari anoncap compares with TraceWrangler and VoIP Analyzer Tool on publicly documented behavior.
This comparison focuses on publicly documented behavior for TraceWrangler and VoIP Analyzer Tool, plus the current open-source anoncap CLI and PacketSafari managed / DeepAnon workflow.
Hover or focus a status icon for the supporting detail. The top rows compare shared anonymization mechanics, default slicing behavior, audit artifacts, and public protocol handling; the Pro: rows at the bottom call out private PacketSafari / DeepAnon coverage that is not part of the open-source default CLI profile.
Yes Partial Narrow No Not documented
| Feature | Open-source anoncapOSS | PacketSafari managed / DeepAnonPro | TraceWranglerTW | VoIP Analyzer ToolVAT |
|---|---|---|---|---|
| Field-aware anonymization | ||||
| L2-L4 identifier rewrite | ||||
| ARP and neighbor identifiers | ||||
| IPv4 class preservation | ||||
| Subnet / prefix shape | ||||
| MAC OUI preservation | ||||
| DNS-aware rewriting | ||||
| DHCP-aware rewriting | ||||
| HTTP / HTTP2 host fields | ||||
| TLS / X.509 names | ||||
| Deterministic mapping | ||||
| Coherent filesets | ||||
| Batch and recursive runs | ||||
| One-input CLI output UX | ||||
| Mapping report | ||||
| pcapng metadata stripping | ||||
| Report and diagnostics artifacts | ||||
| Wireshark verification helpers | ||||
| Rules transparency and export | ||||
| Redissection validation | ||||
| Leak verification | ||||
| Coverage diagnostics | ||||
| Paranoid audit preset | ||||
| Adaptive packet slicing | ||||
| Tunnel header preservation | ||||
| ICMP quote preservation | ||||
| Unknown encapsulation safety | ||||
| Payload reduction modes | ||||
| Forced sensitive-value scrub | ||||
| Custom rules JSON | ||||
| Progress and debug controls | ||||
| Checksum and length fixups | ||||
| RTP G.711 silence replacement | ||||
| Pro: telecom / subscriber identities | ||||
| Pro: DHCPv6 / IPv6 name options | ||||
| Pro: SIP / SDP deep rewrite | ||||
| Pro: Diameter identities | ||||
| Pro: mobile core protocols | ||||
| Pro: RADIUS subscriber fields | ||||
| Pro: Windows identity cleanup | ||||
| Pro: semantic web fields | ||||
| Pro: OT / industrial seed coverage | ||||
| Pro: private regression harness | ||||
| Broad RTP codec replacement |
PacketSafari-specific notes
- default mode is
deep - a postprocess payload cleanup pass can run after the structured rewrite pass
- map files are first-class outputs
--batch-coherentis the recommended standalone mode for dumpcap ring buffers, filesets, and multi-point captures that need consistent replacements across separate anonymized outputs- validation and leak verification are built into the workflow
