Tool comparison

How PacketSafari anoncap compares with TraceWrangler and VoIP Analyzer Tool on publicly documented behavior.

This comparison focuses on publicly documented behavior for TraceWrangler and VoIP Analyzer Tool, plus the current open-source anoncap CLI and PacketSafari managed / DeepAnon workflow.

Hover or focus a status icon for the supporting detail. The top rows compare shared anonymization mechanics, default slicing behavior, audit artifacts, and public protocol handling; the Pro: rows at the bottom call out private PacketSafari / DeepAnon coverage that is not part of the open-source default CLI profile.

Yes Partial Narrow No Not documented
Feature OSSProTWVAT
Field-aware anonymization
L2-L4 identifier rewrite
ARP and neighbor identifiers
IPv4 class preservation
Subnet / prefix shape
MAC OUI preservation
DNS-aware rewriting
DHCP-aware rewriting
HTTP / HTTP2 host fields
TLS / X.509 names
Deterministic mapping
Coherent filesets
Batch and recursive runs
One-input CLI output UX
Mapping report
pcapng metadata stripping
Report and diagnostics artifacts
Wireshark verification helpers
Rules transparency and export
Redissection validation
Leak verification
Coverage diagnostics
Paranoid audit preset
Adaptive packet slicing
Tunnel header preservation
ICMP quote preservation
Unknown encapsulation safety
Payload reduction modes
Forced sensitive-value scrub
Custom rules JSON
Progress and debug controls
Checksum and length fixups
RTP G.711 silence replacement
Pro: telecom / subscriber identities
Pro: DHCPv6 / IPv6 name options
Pro: SIP / SDP deep rewrite
Pro: Diameter identities
Pro: mobile core protocols
Pro: RADIUS subscriber fields
Pro: Windows identity cleanup
Pro: semantic web fields
Pro: OT / industrial seed coverage
Pro: private regression harness
Broad RTP codec replacement

PacketSafari-specific notes

  • default mode is deep
  • a postprocess payload cleanup pass can run after the structured rewrite pass
  • map files are first-class outputs
  • --batch-coherent is the recommended standalone mode for dumpcap ring buffers, filesets, and multi-point captures that need consistent replacements across separate anonymized outputs
  • validation and leak verification are built into the workflow