PacketSafari Features
Core analysis
- Upload
.pcap,.pcapng, and.cap, keep them private, or publish them to the shared library. - Anoncap anonymization workflow for creating separate anonymized capture copies on supported plans, including optional packet slicing and adaptive tunnel-aware slicing for IP-in-IP, GRE, ERSPAN, MPLS-over-GRE, QinQ, PPPoE, GTP, GTP-U extension-header traffic, PFCP/GTP mixed captures, L2TP, Geneve, and VXLAN.
- Deep anoncap coverage biased toward telecom and OT-heavy captures, including GSM MAP / TCAP USSD cleanup, S1AP PLMN remapping, PFCP/GTP identity handling, and seed OT identifier support for S7comm module names plus Modbus and MMS protocol-preservation checks.
- Narrow opt-in RTP silence replacement for supported G.711 voice payloads when media scrubbing is required without changing RTP timing/header behavior.
- Progressive ingest lifecycle with open ready, refining, and complete states so packet view can open before every heavy analysis tail finishes.
- Indexed search across capture names, tags, metadata, DNS queries/responses, TLS SNI, and protocol fields.
- Analyzer workspace with packet list, packet hotspots, decode + hex, follow stream, connection inventory and insights, stats, summary, security, DNS/names, TLS, infrastructure, files, OT, telco, VoIP, Wi-Fi, multicast, IO graphs, export objects, and packet editing/slicing.
- PacketSafari Triage builds right-sized packet evidence for small and huge captures: complete PacketStats rule coverage below
50 MiB, otherwise upload-time coverage over the first1,000,000frames, with owner/admin full scans available later when every packet needs checking. Large full scans are quota-guarded and can be cancelled at safe checkpoints. - Adaptive materialization for expensive artifacts such as file-object inventory and deeper infrastructure analysis, with persisted reuse instead of recomputing everything on every read.
- Customizable profiles for columns, coloring rules, backend settings, and decode preferences.
- Tags, comments, and roles to organize captures and control access.
- Owner-managed signed viewer links for private captures, so SaaS users with full Agent entitlement, grandfathered paid full-access plans, or on-prem users can generate time-limited read-only share URLs without publishing the capture.
AI assistance
Availability depends on deployment mode, entitlement, and admin policy.
Captures tagged noAI also disable AI-assisted analysis and AI-derived packet insights for that capture, even when the user or deployment would otherwise have AI access.
- PacketSafari Quick Insights. A bounded first-pass AI brief with a mini report and capture-specific next actions.
- PacketSafari Copilot. Chat about a capture, ask for summaries, or request filter suggestions while you browse packets.
- PacketSafari Agent. Upload a PCAP and ask AI in one flow, or launch a deeper automated investigation from an existing capture. Choose Fast answer for one bounded preliminary result, Fast + verification for preliminary direction followed by an independent indexed check, or Triage then deep when whole-capture context matters more than first-response time. In hosted SaaS this depends on your plan; on-prem deployments can expose it through local policy.
Hosted Agent Pro exposes Fast answer, Fast + verification, and Triage then deep as the customer-facing workflows. A focused standard-model run uses 1 weighted Agent unit; Fast + verification and a focused strongest-model run use 2; deep investigation on the strongest model uses 4. The hosted allowance is 50 Agent units per month. Saved reports and history show workflow, result phase, and model profile separately. Concrete provider model IDs and reasoning settings remain visible only to admins and on-prem operators where they configure the runtime.

Specialist analysis surfaces
- Security: on-demand Suricata scans, severity-based triage, and IOC export.
- Connections / TCP: correlated connection insights plus on-demand deep TCP diagnosis when a stream needs a more explicit transport-level explanation.
- Packet hotspots: bounded evidence ranges that highlight the packets behind a finding, explain why that range was selected, and provide one-click jumps or Agent handoff from the packet list.
- Infrastructure: inferred host, subnet, and service-role modeling from control-plane and service signals.
- Files / Export objects: persisted extracted-object inventory, certificate inventory, cache-backed object browsing, media/text preview, and per-object downloads when supported by the capture.
- Citrix app delivery: ICA, CGP session reliability, and EDT transport evidence, including bounded loss or stall buckets, path-change indicators, resets/reconnects, and listener-refused setup events.
- TCP setup failures: incomplete-handshake fan-in signals that group repeated setup failures toward one target so listener, load-balancer, or path setup trouble is easier to separate from isolated client noise.
- OT: industrial-protocol semantic mapping for protocols such as GOOSE, Modbus, DNP3, MMS, CIP/EtherNet-IP, and OPC UA.
- Telco / VoIP: signaling and media-focused workflows for SIP, IMS, Diameter, NGAP, GTP, RTP, and related telecom traffic, including localized hotspots for SIP failures, Diameter result-code failures, RTP state anomalies, and core mobility/session churn where the capture has enough evidence.
Runtime and operator visibility
- Ingestion performance cards and timeline to show what finished, what is refining, and what follow-up work is queued.
- Upload insights for live capture progress, derived-unit status, queued follow-up work, and cooperative cancellation on eligible heavy follow-up scans.
- Deferred upload Agent report email status, so a report request can show whether delivery is waiting for the saved report, queueing, queued, sending, sent, failed, or skipped.
- Admin Activity dashboard for recent uploads, AI ledger activity, Agent reports and threads, anoncap/background jobs, and security audit events in one operator view.
- Admin infrastructure views for ingest stages, derived-unit registry state, dependency edges, and adaptive materialization policy.
- On-prem runtime policy controls for sign-in methods, upload entry points, AI authentication options, upload indexing controls, and optional capture probe enrollment.
For a user-facing explanation of how those states affect the analyzer, see:
Plan snapshot
Hosted SaaS and on-prem deployments package the same core analyzer differently:
- Analyzer Free. Manual analysis plus preview-limited Copilot, security, and connection access. Autonomous Agent runs are blocked until upgrade or until a paid subscription with an active end date is assigned.
- Copilot Pro. Full Copilot, security insights, advanced connections, OT analysis, and anoncap anonymization workflows.
- Agent Pro. Everything in Copilot Pro plus prompt-driven Agent uploads, Fast answer, Fast + verification, Triage then deep, saved reports, and the weighted Agent-unit quota.
- Enterprise Shared SaaS. A five-user organization workspace with pooled storage and usage, 500 weighted Agent units, 2,500 Copilot messages, and shared priority Agent and indexing capacity.
- Enterprise Dedicated SaaS. A five-user dedicated environment with 2,000 weighted Agent units, 10,000 Copilot messages, one reserved Agent slot, and one reserved indexing slot.
- Grandfathered paid SaaS plans. Older paid subscription codes still retain full feature access while active, but their quota templates can differ from the current Copilot Pro and Agent Pro offers.
- On-Prem Enterprise. One production and one non-production licensed deployment with 25 named users and 5,000 weighted Agent units per licensed deployment. The customer manages infrastructure, storage, retention, and a compatible AI endpoint, credentials, and compute.
For the current source-of-truth matrix covering plans, admins, downloads, upload ceilings, concurrent-session rules, and runtime exceptions, see User Types and Entitlements.
For anonymization workflow details, see How to anonymize a PCAP.
