Upload PCAPs
From the analyzer landing page choose Upload a PCAP (or press the upload action in the capture library). You can upload multiple .pcap, .pcapng, or .cap files at once. The uploader shows progress, size limits, and which captures will be private or published.
Choose what happens next
The upload dialog starts with the real workflow choice:
- Agent investigation uploads one PCAP into a focused Agent workspace. Choose what PacketSafari should answer and how quickly it should trade first-result speed for capture-wide context.
- Inspect manually uploads and processes the PCAP, then opens the packet and summary workflow for hands-on analysis.
The setup is progressive. Agent investigations move through focused Workflow, Goal, Plan, and Review steps, while manual uploads skip the Agent-only decisions. Each setup screen shows only its current decision; the Plan step shows all three speed-versus-verification choices directly, and the final Review confirms the complete selection. Optional Privacy, Email, Agent, Triage, Security, and Developer controls remain available from Advanced settings on Review without adding another required step or dialog.
For an Agent investigation, first choose the question: Executive summary, Root cause, Security review, or Custom prompt. For captures of 5 MB or more, also provide a known IP, hostname, Call-ID, stream, protocol/error, or time range—or explicitly ask PacketSafari to search the whole capture first. Then choose the analysis workflow:
Selecting Security review automatically enables the complete Suricata-compatible IDS scan and keeps PacketSafari Triage running. The results persist in Security, independently of whether the selected Agent workflow includes a verification report. Available MITRE ATT&CK mappings remain visible with those security findings.
- Fast + verification is the recommended operational path. A focused Agent produces a clearly labelled Preliminary Report while PacketSafari Triage processes the wider capture. A related Verification Report then adopts, qualifies, contradicts, or leaves each strong preliminary candidate inconclusive. Its verifier starts with the validated Sol low default; admins and on-prem operators can change the verifier model and reasoning without changing the two-stage workflow.
- Fast answer starts a bounded preliminary analysis as soon as the capture is safely readable. It does not wait for Triage or full IDS. When full IDS is requested, the preliminary result is labelled IDS pending until that independent Security milestone completes or fails.
- Triage then deep waits for indexed rules, priority flows, protocol signals, and correlations before Agent produces one Verification Report from indexed evidence and fresh packet checks. It has the slowest first response and the strongest capture-wide starting context.
These are analysis-depth choices. They are separate from the question preset, the Agent lane, anoncap anonymization, and report-email delivery. For a visual comparison, see Investigation workflows or the detailed Investigation Path Guide.
Hosted Agent Pro users choose the investigation workflow first. Where the deployment allows a model-profile choice, they can then select Standard model or Strongest model without changing what Fast answer, Fast + verification, or Triage then deep means. Higher-cost combinations are confirmed before PacketSafari spends the selected weighted Agent units.
If Anonymize before upload is enabled, the queued Agent prompt runs on the anonymized sibling capture. If report email delivery is enabled for the deployment and your entitlement allows it, PacketSafari can email the Preliminary Report and later Verification Report as separate milestones. Fast answer supports only the preliminary email; Triage then deep supports only its completed Verification Report.
Choose an organization workspace
For an account with one active organization, PacketSafari selects that workspace automatically. If you belong to multiple active organizations, the metadata step shows a required Organization workspace selector. Choose the customer workspace that should own the capture before uploading.
The selected organization supplies the capture's shared-access default, pooled upload and storage quota, retention policy, AI-provider policy, and analysis capacity. That organization ID remains stored on the capture and its derived cases, tags, profiles, saved filters, chats, investigations, and reports. Changing the selector on a later upload does not move an existing capture.
Only active organizations with an unexpired entitlement are available. If the workspace list cannot be loaded or the selected organization is unavailable, the upload stops instead of falling back to a different tenant. See Organizations for roles, sharing, quotas, and governance.
Upload-time AI outputs
Several AI-assisted outputs can appear after an upload. They are separate features with separate triggers:
| Output | What it is | When it runs | Where it appears |
|---|---|---|---|
| Agent Starter Brief | A short in-app capture brief plus capture-specific Agent prompt suggestions. It helps you decide what to ask Agent next. | After PacketSafari has enough overview context. Public SaaS captures can auto-generate it; private captures require the user's background starter brief preference; on-prem deployments also follow the deployment AI/anonymization policy. | Agent page, upload/first-open context, and AI Analyses history. |
| Quick Summary | A lightweight structured summary of the capture with top good/bad signals and issues to investigate. | Manually from Quick Summary/Quick Insights surfaces for eligible signed-in users, or from the anonymous upload email-summary opt-in path. It does not run for every normal authenticated upload. | Quick Insights, capture summary surfaces, AI Analyses history, or email for the anonymous opt-in flow. |
| Agent investigation run | An Agent investigation started from the upload dialog with a chosen question and analysis-depth workflow. | When you choose Agent investigation and submit a prompt/report preset. It follows Fast answer, Fast + verification, or Triage then deep. | Agent progress view, persisted preliminary and verification milestones when applicable, saved reports, and optional milestone email with delivery status. |
In short: Agent Starter Brief suggests what Agent should investigate, Quick Summary summarizes what the capture looks like at a glance, and Agent investigation starts a full Agent run.
When Agent investigation is configured to email reports, PacketSafari durably stores the request with the investigation and tracks preliminary and verification-follow-up delivery separately from the Agent run. A delivery can still be waiting, queueing, queued, sending, sent, failed, or skipped after the relevant report milestone finishes. Indexing progress itself does not generate an email sequence.
Anonymize during upload
In the metadata step, enable Anonymize before upload to run anoncap before the file is stored.
- When anonymization is enabled, the Privacy pane exposes the complete anoncap configuration directly without opening another dialog.
- The upload dialog defaults to scrubbing
pcapngmetadata and comments from the anonymized sibling capture. Sanitize pcapng metadataremoves capture-level metadata such as section comments, capture application / OS strings, interface names and descriptions, address info, name-resolution blocks, and embedded decryption-secret blocks.Sanitize commentsremoves pcapng capture comments and per-packet comments.- PacketSafari stores anoncap run metadata on the capture.
- PacketSafari keeps the original upload and creates the anonymized result as a separate sibling capture.
- For the fuller workflow and current protocol coverage, see How to anonymize a PCAP.
What happens after upload
- The capture is stored in your library and processed in staged background work.
- PacketSafari runs a fast minimal
capinfosmetadata pass after storage. This records basic file facts and does not count as full processing. - PacketSafari now distinguishes between a capture being open ready and being fully complete.
- Metadata, basic packet openability, and the first useful analyzer surfaces arrive first.
- Deeper dashboards, heavy post-index families, and optional large-capture work can continue refining after the packet view is already usable.
- When heavy follow-up work is deferred, PacketSafari records it as queued follow-up work instead of leaving it as an implicit placeholder.
- PacketSafari can generate a background Agent Starter Brief with PCAP-specific follow-up prompts once overview data is ready. This account preference is separate from Quick Summary and from the prompt-driven Agent report path.
- Captures tagged
noAIkeep normal packet access, but AI-assisted analysis and AI-derived packet insights are disabled. In shared views this means PacketSafari treats those AI insight requests as a terminal skipped state instead of continuing to poll. - Visibility depends on deployment mode and entitlement. Organization uploads use the selected workspace's organization or private default; other hosted and on-premises uploads continue to follow their applicable account and deployment policy.
- Each capture gets a metadata card with owner, packet count, tags, histograms, and download controls.
- You can open the analyzer, launch PacketSafari Agent, start a Copilot chat, or stay in the Agent waiting room when the upload was started with Agent investigation.
The first-pass AI layers are documented in Quick Insights. They are orientation passes, not the full Agent workflow.
If you want to see a completed investigation before uploading production traffic, read the sample Agent report, or review the scenario list in Demo Captures.
Fast answer and deferred processing
Use Fast answer in the Agent investigation path when you want PacketSafari Agent to begin from bounded packet access as soon as the file is safely readable. It returns one clearly labelled preliminary report. PacketSafari Triage can continue in the background, but Fast answer does not automatically create an independent verification follow-up.
For captures of 5 MB or more, the upload flow asks where PacketSafari should focus. Include a focused selector when one is known: an IP address, port, stream, Call-ID, phone number, hostname, BSSID, protocol/error, or time range. PacketSafari recommends Fast + verification when the starting point is selective. Fast answer requires that focused starting point at this size. The upload form shows the selector types it recognized—such as IP address, Call-ID, stream, hostname, protocol symptom, or time marker—before you choose the workflow. If it is not known, choose I don’t know yet — search the whole capture first; PacketSafari then recommends Triage then deep so indexed discovery can find and rank relevant traffic before the Agent starts.
In advanced upload metadata, Skip full processing after upload stores the PCAP and makes raw packets available without queuing the full indexing pipeline.
This option is off by default. When it is on, PacketSafari still runs the
minimal capinfos metadata pass, then opens the capture in raw packet mode.
Summaries, enriched dashboards, and PacketSafari Triage context become available
only after an owner or admin chooses Process now.
See Raw-First Captures for the full workflow and limitations.
Readiness states
During upload and indexing you may see these lifecycle states:
- Accepted: the file was accepted and PacketSafari is preparing metadata and the first analyzer view.
- Open ready: the real packet view can open. Some dashboards may still be refining.
- Refining: the capture is usable, but optional or heavy analysis is still running in the background.
- Complete: all required analysis for this capture generation is finished.
- Failed: a required stage failed and the capture needs recovery or reprocessing.
For large captures this is intentional. PacketSafari favors a fast, trustworthy first open instead of blocking the entire analyzer on the most expensive post-processing steps.
Adaptive analysis on large captures
Not every expensive artifact has to be built during the first ingest pass.
- Small captures often get more analysis eagerly.
- Larger captures can defer heavier artifacts such as file-object inventory or deeper infrastructure summaries.
- When a dashboard, API, or AI workflow requests a deferred artifact, PacketSafari can reuse the persisted result, materialize it on demand, or queue it in the background depending on cost.
- PacketSafari Triage uses the upload policy for PacketStats rule coverage: complete rule stats below
50 MiB, otherwise the first1,000,000frames. A full scan can still be started later when an owner or admin asks for every packet to be checked. Very large full scans are guarded by daily quota and can be cancelled at safe checkpoints.
You do not need to manage those decisions manually in normal use. The analyzer surfaces label provisional or refining results when they are not yet authoritative.
Busy queue behavior
If PacketSafari is already processing other captures, uploads should still behave predictably:
- Queue pressure can downgrade the first pass instead of rejecting the upload outright.
- The capture should still be stored in the library and listed immediately.
- Basic metadata and openability work can still run first while deeper analysis waits.
- Heavy follow-up work can remain queued until capacity is available.
- Eligible queued heavy follow-up tasks can expose a cancel action in upload insights so operators can stop work that is no longer worth finishing.
PacketSafari also reaps obviously stale queued or running task records automatically. Old zombie tasks should not keep new uploads blocked forever just because a worker died or a deferred follow-up never finished cleanly.
See also:
- Analysis Readiness and Refinement
- Processing Runtime and Adaptive Analysis
- Raw-First Captures
- Sample Agent report
- Demo Captures
Tagging while uploading ⚡️
Create tags in Settings → Tags, enable upload tagging in your profile, then select the tag before dropping files. The selected tags are added automatically as the files are stored.
Limits and privacy
- Current hosted SaaS upload ceilings are
1 MBretained for Analyzer Free,200 MBfor Copilot Pro and individual Agent Pro, and10 GiBfor qualified Enterprise Shared or Dedicated organization workspaces. On-prem accepts up to the configured deployment ceiling; 10 GiB support and higher limits must be validated against the customer's storage, memory, queue, and AI profile. - Some deployments can also disable uploads entirely or restrict related AI workflows with runtime policy flags.
- Anonymous upload flows require both authenticated uploads and anonymous uploads to be enabled at the deployment level.
- Plan entitlements, active subscription dates, download access, Agent starter brief eligibility, and other exceptions are documented in User Types and Entitlements.
- Respect data ownership—only upload captures you are allowed to store and analyze.
