PacketSafari
Ecosystem overview

Traffic acquisition

Capture the right packets. Investigate what they prove.

Use a host tool, cloud mirror, virtual switch, SPAN, TAP, broker, or recorder to create the smallest authorized capture that contains the incident.

Choose the observation pointCapture is the enabling layer
Host Cloud Network Recorder
ObserveUseful boundary
AcquireBounded PCAPinterface · filter · time
InvestigatePacketSafarievidence · verification · report

Beyond the endpoint

Capture where the traffic is visible.

A host capture is not always the best evidence. Use the cloud, hypervisor, switching, visibility, or retention layer when that gives the investigation the correct boundary.

Before you press start

A useful capture is deliberate.

PacketSafari can only investigate evidence present at the selected observation point. Encryption, asymmetric visibility, filters, slicing, packet loss, and an incomplete time window remain explicit limits.

01

Capture at the useful boundary

Choose the point that can observe both sides of the question, not merely the nearest available interface.

02

Bound the incident window

Start just before reproduction and stop after the result. Smaller captures are easier to authorize, move, and investigate.

03

Preserve the evidence you need

Use filters or packet slicing only when they will not remove payload, timing, or protocol fields required by the investigation.

04

Handle packet data deliberately

Confirm authorization, retention, transfer, decryption, and sanitization requirements before sharing a capture.

Capture ready

Bring the packet question and its evidence.

Investigate your capture