PacketSafari
Ecosystem overview

Google Cloud packet investigation

Start with Google Cloud context. Finish with packet evidence.

Security Command Center, Cloud Audit Logs, Cloud Monitoring, VPC Flow Logs, Cloud IDS, and Google Security Operations help scope an incident. Packet Mirroring or an authorized workload capture creates the packet record PacketSafari can investigate.

Google CloudContext → capture → investigation
Scope
Security Command CenterCloud Audit LogsCloud MonitoringVPC Flow Logs
AcquirePacket Mirroring · workload captureauthorized incident PCAP
InvestigatePacketSafariCore Engine · Agent · report
Result outExact evidence returns to the team that can act.
Category owns

Detect cloud threats, record control-plane activity, monitor services, and provide network-flow context across Google Cloud workloads.

Acquisition path

Use VPC Packet Mirroring where supported, capture at the workload, or retrieve traffic from an existing virtual sensor or recorder.

PacketSafari owns

Investigate the selected PCAP and return exact frames, flows, protocol behavior, timing, coverage, and uncertainty.

Representative products

Different jobs. One clean handoff.

These are representative ecosystem products, not partner badges or certification claims. Capabilities and packet access vary by edition, license, deployment, and configuration.

Vendor / productPrimary rolePacket boundaryFitPacketSafari value

Cloud risk, posture, findings, and threat context

Finding and resource context; raw PCAP requires a separate acquisition path.

Complementary

Use the finding, resource, and time window to scope the packet question.

Google CloudCloud Audit Logs

Administrative and data-access audit trail

Control-plane and service events, not packet contents.

Complementary

Correlate configuration or identity changes with observed network behavior.

Google CloudCloud Monitoring

Metrics, alerting, uptime, and operational symptoms

Time-series and service context rather than packet evidence.

Complementary

Use the symptom and interval to select the relevant capture window.

Google CloudVPC Flow Logs

Connection metadata for VPC traffic

Aggregated flow records; not raw packets or payloads.

Complementary

Identify peers, ports, direction, and time before deeper packet acquisition.

Google CloudPacket Mirroring

Out-of-band traffic mirroring to collector instances

Creates packet copies that a collector can store as PCAP.

Strong handoff

Supply an authorized, filtered incident window for PacketSafari investigation.

Google CloudCloud IDS

Managed network threat detection

Threat findings from mirrored traffic; packet export is a separate workflow.

Complementary

Investigate the packet exchange behind a selected IDS finding.

SIEM, threat intelligence, and security operations

Cases, events, and telemetry; PCAP requires an acquisition source.

Complementary

Return packet-grounded conclusions to the investigation case.

Decision guide

Use each layer for the decision it owns.

PacketSafari adds depth after a capture exists. It does not become the continuous monitor, enforcement point, access broker, packet broker, or recorder.

Do you only need connection metadata?

Use VPC Flow Logs. They are strong scoping evidence but are not a PCAP.

Do you need packet contents and exact timing?

Use Packet Mirroring or a workload capture to create the bounded PCAP.

Do you need continuous cloud detection?

Keep Security Command Center, Cloud IDS, and Google Security Operations as the detection and case layers.