PacketSafari
Ecosystem overview

Multi-cloud and regional cloud investigation

Keep Oracle, Alibaba, and regional cloud controls. Use one evidence workflow.

Oracle Cloud, Alibaba Cloud and European providers expose different combinations of flow logs, audit events, traffic mirroring and workload access. PacketSafari provides a consistent investigation layer once an authorized PCAP has been acquired.

Oracle, Alibaba & European cloudsContext → capture → investigation
Scope
VTAPVCN Flow LogsVPC Traffic MirroringVPC Flow Logs, ActionTrail & CloudMonitor
AcquireNative mirror · vTAP · workload captureauthorized incident PCAP
InvestigatePacketSafariCore Engine · Agent · report
Result outExact evidence returns to the team that can act.
Category owns

Host workloads, provide virtual networking, enforce cloud policy, and expose provider-specific logs, metrics, audit trails, and visibility features.

Acquisition path

Prefer native mirroring when documented. Otherwise use host capture, a virtual TAP or sensor, a network appliance, Kubernetes capture, or an existing recorder inside the authorized customer boundary.

PacketSafari owns

Normalize the investigation workflow after acquisition: map the PCAP, test the question, verify the conclusion, and hand over reviewable evidence.

Representative products

Different jobs. One clean handoff.

These are representative ecosystem products, not partner badges or certification claims. Capabilities and packet access vary by edition, license, deployment, and configuration.

Vendor / productPrimary rolePacket boundaryFitPacketSafari value
Oracle Cloud InfrastructureVTAP

Virtual traffic mirroring for VNIC and load-balancer paths

Copies filtered traffic to a collector for full-packet capture.

Strong handoff

Use the VTAP collector to create the bounded PCAP PacketSafari investigates.

Oracle Cloud InfrastructureVCN Flow Logs

Network-flow metadata and accept/reject context

Flow records rather than packet contents.

Complementary

Scope the VCN, VNIC, peers, ports, and incident window before capture.

Filtered ENI traffic mirroring over VXLAN

Copies packets to a collector ENI, load balancer, or GWLB endpoint.

Strong handoff

Create a PCAP at the collector and investigate the selected incident window.

Flow metadata, audit events, metrics, and operational scope

Context and connection metadata; not a raw packet capture.

Complementary

Use provider context to identify what, where, and when to capture.

European public-cloud compute and private networking

Confirm native visibility for the selected service; host or virtual-sensor capture may be required.

Architecture-dependent

Keep packet processing within the approved European or customer-controlled boundary.

European cloud compute, private networks, and containers

Capture may be taken from the workload, node, cluster, or approved virtual appliance.

Architecture-dependent

Apply the same PCAP investigation workflow without assuming AWS-style mirroring.

European cloud compute and private networking

Workload or virtual-sensor capture is the conservative acquisition path.

Architecture-dependent

Investigate locally acquired PCAPs while preserving residency requirements.

Open Telekom CloudVirtual Private Cloud

European sovereign-oriented cloud networking

Use documented flow visibility where available and capture from an authorized workload or sensor for PCAP.

Architecture-dependent

Maintain a consistent evidence output across regulated cloud environments.

European cloud compute and private networking

Host, appliance, or cluster capture may be required for raw packet evidence.

Architecture-dependent

Bring the resulting bounded PCAP into a repeatable investigation workflow.

Distributed compute, networking, and Kubernetes

Use workload, node, or approved sensor capture when raw packets are required.

Architecture-dependent

Separate cloud acquisition from PacketSafari analysis and reporting.

Decision guide

Use each layer for the decision it owns.

PacketSafari adds depth after a capture exists. It does not become the continuous monitor, enforcement point, access broker, packet broker, or recorder.

Does the provider offer native traffic mirroring?

Use it when the source, destination, region, performance, and policy constraints fit the incident.

Is only flow metadata available?

Use it to scope the question, then capture at the workload, node, appliance, or adjacent authorized boundary.

Does the client require European or sovereign processing?

Run the capture and PacketSafari deployment path inside the approved region or customer-controlled environment.