Move sensitive captures into analysis sooner

AI packet analysis can help investigate a capture, but raw PCAPs often contain subscriber IDs, hostnames, IPs, MACs, SIP/IMS identifiers, device names, credentials, and customer topology.

anoncap creates a safer sibling capture while leaving the original untouched. The anonymized copy preserves useful diagnostic structure so Agent, Copilot, vendors, customers, and reviewers can work from packet evidence with less exposure of raw identifiers.

Choose a packet case
Public rules and private profiles use the same evidence view.
Public-share
Original PCAP Frame 1482 • VLAN / VXLAN / IPv4 / TCP / HTTP
Public-share output

Before public-share

A tunneled request still carries customer addresses, hostnames, and application payload bytes.

After public-share

Identifiers are deterministically replaced and supported headers remain readable while unsupported payload is truncated.

Packet bytes
Hex + ASCII
0010
81 00 00 6408 00 45 00 01 4a 31 44 40 00 40 1112 b5 12 b5 08 00 00 00 00 12 34
vlan 100vxlan vni 0x1234
0030
45 00 00 f4 7a 21 40 00 40 060a 14 2c 11c6 33 64 18
inner ipv4 10.20.44.17 -> 198.51.100.24
0050
47 45 54 20 2f 61 70 69 2f 76 31 2f 75 73 65 7248 6f 73 74 3a 2061 70 69 2e 63 75 73 74 6f 6d 65 72 2d 65 64 67 65
GET /api/v1/user Host: api.customer-edge
0070
0d 0a 0d 0a 7b 22 73 75 62 73 63 72 69 62 65 72 22 3a22 34 39 31 37 32 30 30 30 31 32 33 34 22
{"subscriber":"491720001234"
0080
2c 22 74 6f 6b 65 6e 22 3a22 6c 69 76 65 2d 64 65 6d 6f 2d 37 66 33 63 39 61 22
,"token":"live-demo-7f3c9a"
Packet details
Decoded fields
outer tunnel
vlan.id 100 + vxlan.vni 0x1234
ipv4.src -> ipv4.dst
10.20.44.17 -> 198.51.100.24
http.host
api.customer-edge.invalid
payload policy
captured JSON body retained
Packet bytes
Hex + ASCII
0010
81 00 00 6408 00 45 00 00 b0 31 44 40 00 40 1112 b5 12 b5 08 00 00 00 00 12 34
vlan 100vxlan vni 0x1234
0030
45 00 00 64 7a 21 40 00 40 060a cb 2c 11cb 00 71 58
inner ipv4 10.203.44.17 -> 203.0.113.88
0050
47 45 54 20 2f 61 70 69 2f 76 31 2f 75 73 65 7248 6f 73 74 3a 2061 70 69 2e 70 73 66 2d 61 6e 6f 6e
GET /api/v1/user Host: api.psf-anon
0070
0d 0a 0d 0a[payload bytes removed]
HTTP body: [JSON removed]
0080
[no L7 tail bytes emitted]
[subscriber/token removed]
Packet details
Decoded fields
outer tunnel
vlan.id 100 + vxlan.vni 0x1234
ipv4.src -> ipv4.dst
10.203.44.17 -> 203.0.113.88
http.host
api.psf-anon.invalid
payload policy
inner headers kept; L7 JSON removed
Drag
Choose the operating boundary

Run locally. Scale privately.

Use the open-source CLI to create a local anonymized sibling capture, or evaluate PacketSafari's private profile when production captures need broader protocol tuning, managed workflow, and customer-controlled deployment.

Quick usage

Default public-share command

Create a local sibling capture with the public sharing baseline.

./bin/anoncap --public-share input.pcapng
./bin/anoncap --explain-defaults
./bin/anoncap --paranoid input.pcapng --report anon.report.json

`--public-share` writes `input-anon.pcapng` by default. Add `-w output.pcapng` to choose a name, or `--overwrite` to replace an existing output.

Detailed usage

Enterprise anonymization

Keep the capture useful.
Keep identifiers out.

Extend the open-source baseline with PacketSafari-maintained profiles for sensitive production and telecom captures.

Compare deployment options
Review protocol coverage

Learn more