PacketSafari

Enterprise packet investigation · Security

Investigate suspicious traffic. Prove it in the packets.

Upload a PCAP and combine signatures, offline threat intelligence, behavioral C2, tunnels, attack paths, and east-west findings with explicit coverage and exact packet evidence. PacketSafari complements live NDR, EDR, and XDR. It is not a continuous network monitor.

If the question is whether a firewall, IDS, IPS, proxy, or VPN action actually worked, use Security Control Validation.

PacketSafari security · Security investigationdns-tunnel-iodine.pcap

Capture evidence available

Current evidence candidate

Encoded TXT queries form a sustained outbound transfer pattern.

Signal
Long labels · small replies · steady retries
Detector
Deterministic DNS behavior
Coverage
Complete capture evidence
Evidence
Frames 104–402
dns.qry.type == 16 && ip.addr == 10.12.4.18

Contain 10.12.4.18 and investigate the queried domain.

Threat evidence workbench with selectable detection views.

Living off the Network

Attackers stay off the endpoint. The network still records the path.

Advanced actors increasingly target firewalls, VPN appliances, hypervisors, IoT, cameras, VoIP, and infrastructure where EDR cannot run or has weak visibility. Compromised systems become bridges through trusted protocols and encrypted paths.

Endpoint-visibleEDR coverage
Workstation Server Admin host
Endpoint blind spotPacket visibility matters
Firewall / VPN Hypervisor Camera / IoT VoIP
  1. 1Internet
  2. 2VPN edge
  3. 3Management plane
  4. 4Internal service
PacketSafari evidenceNetwork path reconstructed
  • IDS match
  • Unexpected management connection
  • New internal target
  • Exact packet pivots

Explanatory attack paths, not customer findings. Packet evidence complements endpoint and infrastructure telemetry.

Explanatory map contrasting EDR-covered endpoints with network-device blind spots and the packet evidence preserved along four modern attack paths.

SSH and SOCKS pivots

SMB, DCERPC, RDP, WinRM, and WMI

DNS, VPN, and encrypted sessions

Packet evidence beside endpoint telemetry

Security proof, counted

Ten named paths. One defensible investigation.

The PacketSafari Core Engine finds and preserves deterministic evidence. Agent focuses the investigation, explains the result, and guides the analyst back to exact packets.

54k+
Loaded signaturesSuricata-compatible signatures in the last qualified production profile.
27k+
ATT&CK-enrichedActive-feed signatures carrying MITRE ATT&CK metadata.
10
Named evidence pathsNine available paths plus one explicitly qualification-only cadence lead.
30
Triage ModulesRelevant deterministic modules activate for supported traffic in the capture.
150+
Curated investigationsExpert-reviewed PCAP investigations and protocol playbooks.
20+ years
Analysis experiencePractical packet and network-analysis experience shaping the workflow.

The 54k+ and 27k+ claims remain the last qualified PacketSafari production-profile counts. Feed revisions and compatibility filtering can change both counts. Payload cadence remains qualification-only.

Investigation layers

Three evidence paths. One packet-grounded conclusion.

Signatures, packet behavior, and cross-connection correlation stay distinct until the evidence supports a shared finding.

Signatures and intelligence

Known indicators retain their source, revision, coverage, and exact packet or connection pivot.

  • Suricata-compatible signature detection
  • Stamus east-west and lateral-movement rules
  • Offline IP, network, domain, URL, and file-hash intelligence
Behavior and attack paths

Independent packet behavior finds suspicious activity that a signature-only review can miss.

  • Behavioral and periodic C2 detection
  • DNS tunnel and covert-channel analysis
  • Active Directory and RDP proxy attack-path correlation
  • Aggregate scan and flood detection
  • OT command anomalies
Correlation and qualification

Cross-connection findings remain reviewable while emerging signals stay clearly qualified.

  • Exact east-west findings with bounded packet pivots
  • Payload-cadence leads: qualification only

Security Triage

Mixed attack evidence in one prioritized view

PacketSafari UI
PacketSafari Security overview showing ARP poisoning, NTLM relay, GPO startup-script deployment, Domain Admin persistence, and periodic command-and-control evidence View full size
Stateful poisoning, behavioral lateral movement, Active Directory persistence, and periodic C2 findings remain distinct, ranked, and tied to retained evidence. Only private lab identifiers are visible.

Prove the business case

Measure the reduction during evaluation.

Compare the team’s current investigation baseline with the same captures and questions in PacketSafari. No invented “faster” percentage.

  1. Time to first defensible finding
  2. Analyst minutes to validate a candidate
  3. Manual packet pivots avoided
  4. Escalation cycles reduced
  5. Verifier disposition and evidence acceptance

Detection foundation

Fast direction when needed. Complete coverage when required.

The PacketSafari Core Engine combines deterministic packet processing with AI investigation. It does not replace required IDS or behavioral processing with a model guess.

  1. Every-packet IDS

    Choose quick partial screening or a separately tracked complete-capture verification milestone.

  2. Behavior over signatures

    Correlate beaconing, DNS tunnels, covert channels, scans, lateral movement, and suspicious connection behavior.

  3. Reproducible intelligence

    Preserve local, ET Open, Stamus, and enabled Abuse.ch source provenance, revision, severity, and exact alerts.

  4. Truthful coverage

    Clean, partial, unavailable, and failed outcomes stay distinct; missing evidence never becomes a clean scan.

30,000+PCAPs across the full corpus

PacketSafari trains and tests its Agent on 150+ expert-curated PCAP investigations and protocol playbooks, shaped by 20+ years of real-world packet analysis.

Periodic beaconing findings are reported with supporting packet evidence and explicit coverage limits.