Enterprise packet investigation · stack architecture
Keep the tools that watch. Add the system that investigates.
Cloud detections, EDR, XDR, NDR, firewalls, flow logs, and observability tools tell you where to look. Capture the relevant traffic, then use PacketSafari to determine what the packets support.
PacketSafari is not a continuous monitor, endpoint agent, packet broker, policy engine, or inline enforcement product.
Analysis result out
- Preliminary
- Verification
- Final Report
- Always onmonitor · detect · enforce
- Incident windowcapture · retain · export
- PacketSafariinvestigate · verify · report
Same stack · different jobs
One and the other. Not one or the other.
The architecture becomes clear when each product is judged by the evidence it creates and the decision it owns.
Live controls
EDR · NDR · firewall · SASE · cloud detectionContinuously observe, decide, enforce, alert, and respond.
May retain telemetry, metadata, or selected packets.
Traffic access
Cloud mirror · Network Watcher · SPAN · TAP · packet brokerCopy and route the relevant traffic without becoming the investigation.
Produces or feeds the bounded packet capture.
PacketSafari
Core Engine · Triage · Agent · VerificationInvestigate the selected PCAP and keep conclusions attached to exact evidence.
Consumes PCAP; does not replace the sensor or enforcement plane.
Response owner
SOC · network · application · cloud · vendorChange policy, contain an endpoint, fix the service, or escalate with proof.
Receives frames, filters, flows, timestamps, coverage, and uncertainty.
The user workflow
The alert is context. The capture is evidence.
Start with the operator's question, acquire the smallest useful packet window, then return an answer to the team that can act.
A tool or user raises a question.
Suspicious host, blocked session, failed transaction, latency spike, reset, or disputed ownership.
Capture the relevant boundary.
Cloud mirror, Network Watcher, host capture, SPAN, TAP, packet broker, or historical recorder.
PacketSafari tests the hypothesis.
Preliminary direction stays separate from independent Verification and the Final Report.
Return proof to the owner.
Frames, filters, flows, timestamps, decoded fields, coverage, uncertainty, and the next evidence.
Technical layers
A clean place in a crowded ecosystem.
Product names are representative context, not partner badges or integration claims. Each dedicated workflow is validated before stronger wording is used.
Signal and scope
GuardDuty · Defender XDR · CrowdStrike Falcon · Vectra · Splunk · Nozomi · Dragos · Defender for IoTUse the finding, entity, asset, time, flow, or operational symptom to define the packet question.
Enforce and inspect
Palo Alto · Fortinet · Check Point · Cisco Secure Firewall · Zscaler · Netskope · Prisma AccessKeep the policy and enforcement product. Capture at an authorized boundary when the decision needs packet proof.
Acquire and distribute
Cloud mirror · vSwitch · virtual TAP · SPAN · Gigamon · Keysight · Profitap · Garland · APCONThis is the strongest handoff: copy, filter, route, and retain the traffic PacketSafari will investigate.
Retain and retrieve
Endace · VIAVI GigaStor · Allegro · Profitap IOTA · Arkime · LiveAction · NETSCOUTSearch the incident window and export the smallest authoritative PCAP.
Inspect and collaborate
Wireshark · tshark · Zeek · Suricata · Snort · NetworkMiner · CloudSharkUse specialist tools when needed; PacketSafari adds capture-wide triage, guided investigation, Verification, and a reviewable report.
Enterprise boundary
Sensitive packets need an explicit path.
Authority, minimization, capture location, retention, AI routing, egress, and deletion are part of the investigation design, not fine print after upload.
Explore controlled deploymentBring the alert and the capture path

