Analyzer overview
The analyzer workspace is organized around tabs and specialist views. The exact set depends on the protocols found in the capture, indexing progress, and the capabilities enabled for your account and deployment.
Core tabs
- Packets: filter bar, packet list, packet hotspots, decode, hex, RFC context, follow stream, and decode overrides.
- Connections: aggregated conversations, timelines, protocol mix, deep connection insights, and capture-point pivots.
- Stats: ranked rule matches, packet hotspots for bounded evidence ranges, correlated connection and call issues, endpoint and conversation summaries, protocol hierarchy, and exported objects.
- Summary: capture metadata, ownership, comments, tags, and upload/indexing context.
The workspace is also lifecycle-aware. A capture can be:
- open ready, meaning packet view is available
- refining, meaning background analysis is still running
- complete, meaning all required work for the current generation is finished
Specialist tabs
- Security: Suricata-based alert summaries, severity counts, detector coverage, and IOC export.
- Names: DNS-focused pivots for hostnames, resolver posture, and name-resolution behavior.
- TLS: encrypted-traffic summaries, SNI/certificate context, and TLS-focused pivots.
- Infrastructure: inferred hosts, roles, links, subnets, and service-role signals.
- Files: extracted objects and related evidence artifacts when supported by the capture.
- OT: industrial-protocol semantic mapping, signal timelines, and OT event stories.
- VoIP: RTP and telephony-focused media troubleshooting.
- Telco: telecom signaling correlations, grouped dialogs, and ladder views.
- Wi-Fi and Multicast: protocol-specific dashboards that appear when the capture contains those signals.
AI helpers
- Quick Insights: the bounded first-pass AI brief with a mini report and next actions.
- Copilot: capture-aware chat and guided pivots.
- Agent: deeper automated investigation runs with evidence-backed findings.
- AI Analyses: shared history of Agent and Copilot work across captures.
- PacketSafari Triage: the non-AI evidence map that lets PacketSafari handle large PCAPs with right-sized rules, indexing, and derived artifacts.
- Investigation Path Guide: how to choose Fast answer, Fast + verification, or Triage then deep without confusing analysis depth with manual, Copilot, Agent, anoncap, or email choices.
- Sample Agent report and Demo Captures: a completed evidence-backed investigation and scenarios for validating the workflow before using production traces.
Processing awareness
The analyzer is designed to stay useful while indexing continues.
- The packet view can open before every heavy post-index step is done.
- Packet hotspots can appear as soon as PacketSafari has localized evidence ranges, even while broader analysis continues.
- Some dashboards can show provisional preview or sampled results before full coverage arrives.
- Expensive artifacts can be served from persisted cache, materialized on demand, or queued as follow-up work depending on capture size.
For those runtime details, see:
The header also gives quick access to PacketSafari Agent, time-range changes, and specialist tabs. The Misc menu contains shortcuts for Decode as, profile settings, saving selected packets, column autosizing, and dark mode. The older walkthrough-style Analyses workspace menu entry is currently hidden while that feature is paused.
Decode As
When a protocol is on a non-standard port, use Decode as to override decoding (for example RTP on an unusual UDP port). Once applied, the packet list, decode, and graphs reflect the new interpretation.
Dark Mode
A dark theme is available from the action menu if you prefer low-glare viewing.
