Networking

PCAP Conversation Analyzer

Drop in a capture from tcpdump, tshark or Wireshark and get the picture those tools bury in a packet list: a map of who talked to whom, how much moved in each direction, which services were involved and which connections never completed. The file is read in this tab — it is never uploaded.

Capture file

Reading a capture honestly

  • A capture only knows what passed its interface. Taken on a laptop it sees that laptop; taken on a switch port without a mirror it sees broadcast and little else. If a host you expected is missing, suspect the capture point before you suspect the network.
  • Encrypted means encrypted. For TLS, this page can tell you who was contacted and how much moved, because the addresses, ports and the server_name in the handshake are in the clear. It cannot tell you what was said.
  • Byte counts use the on-the-wire length. If you captured with a snap length, payloads are cut short but the volume figures are still right — only the payload details, such as TLS SNI, go missing. Capture with -s 0 when you care about those.
  • NAT hides the real endpoints. Capture outside a NAT and every host behind it collapses into one address. The conversation map is drawn from what the packets say, not from what the topology is.

Runs entirely in your browser — nothing you type here is uploaded, logged or stored. Privacy policy