Networking
PCAP Conversation Analyzer
Drop in a capture from tcpdump, tshark or Wireshark and get the picture those tools bury in a packet list: a map of who talked to whom, how much moved in each direction, which services were involved and which connections never completed. The file is read in this tab — it is never uploaded.
Capture file
Capture
Who is talking to whom
What the traffic actually is
What stands out
Conversations
| Host A | Host B | A → B | B → A | Packets | Total | Services | Duration |
|---|
Hosts
| Host | Where | Sent | Received | Packets | Peers | Serving on |
|---|
Services reached
| Service | Listening on | Clients | Packets | Bytes | Encrypted |
|---|
Names seen inside the capture
Read out of DNS answers, TLS server_name extensions and HTTP Host headers — no
lookups were performed.
| Name | Address | Learned from |
|---|
The same answers from tshark
Everything above comes from packet headers, so it has a command-line equivalent. These are the ones worth keeping in your notes.
Reading a capture honestly
- A capture only knows what passed its interface. Taken on a laptop it sees that laptop; taken on a switch port without a mirror it sees broadcast and little else. If a host you expected is missing, suspect the capture point before you suspect the network.
- Encrypted means encrypted. For TLS, this page can tell you who was contacted and how much
moved, because the addresses, ports and the
server_namein the handshake are in the clear. It cannot tell you what was said. - Byte counts use the on-the-wire length. If you captured with a snap length, payloads are cut
short but the volume figures are still right — only the payload details, such as TLS SNI, go missing. Capture
with
-s 0when you care about those. - NAT hides the real endpoints. Capture outside a NAT and every host behind it collapses into one address. The conversation map is drawn from what the packets say, not from what the topology is.
Runs entirely in your browser — nothing you type here is uploaded, logged or stored. Privacy policy