REDMARK FORGE SANDBOX
Parse · Filter · Investigate

Protocol & Packet Lab

Offline classic-PCAP parser for Ethernet, IPv4/IPv6, TCP/UDP and basic DNS/HTTP indicators. Filter packet lists, inspect bounded payload previews and export CSV/JSON.

Scope: offline analysis only; no live capture, packet injection, decryption or reassembly. Currently supports classic PCAP with Ethernet link type; PCAPNG and other link types are rejected explicitly.

01 · Load a packet capture

Classic PCAP parser; Ethernet link type. PCAPNG and live capture are not supported.

Capture stays local. Packet payloads are not sent anywhere.
Packets parsed—
Capture bytes—
Link type—
IPv4—
TCP—
UDP—

02 · Filter & search

Filter protocol, source/destination, port, text and minimum packet length.

No capture loaded.

03 · Packet list

Click a packet to inspect its decoded header and bounded payload preview.

#Time (s)LengthProtocolSourceDestinationInfo
No packets parsed.
Select a packet row.

05 · Enhanced analysis: classic PCAP and PCAPNG, more link types, statistics

Re-reads the file chosen in panel 01 with a wider parser: PCAP + PCAPNG, Ethernet, Linux cooked (SLL), raw IP and loopback captures, VLAN, IPv6 extension headers. Adds protocol hierarchy, top talkers, packet-rate timeline and a size histogram.

No capture loaded.
Results appear here.

06 · Conversations & security findings

Flow table (5-tuple) with bytes, duration and TCP flags, plus heuristics for cleartext credentials, scans, ARP spoofing, DNS tunnelling, ICMP tunnels, beaconing and legacy TLS.

Results appear here.

07 · Application-layer view

Decoded DNS queries/answers, HTTP requests, TLS SNI, DHCP leases and ARP mappings across the whole capture.

Results appear here.

08 · Follow TCP stream & extract HTTP objects

Reassembles streams by sequence number (handles reordering and retransmits), shows both directions and carves HTTP bodies (Content-Length, chunked, gzip).

Analyze a capture first, then pick a stream.

09 · Packet builder, PCAP writer & hex dissector

Craft Ethernet/IPv4 packets with correct checksums, collect them into a capture, download a real PCAP and analyze it above. Or paste a hex dump (tcpdump -X, Wireshark hex, raw hex) to see its layers.

Built packets appear here with their layer decode.
Results appear here.