Protocol & Packet Lab
Offline classic-PCAP parser for Ethernet, IPv4/IPv6, TCP/UDP and basic DNS/HTTP indicators. Filter packet lists, inspect bounded payload previews and export CSV/JSON.
01 · Load a packet capture
Classic PCAP parser; Ethernet link type. PCAPNG and live capture are not supported.
02 · Filter & search
Filter protocol, source/destination, port, text and minimum packet length.
03 · Packet list
Click a packet to inspect its decoded header and bounded payload preview.
| # | Time (s) | Length | Protocol | Source | Destination | Info |
|---|---|---|---|---|---|---|
| No packets parsed. | ||||||
05 · Enhanced analysis: classic PCAP and PCAPNG, more link types, statistics
Re-reads the file chosen in panel 01 with a wider parser: PCAP + PCAPNG, Ethernet, Linux cooked (SLL), raw IP and loopback captures, VLAN, IPv6 extension headers. Adds protocol hierarchy, top talkers, packet-rate timeline and a size histogram.
06 · Conversations & security findings
Flow table (5-tuple) with bytes, duration and TCP flags, plus heuristics for cleartext credentials, scans, ARP spoofing, DNS tunnelling, ICMP tunnels, beaconing and legacy TLS.
07 · Application-layer view
Decoded DNS queries/answers, HTTP requests, TLS SNI, DHCP leases and ARP mappings across the whole capture.
08 · Follow TCP stream & extract HTTP objects
Reassembles streams by sequence number (handles reordering and retransmits), shows both directions and carves HTTP bodies (Content-Length, chunked, gzip).
09 · Packet builder, PCAP writer & hex dissector
Craft Ethernet/IPv4 packets with correct checksums, collect them into a capture, download a real PCAP and analyze it above. Or paste a hex dump (tcpdump -X, Wireshark hex, raw hex) to see its layers.