Analyze PCAP online in minutes.
Free and public for sanitized captures. Private for incident, client, and internal traffic.
Upload a .pcap or .pcapng. A-Packets reads the whole capture and hands back what it found - hosts, sessions, credentials, files, anomalies - before you’ve decided what to look for.
Free · no signup · your result page is public
Captures with credentials, internal hosts, or incident evidence belong in a private plan or an on-prem deployment, not in the public flow.
Analysis Modes
Pick the mode that fits the capture
Use public analysis for sanitized PCAPs, private plans for sensitive data, and on-prem when captures cannot leave your environment.
Public analysis
Best for sanitized traces, product evaluation, labs, and quick checks where a public result page is acceptable.
- No signup required
- Upload and inspect results immediately
- 25 MB limit on free uploads
Private analysis
Use Packs or Workspace plans when the capture includes internal hosts, credentials, customer traffic, or active incident evidence.
- Results stay out of the public feed
- Built for SOC, DFIR, and consulting teams
- Good fit for recurring teams and one-off sensitive cases
On-prem deployment
For teams whose captures and evidence cannot leave their own infrastructure.
- Captures never leave your network
- Built for regulated environments and evidence handling
- Good fit for air-gapped and isolated networks
What You Get
Get to the useful parts of a capture faster
Triage is where the time goes: hours spent finding out whether a capture holds anything worth investigating. A-Packets answers that in minutes.
Reconstruct HTTP Sessions
Inspect requests, responses, headers, forms, and transferred content without stepping through raw packets one by one.
Read more Show less
Use this to review suspicious web traffic, rebuild client-server exchanges, and move from packet capture to analyst-readable evidence faster.
When you need to verify form submissions, web payloads, or transferred documents, the session view gives you a shorter path than raw Wireshark drilling.
Map Hosts and Services
See which hosts communicated, which services were exposed, and where to focus next during triage.
Read more Show less
Classify nodes, review TCP and UDP communication patterns, and identify infrastructure roles from the capture itself.
Use passive fingerprints and protocol hints to spot DNS, DHCP, LDAP, and other service activity without building manual host inventories.
The graph view is useful when the question is not "what packet is this?" but "which systems were involved and how are they related?"
Review Wireless Artifacts
Extract SSIDs, probe requests, multicast patterns, and handshake artifacts from wireless captures.
Read more Show less
Use the wireless view to separate infrastructure noise from useful evidence and identify what access points and client probes were present in the trace.
Detected WPA/WPA2 handshakes can be exported to .hccapx for offline recovery
workflows with Hashcat.
Extract Files and Payloads
Pull images, documents, and transferred payload artifacts out of HTTP flows without rebuilding them manually.
Read more Show less
Use quick previews to confirm whether the capture contains useful artifacts before you spend time on deeper manual analysis.
This is especially useful for phishing reviews, malware delivery checks, or any case where the question is "what actually moved over the wire?"
Find Credential Exposure
Scan the capture for plaintext credentials, auth material, and challenge-response artifacts across common protocols.
Read more Show less
Useful for confirming whether a capture contains credential leakage worth escalating. The analyzer also looks for challenge-based authentication artifacts that may matter during DFIR and credential exposure reviews.
- HTTP Basic/Digest
- SIP Digest & SMB
- NTLMv1/v2
- Kerberos & LDAP
- Postgres & MSSQL
- Telnet/FTP
Spot Triage-Worthy Events
Identify suspicious patterns such as scans, insecure credential use, and other anomalies that deserve analyst attention.
Read more Show less
Event detection is useful when you want the product to highlight likely starting points instead of manually hunting through the full trace first.
For recurring team use, this becomes more valuable in private plans where sensitive captures and ongoing incident work should not sit in a public result feed.
Working with sensitive captures? See private plans → to keep results out of the public feed.
Frequently Asked Questions
The main questions are usually about privacy, public vs private analysis, and what public analysis is actually for.
When should I use public analysis?
What if the PCAP contains internal or sensitive data?
What file formats does A-Packets support?
Analyze your first PCAP in under a minute.
Free and public for sanitized captures. Private plans for incident data, client traffic, and anything that shouldn't be public.