Private plans for sensitive captures

Analyze PCAP online in minutes.

Free and public for sanitized captures. Private for incident, client, and internal traffic.

Upload a .pcap or .pcapng. A-Packets reads the whole capture and hands back what it found - hosts, sessions, credentials, files, anomalies - before you’ve decided what to look for.

Free · no signup · your result page is public

364,562 PCAPs analyzed

Captures with credentials, internal hosts, or incident evidence belong in a private plan or an on-prem deployment, not in the public flow.

What You Get

Get to the useful parts of a capture faster

Triage is where the time goes: hours spent finding out whether a capture holds anything worth investigating. A-Packets answers that in minutes.

Reconstruct HTTP Sessions

Inspect requests, responses, headers, forms, and transferred content without stepping through raw packets one by one.

Read more

Use this to review suspicious web traffic, rebuild client-server exchanges, and move from packet capture to analyst-readable evidence faster.

When you need to verify form submissions, web payloads, or transferred documents, the session view gives you a shorter path than raw Wireshark drilling.

Map Hosts and Services

See which hosts communicated, which services were exposed, and where to focus next during triage.

Read more

Classify nodes, review TCP and UDP communication patterns, and identify infrastructure roles from the capture itself.

Use passive fingerprints and protocol hints to spot DNS, DHCP, LDAP, and other service activity without building manual host inventories.

The graph view is useful when the question is not "what packet is this?" but "which systems were involved and how are they related?"

Review Wireless Artifacts

Extract SSIDs, probe requests, multicast patterns, and handshake artifacts from wireless captures.

Read more

Use the wireless view to separate infrastructure noise from useful evidence and identify what access points and client probes were present in the trace.

Detected WPA/WPA2 handshakes can be exported to .hccapx for offline recovery workflows with Hashcat.

Extract Files and Payloads

Pull images, documents, and transferred payload artifacts out of HTTP flows without rebuilding them manually.

Read more

Use quick previews to confirm whether the capture contains useful artifacts before you spend time on deeper manual analysis.

This is especially useful for phishing reviews, malware delivery checks, or any case where the question is "what actually moved over the wire?"

Find Credential Exposure

Scan the capture for plaintext credentials, auth material, and challenge-response artifacts across common protocols.

Read more

Useful for confirming whether a capture contains credential leakage worth escalating. The analyzer also looks for challenge-based authentication artifacts that may matter during DFIR and credential exposure reviews.

  • HTTP Basic/Digest
  • SIP Digest & SMB
  • NTLMv1/v2
  • Kerberos & LDAP
  • Postgres & MSSQL
  • Telnet/FTP

Spot Triage-Worthy Events

Identify suspicious patterns such as scans, insecure credential use, and other anomalies that deserve analyst attention.

Read more

Event detection is useful when you want the product to highlight likely starting points instead of manually hunting through the full trace first.

For recurring team use, this becomes more valuable in private plans where sensitive captures and ongoing incident work should not sit in a public result feed.

Working with sensitive captures? See private plans → to keep results out of the public feed.

Frequently Asked Questions

The main questions are usually about privacy, public vs private analysis, and what public analysis is actually for.

When should I use public analysis?
Use public analysis for sanitized PCAPs, product evaluation, labs, and non-sensitive traces. It is free and needs no registration, but it is limited to 25 MB per upload and creates a public result page.
What if the PCAP contains internal or sensitive data?
Do not use public analysis for captures that include credentials, internal hosts, customer traffic, or active incident evidence. Use a private plan or on-prem deployment if the data should stay private.
What file formats does A-Packets support?
Currently, our engine effectively processes native .pcap and .pcapng file structures generated by standard capture suites (Wireshark, tcpdump, etc.). Need help? Follow our Upload instructions.
How do I choose between Packs, subscriptions, and on-prem?
Use Packs for one-off sensitive cases, subscriptions for recurring SOC or DFIR work, and on-prem when packet captures cannot leave your environment.

Analyze your first PCAP in under a minute.

Free and public for sanitized captures. Private plans for incident data, client traffic, and anything that shouldn't be public.