LOCAL NETWORK FORENSICS

See which apps appear in a capture

Inspect an authorized PCAP or enrich a correlation JSON request with evidence-backed app identifiers. Sign in with your approved Google account to access the analyser.

QUICK GUIDE

From capture to evidence in three steps

01

Select a file

Choose an authorized .pcap, .pcapng, .net Snoop capture, or correlation .json file.

02

Select the operating system

Choose iOS, Android, or Unknown. We select a likely option from visible network signals, and you can change it before analysis.

03

Review the evidence

Compare suggested apps, confidence, identification method, activity timestamps, domains, request order, and directly visible identifiers.

TRY A REAL EXAMPLE

Inspect the capture and compare the report

Download a real capture, explore it in PCAP Analyser, and compare your findings with the example report.

PCAP

Example capture

Explore real iPhone network activity and discover what PCAP Analyser can reveal.

Download PCAP
REPORT

Example analysis

See how PCAP Analyser turns network activity into clear, evidence-backed results.

View report

PRIVATE BY DESIGN

Your capture stays in the analysis environment

Uploaded PCAP and JSON files are used only for the requested analysis. They are not retained or shared and are deleted after analysis, cancellation, or failure.

Downloadable reports are generated on demand and are not retained or shared by the service. Results are estimates: encrypted or shared background traffic can affect accuracy.