About

Packets don’t lie

If one thing has stayed true throughout my career, it’s this: packet-level data provides the most granular insight into network communication — whether you’re chasing an elusive network problem or reconstructing a security breach.

I’m Walter Hofstetter, a security analyst and packet whisperer based in Zürich. My journey with packets began at Network General Corporation, the makers of the legendary Sniffer Network Analyzer. From there I moved through technical roles at Network Associates, Symantec, and Palo Alto Networks, and today I work as a consultant for Anyweb, a fantastic Swiss company. Whatever role I’ve held along the way — instructor, consultant, workshop lead, speaker — I’ve always kept an eye on the packets.

Forensic packet analysis — a flagged connection under a scope
What I do

Teaching, tools, and talking shop

Teaching

The Packet Factor

A hands-on two-day training on analyzing network traffic from a security perspective. Beyond Wireshark, we work with a range of open-source tools, look at attacks from the attacker’s point of view, and learn to read the traces they leave on the wire. Available on demand — see my Training page or book through anyweb-training.ch.

Speaking & consulting

Talks & workshops

I regularly give talks and run workshops on packet analysis and security analytics. A few recent examples:

  • TEFO (Technologie Forum) 2025 — “Einsatz von KI für Netzwerk- und Security-Analyse”
  • SharkFest ’24 Vienna — “Unlocking Security Insights: Wireshark Techniques for Security Analysts”
  • Packet Fest ’25 — “Decoding Cyber Threats: Wireshark Tips and Tricks for Analyzing Suspicious Traffic Patterns”

Building tools

Motivation & community

I’ve benefited from open-source tools and the community my entire professional life, so giving something back matters to me. AI assistants now take care of the low-level coding, letting me focus on workflows and data modelling. As my paid work winds down, this shifts from a side project into something closer to volunteer work — driven by curiosity about packets, not a business.

On GitHub

A few highlights

PacketCircle C · Swift

My favourite: traffic-matrix visualisation, available as a native Wireshark plugin and as a native app for iOS and macOS.

github.com/netwho/PacketCircle →

PacketReporterPro C

Native reporting plugin for Wireshark — turns a capture into a professional PDF report.

github.com/netwho/PacketReporterPro →

PacketSanitizerPro C

Sanitize PCAP/PCAPNG files for safe sharing outside your organization.

github.com/netwho/PacketSanitizerPro →

ASK — Analyst’s Shark Knife Lua

A multi-tool for packet analysts, right-click included.

github.com/netwho/ASK →

Vulnerability Correlator Lua

Correlate observed traffic with known vulnerabilities, right inside Wireshark.

github.com/netwho/Vulneariblity-Correlator →
Wire-first cyber defense — protocol streams between two hosts
Wire-First Cyber Defense

The packets are the witness that never lies

Attackers can delete logs, disable agents, and hide from endpoint tools — but they can’t avoid the network. Every scan, exploit, and exfiltration leaves traces in the packets. That’s why I approach cybersecurity wire-first: capture the traffic, correlate it with threat intelligence, and let the evidence tell the story of a breach.

Whether it’s hunting malicious behavior in live traffic or reconstructing an incident from a trace file, the packets are the witness that never lies.

Looking ahead

My paid professional life is winding down — I’ve reduced my working time to 60%, which is why my projects don’t take years to finish ;-). After retirement I plan to continue volunteering, in tech and beyond. But as long as I stay curious about packets — and I don’t see that changing — this work will continue.