I’m Walter Hofstetter, a security analyst and packet whisperer based in Zürich. My journey with packets began at Network General Corporation, the makers of the legendary Sniffer Network Analyzer. From there I moved through technical roles at Network Associates, Symantec, and Palo Alto Networks, and today I work as a consultant for Anyweb, a fantastic Swiss company. Whatever role I’ve held along the way — instructor, consultant, workshop lead, speaker — I’ve always kept an eye on the packets.
The Packet Factor
A hands-on two-day training on analyzing network traffic from a security perspective. Beyond Wireshark, we work with a range of open-source tools, look at attacks from the attacker’s point of view, and learn to read the traces they leave on the wire. Available on demand — see my Training page or book through anyweb-training.ch.
Talks & workshops
I regularly give talks and run workshops on packet analysis and security analytics. A few recent examples:
Motivation & community
I’ve benefited from open-source tools and the community my entire professional life, so giving something back matters to me. AI assistants now take care of the low-level coding, letting me focus on workflows and data modelling. As my paid work winds down, this shifts from a side project into something closer to volunteer work — driven by curiosity about packets, not a business.
My favourite: traffic-matrix visualisation, available as a native Wireshark plugin and as a native app for iOS and macOS.
github.com/netwho/PacketCircle →Native reporting plugin for Wireshark — turns a capture into a professional PDF report.
github.com/netwho/PacketReporterPro →Sanitize PCAP/PCAPNG files for safe sharing outside your organization.
github.com/netwho/PacketSanitizerPro →A multi-tool for packet analysts, right-click included.
github.com/netwho/ASK →Correlate observed traffic with known vulnerabilities, right inside Wireshark.
github.com/netwho/Vulneariblity-Correlator →
Attackers can delete logs, disable agents, and hide from endpoint tools — but they can’t avoid the network. Every scan, exploit, and exfiltration leaves traces in the packets. That’s why I approach cybersecurity wire-first: capture the traffic, correlate it with threat intelligence, and let the evidence tell the story of a breach.
Whether it’s hunting malicious behavior in live traffic or reconstructing an incident from a trace file, the packets are the witness that never lies.
My paid professional life is winding down — I’ve reduced my working time to 60%, which is why my projects don’t take years to finish ;-). After retirement I plan to continue volunteering, in tech and beyond. But as long as I stay curious about packets — and I don’t see that changing — this work will continue.