netwho · Packet Notes
Updates & Blogs · Article

PacketCircle for iPhone: your PCAPs as a circle, in your pocket, for free

Native Swift. Offline PCAP/PCAPNG. No ads, no subscriptions, no telemetry — and yes, no live sniffing (I’ll explain why).

Walter Hofstetter · August 2026

Free No ads No telemetry Offline-first
PacketCircle for iOS 1.2.5 is now live on the App Store. Download it here →

It (still) starts with a circle

I have a mildly unreasonable love for one idea: draw network conversations as a circle. Who talks to whom, which protocols, which edges run hot. Last year that turned into PacketCircle, an open-source Wireshark plugin. The mental model never let go of me — once you see traffic as a ring of relationships, packet lists feel like reading a phone book to find a party.

So this is less “startup” and more “the itch came back.” I wanted the circle on the one screen that’s always in my pocket.

The confession up front: this is a learning project

I’m not a “real” developer. I pay the bills as a consultant, and I’ve had an Apple Developer account for years — used almost entirely to wrap and sign other people’s apps for MAM/MDM distribution. Never to actually build something. PacketCircle for iPhone was my excuse to finally get my hands dirty with Xcode, Swift and SwiftUI.

And like most of my side projects: yes, this one is AI-assisted. I built it with Cursor riding shotgun. I’m not going to be coy about it — and I’m not undervaluing writing the code either. Getting a native app to compile and behave is real work. What still eats the calendar, though, is the stuff AI can’t invent for you: information modeling and visualization that fits a small screen — which metrics belong on the circle vs. in Session details, how TCP health should read at a glance, what a thumb-sized workflow looks like when you’re actually troubleshooting. If you don’t understand the metrics representation and the analyst’s path through the UI, you just get a pretty toy. I hope people really find PacketCircle useful — more than a toy. 😉

Home screen: Guided tour, Open Capture, Demo Mode

Home screen — Guided tour, Open Capture, Demo Mode.

The deal (this is the part I actually care about)

Because I’m tired of opening the App Store and finding a flashlight that wants a subscription and my location data, here’s the whole contract for PacketCircle on iPhone:

Why free? The honest answer: I don’t need PacketCircle to pay rent — consulting does that. The slightly grumpier answer: the App Store is drowning in subscriptions, ad SDKs and data lakes, and I wanted to drop one small thing into it that’s just… a tool. If it saves you ten minutes, buy me a coffee and send good karma — I’m good. ☕

Why the App Store at all (and why there’s no open-source inside)

For an iPhone app that normal humans can actually install, the App Store is basically the only reasonable door. Sideloading and enterprise tricks aren’t a real distribution story for a tool like this. So App Store it is — which shaped two decisions:

  1. No local Wi-Fi/interface capture on iOS. You can’t sniff the Wi-Fi/interface from a sandboxed App Store app, and the VPN/tunnel “cheats” people whisper about won’t survive review anyway. PacketCircle stays honest about that: it’s an analyzer for captures you already have — plus, since 1.2.5, a live PCAP over IP stream you pull in from a sensor you control. The phone still never touches its own Wi-Fi or cellular traffic.
  2. No open-source dissection code shipped. The original plugin lives in GPL land. Mixing GPL v2 with App Store distribution is a famous legal rabbit hole, and I’ll admit it plainly: I haven’t chased down every detail. So instead of guessing, I removed the temptation entirely — no libwiretap, no borrowed GPL dissectors. The iOS app is clean, native Swift end to end. Less code coverage than Wireshark, sure, but zero license landmines.

The upside of that constraint: the decodes are mine, they’re limited on purpose, and I can put them on the Store with a clear conscience.

Circle view: node-to-node conversations colored by protocol
Services view: hosts on the left, services on the right
Quality view: same hosts ring, edges colored by TCP session health

Circle, Services, and Quality views — same capture, three ways to read it.

What it actually does today

Load a capture, and PacketCircle turns it into a circle of talkers you can poke at with your thumb: tap a node or an edge, filter by the legend chips, then drill into session health, skim a decode tree, or follow a TCP stream — all on the phone.

Two switches on the circle change what you’re looking for:

Gauges add a Degraded Quality Conversations list (Fair/Poor) and a quality timeline you can tap into a time slice for Talkers. Conversation summaries are bi-directional; ports show when you pick a socket. Optional Show host names pulls shortened labels from DNS / mDNS / NetBIOS in the capture.

No file handy? There’s a built-in demo capture that replays so you can see the whole thing move without a lab network.

The 2-minute tour

  1. Open a capture or hit Demo Mode.
  2. Play in the Circle: tap nodes/edges; flip Color between Protocol and Quality; use the legend chips as filter. Hosts vs Services rearranges the ring.
  3. Peek at Gauges for rates, degraded Fair/Poor conversations, and the quality timeline.
  4. Browse Talkers for the full conversation list, or Decode for frames + details/hex.
  5. Open Session details for the bi-dir summary, TCP health, exchange ladder, and app decode.
  6. Follow TCP Stream when you want the reassembled payload (ASCII/hex) — with a budget so your phone doesn’t melt on a 2 GB elephant.
  7. Tap the status bar (filename · packets · pairs) to replay with original timing.
  8. Open the ⓘ About and the Options gear for the guided tour, quality bands, host names, IP-pair vs TCP-socket focus, and the stream budget.
Gauges: packet/byte/error rates, top talkers and protocols
Talkers: conversation list with protocol badges and TCP health grades
Decode: packet list, details tree and hex dump

Gauges, Talkers, and Decode.

Feature list (v1.2.5)

AreaWhat you get
OpenPCAP / PCAPNG from Files / share sheet — fully offline
DemoBundled demo capture, replayable
CircleConversation graph; Protocol or Quality edge colors; Hosts / Services layout; Top-N focus
Quality coloringEdges graded Excellent / Good / Fair / Poor from native TCP health; legend chips filter by grade
GaugesRates, top talkers & protocols; Degraded Quality Conversations; quality timeline → Talkers slice
TalkersAll analyzed pairs (Circle keeps Top-N); bi-dir summary; protocol badges and health grades
DecodePacket list, friendly details tree, hex/ASCII (capped frames); broader infra peeks in 1.1
Session healthNative TCP score & metrics — RTT, window, retransmits, RST, zero-window, SYN/FIN (not Wireshark tcp.analysis)
Conversation UIBi-directional hosts; ports when a socket is selected; unnamed listeners stay visible
Host namesOptional shortened DNS / mDNS / LLMNR / NetBIOS labels (Options)
Quality chartsTCP line graphs over the session: ACK round trip, packet size, inter-arrival (and related series)
TCP exchangeClient↔server ladder of segments/ACKs
Application decodeLightweight previews (DNS/HTTP/Telnet/… + infra where present)
Follow TCP StreamReassembly, direction filters, ASCII/hex (budget-capped)
ReplayTap the status bar → replay with original timing
OptionsQuality thresholds, host names, IP-pair vs TCP-socket focus, stream budget
Guided tourCircle → Session → Gauges; Finish leaves a clean desk
Remote capturePCAP over IP (1.2.5+) — pull a live stream from a sensor you point it at (pcapoverip, PolarProxy); the phone never sniffs its own Wi-Fi or cellular traffic
SanitizeOn-device payload sanitize (1.2.5+) — the PacketSanitizerPro modes, native on iPhone/iPad
ReportNative PDF report generation (1.2.5+) — the PacketReporterPro report set, same pipeline as the Mac app
PrivacyAnalysis stays on device — no upload, no telemetry, ever. PCAP over IP is opt-in: you choose the sensor it connects to.
TCP session health: poor score with retransmissions and zero-window events
Quality charts: ACK round trip, packet size and inter-arrival line graphs
TCP exchange ladder: client and server segments with ACKs
Follow TCP Stream: reassembled FTP session with client/server coloring
Application decode: Telnet messages with plain-text payload
Options: guided tour, session focus, quality thresholds

Session health, quality charts, TCP exchange ladder, Follow TCP Stream, application decode, and Options.

The use cases that make people lean in

1. “Just show me who’s talking.” You grabbed a PCAP off a SPAN/TAP/laptop. On the train home — or mid-meeting — open it on the phone and see the conversation map. Flip to Quality coloring and the sick pairs light up red (retransmits, RSTs, zero-window, poor score) without leaving the circle. No laptop, no boot time.

2. Teaching without a lab. Demo Mode is a story told in a circle — HTTP, DNS, SSH, Telnet, SMB, all lit up. Perfect for showing a junior (or a skeptical manager) what “conversation-first” troubleshooting means, without wiring up a network.

3. The map before the microscope. Use the circle and Talkers to spot the interesting IP pair/port, then jump to full Wireshark on a laptop with a proper display filter. PacketCircle finds the needle; Wireshark dissects it.

4. TCP health triage in your hand. Session details give a native health estimate (not Wireshark tcp.analysis): window, retransmissions, RST, SYN/FIN, zero-window events — plus Quality charts (ACK round trip, packet size, inter-arrival) so you can see the session breathe. Focus per TCP socket so one sick HTTPS port can’t hide behind a perfectly healthy SSH session on the same IP pair.

5. Payload peek, no laptop required. Follow TCP Stream for Telnet/HTTP-ish text with client/server coloring. The caps are deliberate — a phone isn’t a workstation — and Options lets you raise the budget when you mean it.

6. Customer site / air-gapped, guilt-free. No cloud account, no “upload your customer’s PCAP to our servers.” Open locally, analyze locally, delete when done. What happens on the phone stays on the phone.

Honest limits (and what Options can change)

A phone is not a laptop. PacketCircle is built for triage on a small screen, so a few caps are deliberate — and most of the tunable ones live in Options:

There’s no hard-coded maximum PCAP size, but memory and CPU still rule. On a recent iPhone, circle / gauges / talkers stay comfortable well past the sizes I typically throw at it. Personally, the largest capture I tickle day-to-day is around ~15 MB — and that opens with no major delay. The one place you may notice wait time is Follow TCP Stream on a chatty flow (it re-scans and reassembles payload under the budget). Bigger files can work; just don’t expect a multi-hundred-megabyte elephant to feel as snappy as Wireshark on a MacBook.

Decode depth is native and limited (reasonable IP/TCP, some app-layer peeks) — not Wireshark-class. That’s the trade for staying clean, offline, and App Store–shippable.

What it is honestly not

For the curious / future dev

1.1.0 already landed the conversation UX polish, Gauges quality panels, host names, and broader native decode described above. What’s still on my mind:

Status & links

Built by one packet nerd, for the packet community — with a lot of Cursor and a little obsession with circles.

Feedback — get in touch — helps a lot. What works, what’s missing, tablet use case or not: tell me.

© 2026 Walter Hofstetter Privacy & Cookies Terms GitHub