Native Swift. Offline PCAP/PCAPNG. No ads, no subscriptions, no telemetry — and yes, no live sniffing (I’ll explain why).
I have a mildly unreasonable love for one idea: draw network conversations as a circle. Who talks to whom, which protocols, which edges run hot. Last year that turned into PacketCircle, an open-source Wireshark plugin. The mental model never let go of me — once you see traffic as a ring of relationships, packet lists feel like reading a phone book to find a party.
So this is less “startup” and more “the itch came back.” I wanted the circle on the one screen that’s always in my pocket.
I’m not a “real” developer. I pay the bills as a consultant, and I’ve had an Apple Developer account for years — used almost entirely to wrap and sign other people’s apps for MAM/MDM distribution. Never to actually build something. PacketCircle for iPhone was my excuse to finally get my hands dirty with Xcode, Swift and SwiftUI.
And like most of my side projects: yes, this one is AI-assisted. I built it with Cursor riding shotgun. I’m not going to be coy about it — and I’m not undervaluing writing the code either. Getting a native app to compile and behave is real work. What still eats the calendar, though, is the stuff AI can’t invent for you: information modeling and visualization that fits a small screen — which metrics belong on the circle vs. in Session details, how TCP health should read at a glance, what a thumb-sized workflow looks like when you’re actually troubleshooting. If you don’t understand the metrics representation and the analyst’s path through the UI, you just get a pretty toy. I hope people really find PacketCircle useful — more than a toy. 😉

Home screen — Guided tour, Open Capture, Demo Mode.
Because I’m tired of opening the App Store and finding a flashlight that wants a subscription and my location data, here’s the whole contract for PacketCircle on iPhone:
Why free? The honest answer: I don’t need PacketCircle to pay rent — consulting does that. The slightly grumpier answer: the App Store is drowning in subscriptions, ad SDKs and data lakes, and I wanted to drop one small thing into it that’s just… a tool. If it saves you ten minutes, buy me a coffee and send good karma — I’m good. ☕
For an iPhone app that normal humans can actually install, the App Store is basically the only reasonable door. Sideloading and enterprise tricks aren’t a real distribution story for a tool like this. So App Store it is — which shaped two decisions:
The upside of that constraint: the decodes are mine, they’re limited on purpose, and I can put them on the Store with a clear conscience.



Circle, Services, and Quality views — same capture, three ways to read it.
Load a capture, and PacketCircle turns it into a circle of talkers you can poke at with your thumb: tap a node or an edge, filter by the legend chips, then drill into session health, skim a decode tree, or follow a TCP stream — all on the phone.
Two switches on the circle change what you’re looking for:
Gauges add a Degraded Quality Conversations list (Fair/Poor) and a quality timeline you can tap into a time slice for Talkers. Conversation summaries are bi-directional; ports show when you pick a socket. Optional Show host names pulls shortened labels from DNS / mDNS / NetBIOS in the capture.
No file handy? There’s a built-in demo capture that replays so you can see the whole thing move without a lab network.



Gauges, Talkers, and Decode.
| Area | What you get |
|---|---|
| Open | PCAP / PCAPNG from Files / share sheet — fully offline |
| Demo | Bundled demo capture, replayable |
| Circle | Conversation graph; Protocol or Quality edge colors; Hosts / Services layout; Top-N focus |
| Quality coloring | Edges graded Excellent / Good / Fair / Poor from native TCP health; legend chips filter by grade |
| Gauges | Rates, top talkers & protocols; Degraded Quality Conversations; quality timeline → Talkers slice |
| Talkers | All analyzed pairs (Circle keeps Top-N); bi-dir summary; protocol badges and health grades |
| Decode | Packet list, friendly details tree, hex/ASCII (capped frames); broader infra peeks in 1.1 |
| Session health | Native TCP score & metrics — RTT, window, retransmits, RST, zero-window, SYN/FIN (not Wireshark tcp.analysis) |
| Conversation UI | Bi-directional hosts; ports when a socket is selected; unnamed listeners stay visible |
| Host names | Optional shortened DNS / mDNS / LLMNR / NetBIOS labels (Options) |
| Quality charts | TCP line graphs over the session: ACK round trip, packet size, inter-arrival (and related series) |
| TCP exchange | Client↔server ladder of segments/ACKs |
| Application decode | Lightweight previews (DNS/HTTP/Telnet/… + infra where present) |
| Follow TCP Stream | Reassembly, direction filters, ASCII/hex (budget-capped) |
| Replay | Tap the status bar → replay with original timing |
| Options | Quality thresholds, host names, IP-pair vs TCP-socket focus, stream budget |
| Guided tour | Circle → Session → Gauges; Finish leaves a clean desk |
| Remote capture | PCAP over IP (1.2.5+) — pull a live stream from a sensor you point it at (pcapoverip, PolarProxy); the phone never sniffs its own Wi-Fi or cellular traffic |
| Sanitize | On-device payload sanitize (1.2.5+) — the PacketSanitizerPro modes, native on iPhone/iPad |
| Report | Native PDF report generation (1.2.5+) — the PacketReporterPro report set, same pipeline as the Mac app |
| Privacy | Analysis stays on device — no upload, no telemetry, ever. PCAP over IP is opt-in: you choose the sensor it connects to. |






Session health, quality charts, TCP exchange ladder, Follow TCP Stream, application decode, and Options.
1. “Just show me who’s talking.” You grabbed a PCAP off a SPAN/TAP/laptop. On the train home — or mid-meeting — open it on the phone and see the conversation map. Flip to Quality coloring and the sick pairs light up red (retransmits, RSTs, zero-window, poor score) without leaving the circle. No laptop, no boot time.
2. Teaching without a lab. Demo Mode is a story told in a circle — HTTP, DNS, SSH, Telnet, SMB, all lit up. Perfect for showing a junior (or a skeptical manager) what “conversation-first” troubleshooting means, without wiring up a network.
3. The map before the microscope. Use the circle and Talkers to spot the interesting IP pair/port, then jump to full Wireshark on a laptop with a proper display filter. PacketCircle finds the needle; Wireshark dissects it.
4. TCP health triage in your hand. Session details give a native health estimate (not Wireshark tcp.analysis): window, retransmissions, RST, SYN/FIN, zero-window events — plus Quality charts (ACK round trip, packet size, inter-arrival) so you can see the session breathe. Focus per TCP socket so one sick HTTPS port can’t hide behind a perfectly healthy SSH session on the same IP pair.
5. Payload peek, no laptop required. Follow TCP Stream for Telnet/HTTP-ish text with client/server coloring. The caps are deliberate — a phone isn’t a workstation — and Options lets you raise the budget when you mean it.
6. Customer site / air-gapped, guilt-free. No cloud account, no “upload your customer’s PCAP to our servers.” Open locally, analyze locally, delete when done. What happens on the phone stays on the phone.
A phone is not a laptop. PacketCircle is built for triage on a small screen, so a few caps are deliberate — and most of the tunable ones live in Options:
There’s no hard-coded maximum PCAP size, but memory and CPU still rule. On a recent iPhone, circle / gauges / talkers stay comfortable well past the sizes I typically throw at it. Personally, the largest capture I tickle day-to-day is around ~15 MB — and that opens with no major delay. The one place you may notice wait time is Follow TCP Stream on a chatty flow (it re-scans and reassembles payload under the budget). Bigger files can work; just don’t expect a multi-hundred-megabyte elephant to feel as snappy as Wireshark on a MacBook.
Decode depth is native and limited (reasonable IP/TCP, some app-layer peeks) — not Wireshark-class. That’s the trade for staying clean, offline, and App Store–shippable.
1.1.0 already landed the conversation UX polish, Gauges quality panels, host names, and broader native decode described above. What’s still on my mind:
Built by one packet nerd, for the packet community — with a lot of Cursor and a little obsession with circles.
Feedback — get in touch — helps a lot. What works, what’s missing, tablet use case or not: tell me.