PacketTools · Documentation

PacketReporter Pro

A native Wireshark plugin that generates professional PDF reports directly from packet captures — no external tools required.

Wireshark 4.2.x Wireshark 4.4.x Wireshark 4.6.x Platform License GPL-2.0 PDF engine Cairo Qt6

PacketReporter Pro is a compiled C/C++ Wireshark plugin using libcairo for high-quality vector PDF rendering and Qt6 for an integrated settings window. It replaces the original Lua-based PacketReporter with dramatically better performance, richer reports, and zero runtime dependencies beyond Wireshark itself.

Why native?

PacketReporter Pro is derived from the Lua-based PacketReporter plugin. The Lua version’s reliance on external tools for PDF generation (rsvg-convert, pdfunite) became a real pain point — particularly on Windows, where Lua opened a terminal window for every single page of a report. Lua remains a great fit for lightweight decode modules, as demonstrated by PacketSanitizer; it just wasn’t the right approach for a report generator.

  • Performance — native compiled C code instead of interpreted Lua
  • Integrated UI — a Qt6 settings window to select paper size (A4/Legal), configure a custom logo and cover page text, and choose report type
  • Network Analysis — Summary, Detailed, and Annotated reports
  • WiFi / 802.11 Analysis — Summary, Detailed, and Annotated reports

Screenshots

Main window

PacketReporter Pro main window

Detailed report

PacketReporter Pro detailed report sample

Annotated report

PacketReporter Pro annotated report sample

60/40 layout with expert annotation sidebars explaining each section for non-experts

WiFi report

PacketReporter Pro WiFi report sample

Report types

ReportCapture typePagesContent
Network SummaryNetwork1Packet/byte counts, protocol distribution, top IP addresses
Network DetailedNetwork14+Cover page, ToC, 12 analysis sections, summary page
Network AnnotatedNetwork14+Detailed report with expert annotation sidebars (60/40 layout)
WiFi Summary802.11 (monitor)1BSSIDs, clients, channels, RSSI, retry rate, channel pie chart
WiFi Detailed802.11 (monitor)10+RSSI, SNR, channels, MCS, frames, deauth, retry, airtime
WiFi Annotated802.11 (monitor)12+WiFi Detailed with annotation sidebars for each metric

WiFi reports require a capture in monitor mode (rfmon) — a regular managed-mode capture has no radiotap headers or 802.11 management frames.

Detailed report sections

The Network Detailed / Annotated report covers 12 sections: PCAP summary, IP stats, protocol hierarchy, IP communication matrix, port analysis, DNS analysis, TLS/SSL analysis, HTTP analysis, MAC layer analysis, IP layer analysis (TTL, fragmentation, DSCP), and TCP analysis (window size, segment length, options negotiated, top connections by throughput and by flag usage).

Quick start

macOS (universal binary, Cairo statically linked): cd installers/macos && ./install.sh

Linux (auto-detects Wireshark 4.2/4.4/4.6): cd installers/linux && ./install.sh

Windows: cd installers\windows && .\install.bat

Then: Tools → PacketReporter Pro → Refresh → customize the cover page (logo, description) and paper size → click a report button. The PDF opens automatically.

Requirements

End users need only Wireshark installed — the macOS binary has Cairo statically linked, and the Linux/Windows Wireshark packages include the required shared libraries. Building from source additionally needs CMake, Qt6, Cairo, and GLib 2.x (see the build dependencies table).

Migrating from the Lua plugin

FeatureLua pluginPacketReporter Pro
PDF generationRequires rsvg-convert + pdfuniteBuilt in (Cairo)
Report qualitySVG → PNG → PDF pipelineDirect vector PDF
WiFi reportsBasicFull 10-section analysis + annotated
Annotated reportsNoneExpert sidebars explaining each section
Settings UINoneIntegrated Qt6 window
PerformanceInterpretedCompiled C/C++
Theme supportNoneDark / light auto-detect

Both plugins can coexist — your existing ~/.packet_reporter/ config is preserved.

License

Follows Wireshark’s GPL-2.0 license — see LICENSE.

Acknowledgments

Author & architect: Walter Hofstetter. AI-assisted (Claude by Anthropic) for build system automation, installer scripting, cross-platform compatibility, and documentation.

View on GitHub → github.com/netwho/PacketReporterPro