Open source

PacketTools

Free, open-source tools for packet analysts. I build these to give back to the community — powerful AI assistants handle the low-level coding these days, so I can focus on workflows, data modelling, and the best way to represent what the wire reveals. Everything lives on GitHub; feedback and ideas are always welcome.

PacketCircle C · Swift

See who is talking to whom, using which protocol, and how much — instantly.

PacketCircle turns packet captures into interactive circle and graph diagrams: hosts as nodes, connections as arcs, colored by protocol and weighted by traffic volume. Right-click any connection for deep protocol details — TLS certs, HTTP headers, DNS answers, Kerberos tickets, and 20+ more.

Wireshark plugin (C) — native plugin for macOS, Windows, and Linux with full Wireshark integration: apply display filters, follow TCP streams, Wi-Fi monitoring mode, anomaly scoring, and 3-page PDF reports.
Native app for iOS & macOS (Swift) — explore PCAP/PCAPNG captures with a fully native UI. The Mac captures live traffic itself; iPhone and iPad open PCAP/PCAPNG files you import, or pull a live stream from a remote sensor over PCAP over IP (1.2.4+) — the phone never sniffs its own Wi-Fi or cellular traffic. iOS 1.2.5 adds native Sanitize and PDF Report generation too — the same PacketSanitizerPro and PacketReporterPro functions, on device. Free to use, and it collects no data at all.

PacketCircle for iOS 1.2.5 is live on the App Store — free, no ads, no telemetry, fully offline. Download on the App Store → PacketCircle for macOS 1.2.6 is in Tech Preview — Expert Alerts, Compare, Sanitize, and Report. See what’s new → Download PacketCircle-1.2.6.dmg

PacketCircle — Wireshark plugin, iOS and macOS app showcase

PCAP over IP — PacketCircle connects out to a remote pcap stream, the same convention Wireshark uses with -k -i TCP@host:port. Point it at a broker on the sensor side: github.com/netwho/pcapoverip (single-file, free, GPL-2.0), or any tool that already speaks the protocol, such as PolarProxy. Nothing is captured until PacketCircle connects; the sensor streams only what crosses the interface you point it at.

Sensor pcapoverip / PolarProxy dumpcap · tcpdump PacketCircle iPhone · iPad · Mac connects out TCP@host:57012 pcap stream

ASK — Analyst’s Shark Knife Lua

A Swiss Army knife for the packet list, right-click included.

ASK adds a right-click menu straight in Wireshark’s packet list for the lookups you’d otherwise do in five different browser tabs: IP registration (RDAP), IP reputation (AbuseIPDB, VirusTotal), IP intelligence (Shodan, IPinfo, GreyNoise), DNS analytics, ping, traceroute, and offensive checks (SYN scan, service scan, OS fingerprinting) for when you’re testing your own lab. It also runs full SSL/TLS certificate and security grading via the SSLLabs API — vulnerability checks (Heartbleed, POODLE, etc.) and an industry-standard A–F grade, no API key required.

ASK — Analyst's Shark Knife showcase

PacketSanitizerPro C

Share a trace file without sharing your network.

A native Wireshark epan plugin — no Python, no Lua, no external dependencies — that sanitizes PCAP/PCAPNG files at wire speed before they leave your organization. Checksums are recomputed automatically, and the original file is always preserved.

  • Sanitize All Payload — zeros every TCP/UDP/ICMP payload, keeps IP/MAC addresses and structure intact
  • Sanitize Clear-Text Payload — only touches unencrypted protocols (HTTP, FTP, Telnet, SMTP, POP3, IMAP, DNS)
  • Sanitize Payload + Anonymize IP & MAC — full sanitization with deterministic address anonymization, for sharing outside your organization
PacketSanitizerPro showcase

Vulnerability Correlator Lua

See which packets belong to a known CVE, without leaving Wireshark.

This plugin bridges vulnerability scanning and packet analysis: feed it an nmap Vulners scan or an OpenVAS export, and it correlates the findings directly against your capture. CVSS scores and CVE IDs show up as columns in the packet list, high-severity traffic gets color-coded automatically, and a dedicated menu generates a full correlation report — scan summary, matched hosts, and detailed findings with packet references.

Vulnerability Correlator showcase

PacketReporterPro C

Turn a packet capture into a professional PDF report — no external tools required.

A native Wireshark plugin using libcairo for vector PDF rendering and Qt6 for an integrated settings window. It replaces my earlier Lua-based PacketReporter, which leaned on external tools for PDF generation. PacketReporterPro compiles the whole pipeline natively instead: zero runtime dependencies beyond Wireshark itself.

  • Network Summary — one-page stats, protocol pie chart, top talkers
  • Network Detailed — 14+ pages covering PCAP summary, IP stats, protocol hierarchy, DNS, TLS/SSL, HTTP, MAC/IP layers, TCP analysis
  • Network Annotated — the Detailed report with expert sidebars, for sharing with non-experts
  • WiFi Summary / Detailed / Annotated — the same depth for 802.11 monitor-mode captures

Supports Wireshark 4.2 through 4.6, with prebuilt binaries for macOS (universal), Linux, and Windows.

PacketReporterPro showcase

Want to see these tools in action?

The Packet Factor training walks through several of these tools hands-on, using real attack traffic.

Learn about the training
×