Transform packet captures into searchable records, connected visual evidence, and prioritized security findings.
Browse Audit RecordsThe grouped record inventory shows which protocol datasets are available for focused investigation.Visualize Connections in 3DThe interactive spatial view reveals clusters and outliers across captured network connections.Map Host CommunicationsThe communication graph makes dominant hosts and their peer relationships immediately visible.Trace Protocol FlowThe flow diagram traces how traffic moves through protocol layers and exposes unusual combinations.Compare Record VolumesThe proportional treemap highlights which record types dominate the capture before deeper analysis.Compare Protocol CountsThe ranked chart surfaces the most prevalent protocols and long-tail activity in the dataset.Explore DNS QueriesThe domain distribution helps analysts spot repeated, rare, or suspicious DNS lookups.Review Discovered HostsThe host inventory consolidates identity, service, and platform evidence for each observed system.Identify Network DevicesThe device table links hardware addresses to vendors and observed network roles.Investigate ConnectionsThe filterable connection table supports rapid review of endpoints, services, and traffic behavior.Inspect HTTP TrafficThe transaction view brings headers, status, content, and endpoint details together for inspection.Audit CertificatesThe certificate inventory exposes trust, expiry, and identity signals observed in encrypted traffic.Inventory Detected SoftwareThe software inventory turns passive network evidence into an actionable technology overview.Review Detected VulnerabilitiesThe findings table connects detected software to vulnerabilities that warrant investigation.Review Extracted FilesThe file view summarizes transferred content and preserves individual artifacts for review.Hunt Suspicious RequestsThe searchable request log helps analysts isolate unusual destinations, methods, and paths.Review Exposed CredentialsThe credential findings identify sensitive authentication data exposed within captured traffic.Review Capture SoftwareThe capture-wide software list shows technology versions and associated security exposure.Prioritize VulnerabilitiesSeverity filters and affected-host counts focus remediation on the most consequential weaknesses.Triage Security AlertsThe alert queue combines severity, rules, timestamps, and status for efficient triage.Inspect Alert EvidenceThe evidence panel explains why an alert fired and provides the underlying network context.