Observed arrival · 2026-09-28
PCAP Parser: Network Forensics in the Browser
A browser-based analyzer for PCAP and PCAPNG captures that surfaces network conversations, DNS, HTTP, TLS details, extracted files, and indicators of compromise.
- For
- DFIR analysts and network defenders inspecting packet captures
- Worth noticing
- The page says large captures are streamed in chunks, so they do not need to fit in memory twice.
Field notes
Users can drop a capture, folder, or ZIP, choose a folder, or load a synthetic sample; the page says parsing runs locally through Rust compiled to WebAssembly. It lists reconstructed conversations, DNS, HTTP, TLS ClientHello details including SNI and JA3/JA4, extracted files, IOCs, and cleartext credentials. The parser supports classic pcap in both byte orders and microsecond or nanosecond formats, plus pcapng; large captures are streamed in chunks.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue