About PCAPNG Analyzer
PCAPNG Analyzer is a self-hosted packet-capture analysis application created and maintained by Stuart Mathieson.
A practical tool with a defined scope
The application turns PCAP and PCAPNG files into browser-based protocol, endpoint, conversation, DNS, HTTP and visible TLS reports. It includes packet filtering, batch analysis, two-file comparison and exports. Optional Pro features add 29 configurable heuristic detectors, watched-folder ingestion, multi-user proxy authentication, larger uploads and unlimited history.
It is intended to make repeatable first-pass analysis and review easier. It does not replace Wireshark for deep protocol dissection, stream reconstruction, live capture or specialist graphs. The Wireshark comparison explains those differences directly.
Privacy: no usage telemetry
PCAPNG Analyzer does not send usage telemetry, analytics, capture files, decoded packets or analysis results to Stuart Mathieson or a hosted analysis service.
If a Pro license key is configured, the sole application-initiated outbound communication is an HTTPS license-status check. It carries the license key and a product/version identifier, but no capture or analysis data. With no licensing configuration, that background check does not run. See the full security and privacy explanation.
Support from the author
Questions about setup, licensing, billing or unexpected behaviour can be sent to [email protected]. Messages are handled directly by Stuart Mathieson.
Do not send packet captures, credentials or sensitive payloads in an initial support email. Describe the issue first so a safe diagnostic approach can be agreed.
Refund promise
Pro purchases receive a full refund when requested within 14 days of purchase, with no questions asked. Email [email protected] with the license key so the purchase can be identified.
How the guides are written
The technical guides describe manual Wireshark and tshark methods as well as the relevant PCAPNG Analyzer workflow. They distinguish observed packet evidence from inference, mention capture artefacts and encryption limits, and identify Pro-only features. Articles carry an author and last-updated date so readers can judge their provenance and freshness.
See what the application produces
Explore a sanitised report or run the Free tier on a server you control.
Start freeView sample report