Sanitized real output

Sample network capture report

This report was built from an actual PCAPNG Analyzer export. It shows the aggregate results available after uploading a capture, with identifying network data replaced before publication.

sanitized-sample.pcapng26.5-second capture2,160 packets
What was changed: IP addresses use documentation-only ranges, MAC addresses are synthetic, domains use reserved example names, and dates were shifted. Packet counts, byte counts, timing intervals and protocol distribution are retained from the exported report.
Packets
2,160
Across 26.5 seconds
Captured traffic
1.69 MB
784-byte average packet
Conversations
39
IP pairs observed
Application activity
11
6 DNS names, 5 TLS names

Protocol distribution

Packets grouped by their decoded transport or network protocol.

TCP1,130 · 52.3%
UDP1,028 · 47.6%
ARP2 · 0.1%

Capture details

Basic file and packet-size information from the analysis export.

File size1.77 MB
Capture start10:00:00 UTC
Minimum packet42 bytes
Maximum packet6,974 bytes
Average packet784.3 bytes

Traffic over time

Packets per one-second interval. The largest interval contained 547 packets.

10:00:0010:00:1310:00:27 UTC

Top talkers

Endpoints ranked by the number of packets in which they appear.

EndpointPackets
192.0.2.102,155
198.51.100.36415
198.51.100.44351
198.51.100.45206
198.51.100.38158
198.51.100.43146

TCP flags

Flag frequency across decoded TCP packets. A packet can contribute more than one flag.

ACK1,124
PSH486
SYN12
FIN8
RST4

Largest network conversations

The report keeps packet and byte totals for every observed IP pair.

IP pairPacketsBytes
198.51.100.36 ↔ 192.0.2.10415424,853
198.51.100.44 ↔ 192.0.2.10351321,391
192.0.2.10 ↔ 198.51.100.38158197,619
192.0.2.10 ↔ 198.51.100.45206181,545
192.0.2.10 ↔ 198.51.100.20139160,283
198.51.100.43 ↔ 192.0.2.1014694,460

Application-layer activity

Decoded DNS queries and TLS Server Name Indication values reveal which services were contacted without claiming access to encrypted HTTPS content.

DNS queries

  • data.example.net6
  • portal.example4
  • api.example.net4
  • archive.example.net4
  • challenge.example.net2
  • shipping.example.net2

TLS/HTTPS domains

  • shipping.example.net2
  • status.example.net1
  • api.example.net1
  • data.example.net1
  • challenge.example.net1

Clear-text HTTP

No HTTP hosts or methods detected.
This capture used encrypted TLS traffic, so HTTP paths and content were not available.

Inspect the sanitized exports

Download the same aggregate data as JSON or as a ZIP containing 17 CSV tables.

Run the same analysis on your own capture

PCAPNG Analyzer runs on your server, where your packet data stays under your control.

Start with the Free tierCompare Free and Pro