Protocol distribution
Packets grouped by their decoded transport or network protocol.
Capture details
Basic file and packet-size information from the analysis export.
| File size | 1.77 MB |
| Capture start | 10:00:00 UTC |
| Minimum packet | 42 bytes |
| Maximum packet | 6,974 bytes |
| Average packet | 784.3 bytes |
Traffic over time
Packets per one-second interval. The largest interval contained 547 packets.
Top talkers
Endpoints ranked by the number of packets in which they appear.
| Endpoint | Packets |
|---|---|
192.0.2.10 | 2,155 |
198.51.100.36 | 415 |
198.51.100.44 | 351 |
198.51.100.45 | 206 |
198.51.100.38 | 158 |
198.51.100.43 | 146 |
TCP flags
Flag frequency across decoded TCP packets. A packet can contribute more than one flag.
Largest network conversations
The report keeps packet and byte totals for every observed IP pair.
| IP pair | Packets | Bytes |
|---|---|---|
198.51.100.36 ↔ 192.0.2.10 | 415 | 424,853 |
198.51.100.44 ↔ 192.0.2.10 | 351 | 321,391 |
192.0.2.10 ↔ 198.51.100.38 | 158 | 197,619 |
192.0.2.10 ↔ 198.51.100.45 | 206 | 181,545 |
192.0.2.10 ↔ 198.51.100.20 | 139 | 160,283 |
198.51.100.43 ↔ 192.0.2.10 | 146 | 94,460 |
Application-layer activity
Decoded DNS queries and TLS Server Name Indication values reveal which services were contacted without claiming access to encrypted HTTPS content.
DNS queries
data.example.net6portal.example4api.example.net4archive.example.net4challenge.example.net2shipping.example.net2
TLS/HTTPS domains
shipping.example.net2status.example.net1api.example.net1data.example.net1challenge.example.net1
Clear-text HTTP
This capture used encrypted TLS traffic, so HTTP paths and content were not available.
Inspect the sanitized exports
Download the same aggregate data as JSON or as a ZIP containing 17 CSV tables.
Run the same analysis on your own capture
PCAPNG Analyzer runs on your server, where your packet data stays under your control.
Start with the Free tierCompare Free and Pro