Upload a pcap. Ask a question. Get a grounded answer — backed by real detections, not guesses.
3 free captures/month. No credit card required.
The LLM never sees raw packets. The analyzer parses the capture and a deterministic detection engine runs first — beaconing, DNS tunneling, port scans, plaintext creds, rare ports. The model reasons over structured evidence and drills down via parameterized query tools. Never model-generated SQL. Never fabricated evidence.
Routes every question to the right specialist automatically — NotebookLM-style, no menus.
Proactively investigates beacons, exfiltration, lateral movement, and C2 activity.
Precise, factual answers about connections, protocols, and specific packets.
Turns findings into incident reports and executive summaries.
Explains protocols and attack techniques, grounded in your actual capture.
Generates Wireshark filters, analyzer scripts, and detection rules on demand.