AI-native network forensics

Talk to your packets.

Upload a pcap. Ask a question. Get a grounded answer — backed by real detections, not guesses.

Start free → See pricing

3 free captures/month. No credit card required.

$ pcaplm analyze suspicious.pcap
> Analyzer parsed 1,204 connections, 340 DNS queries, 12 HTTP requests
> Detection engine flagged 3 findings before any LLM call
> Hunter: "10.0.0.5 is beaconing to 203.0.113.50 every ~10s (jitter 2.6%) — consistent with C2 (T1071). Want the Wireshark filter?"

The core principle

The LLM never sees raw packets. The analyzer parses the capture and a deterministic detection engine runs first — beaconing, DNS tunneling, port scans, plaintext creds, rare ports. The model reasons over structured evidence and drills down via parameterized query tools. Never model-generated SQL. Never fabricated evidence.

Seven roles. One conversation.

Orchestrator

Routes every question to the right specialist automatically — NotebookLM-style, no menus.

Hunter

Proactively investigates beacons, exfiltration, lateral movement, and C2 activity.

Analyst

Precise, factual answers about connections, protocols, and specific packets.

Writer

Turns findings into incident reports and executive summaries.

Teacher

Explains protocols and attack techniques, grounded in your actual capture.

Builder

Generates Wireshark filters, analyzer scripts, and detection rules on demand.