Nobuf

PCAP Network Analyzer

Local capture analysis

Inspect PCAP and PCAPNG traffic locally with packet decoding, conversations, DNS, HTTP, TLS and privacy findings.

Inspect a packet capture without uploading it

Decode common PCAP and PCAPNG traffic, follow conversations and DNS/web metadata, inspect packet bytes and export redacted evidence.

Packet captures can contain secrets
Addresses, domains, cookies, tokens and payload previews remain in this browser. Review every export; default reports omit payloads and redact common identifiers.

How to use it

  1. 01

    Open a packet capture

    Detect PCAP or PCAPNG byte order, interfaces and timestamp resolution while enforcing strict block and packet limits.

  2. 02

    Trace traffic evidence

    Filter packets, inspect protocol fields and bytes, follow conversations, DNS, plaintext HTTP and TLS ClientHello metadata.

  3. 03

    Triage and report

    Review explainable privacy and troubleshooting findings, charts and endpoints, then export filtered metadata or a deterministically redacted report.

Frequently asked questions

Does this replace Wireshark?

No. It focuses on common local triage protocols and safe browser workflows, not Wireshark's thousands of dissectors, decryption, live capture or expert filtering language.

Is the capture uploaded?

No. Capture bytes, addresses, domains and payload previews stay in this browser tab. Default reports omit raw payloads and redact common identifiers.

Can it capture live network traffic?

No. Browser pages cannot access arbitrary network interfaces. The tool reads existing PCAP or PCAPNG files produced by trusted capture software.

Does a finding prove an attack?

No. Cleartext headers, resets, DNS errors and retransmission hints are evidence for investigation, not proof of compromise or attribution.

Keep working with other focused browser utilities.

All tools

Local by default; remote data sources are clearly disclosed.

© 2026 Nobuf

Nobuf

Fast, local-first utilities powered by your browser.