Full capability list

Everything Frame Bench does

One frame table underneath. Edit a byte and every view updates.

See protocol coverage Read the scenarios
5guided packet builders, plus Craft lab
70built-in protocols, link layer to application
TLS · QUICdecrypt from a keylog, exported back to pcap
0 bytessent anywhere - it runs fully offline
01

Editing and integrity

Every edit is undoable and checked.

Frame #48 · health check 2 issues fixed
IPv4 total_length 40 → 46 ✓
TCP checksum 0x4a12 → 0x0a92 ✓
Ethernet padding 6 bytes · left untouched

Byte-level hex editing

Type into any offset, or cut, copy and paste ranges as hex, text or a C array.

Health check auto-fix

Recomputes lengths and checksums after every edit, padding included.

Undo, redo, revert

Undo a whole batch in one step, or revert every changed frame at once.

Notes and comments

Annotate a byte range or a frame. Exports keep them.

02

Crafting frames

From a guided form to a batch run across a whole capture.

Batch apply - Recalculate TCP seq/ack
ScopeChecked frames · 3
Client seq
1000
Server seq
2000000
Renumbers every frame in the stream - not just the checked ones - so seq/ack stay consistent end to end.
9 of 9 frames affected Apply

Guided builders

TCP, UDP, DNS, ICMP, ARP and HTTP from real fields, with checksums done for you.

Craft lab

Expressions, series, mutation and fuzzing, and ready-made multi-frame scenarios.

Batch apply

XOR, add a template, rewrite addresses or recalculate seq/ack across many frames.

Templates and library

Save custom layouts and crafted frames. Reuse them in any capture.

03

Analysis and decryption

The views you expect, next to the frame table.

TLS decrypt - Certificate
Subject
CN=*.cloudflare-quic.com
Issuer
CN=DigiCert TLS RSA SHA256 2020 CA1
TLS 1.3 AES-128-GCM
GET /resource/v2 HTTP/2
200 OK · application/json · 812 B

TLS and QUIC decrypt

From a keylog or PcapNG secrets, with certificate extraction and search.

Conversations and hosts

Protocol hierarchy, hosts and ports, and a graph that selects frames on click.

RTP streams

Loss, reordering and jitter per stream.

Filter language

Autocomplete, presets and fields like http.status and frame.cap_len.

Extract field values

Every distinct value of a field, counted and traced to its frames.

Signature search

Find byte patterns across the whole capture.

04

Workspace

Pick up where you left off.

Recent sessions
incident_2026-09-14_session.json 2 min ago
quic_repro_session.json yesterday
dns_exfil_draft_session.json 3 days ago

Sessions

Save frames, templates, rules and filters as one file. Restore it later.

Views, filters, coloring

Saved table views and rules, with a live preview as you tune a color.

Compare frames

Byte diff of up to five frames. Export as HTML, Markdown or unified diff.

05

Built for big captures

Multi-gigabyte files without a frozen window.

live_capture.pcapng watching
Indexed2.3 GB
Loaded18,402 of 4.1M frames
New since open+612 frames

Large-capture mode

Indexes the file and loads only the range or filter you pick.

Streaming export

Writes filtered output straight to disk in chunks.

Live re-indexing

Watches a growing capture and offers its new frames.

06

Export what changed

The whole capture, only your edits, or a filtered slice.

.pcap and PcapNG

With embedded TLS secrets and custom metadata.

HTML report

A color-tinted frame list you can share without the capture.

Raw-frames JSON

Lossless, diffable, with notes and comments.

Settings file

Templates, presets and rules in one portable file.

07

Transform and import

Change what a frame is, or bring in what was never a pcap.

Convert frame - IPv4 to IPv6
IPv4 203.0.113.9
NAT64 prefix 64:ff9b::/96
IPv6 64:ff9b::cb00:7109
TTL/Hop Limit carried across. IPv4 options and IPv6 extension headers aren't - dropped, not guessed at.

TCP and UDP conversion

Convert a stream either way. Seq/ack and checksums are rebuilt.

IPv4 and IPv6 conversion

Stateless NAT64 translation through a configurable /96 prefix.

Fiddler SAZ and HAR import

Sessions arrive as real, editable TCP and HTTP frames.

Rewrite addresses

A saved MAC, IP and port preset, applied to every frame in scope.

Edit timestamps

Set a time exactly or shift by an offset, per frame or for the whole capture.

Which protocols?

Every protocol Frame Bench understands, by layer

A searchable list of what Frame Bench decodes and builds.

Open protocol coverage
21link-layer formats
18network-layer protocols
5transport protocols
26application protocols

See these capabilities strung into a real workflow

See nine scenarios, start to finish.

Read the scenarios
All Rights Reserved © 2026 Netomize