Incident response

The TLS handshake that wouldn't decrypt

A TLS session never completes. Why did the next request fail?

1
Load the capture, decrypt with the customer's keylog.
2
Extract the certificate chain.
3
Search across the decrypted stream.
4
Star the frame, write a case note, export the report.
Root cause found in one session - the server's own idle timeout, not a client bug.
Bug reproduction

Reproducing a malformed frame for a bug report

A parser crashes on one frame in a 40,000-frame capture.

1
Run a health check across the capture.
2
Isolate just that frame.
3
Edit the byte, confirm the fix, keep the original too.
4
Attach both as a minimal .pcap.
A 40,000-frame capture becomes a 2-frame repro.
Threat hunting

Tracing a DNS exfiltration attempt

An endpoint sends unusual DNS volume. Which host, which domain, how long?

1
Filter to just DNS.
2
Extract every distinct query name.
3
Confirm the source with Conversations.
4
Star the pattern, save the filter, hand off the findings.
One host, one pattern, one saved filter for the next time it happens.
Test engineering

Turning one capture into a thousand test cases

A new parser needs malformed and edge-case variants, not one clean capture.

1
Mutate the reference frame.
2
Generate a numbered series for the clean cases.
3
Batch-recalculate seq/ack and checksums across the whole set.
4
Export the corpus as raw-frames JSON.
One capture, checked into CI as a real regression suite.
Detection engineering

Testing a detection rule with traffic you build

A new IDS rule needs traffic that matches it, and nobody has a capture of the attack.

1
Compose the request in the HTTP builder.
2
Write the evasion variant as a Craft lab expression.
3
Run the health check, so a miss means the rule and not a bad frame.
4
Export both streams as one pcap and replay it.
A repeatable test capture for the rule, with no live attack needed.
Data sharing

Sharing a capture without sharing your network

A vendor needs your capture, but it is full of real addresses.

1
Define a rewrite preset for MACs, IPs and ports.
2
Apply it to every frame with Batch apply.
3
Run the health check to confirm checksums and lengths.
4
Export the scrubbed capture as pcap.
A shareable capture with no real addresses in it.
Network testing

Replaying an IPv4 capture over IPv6

A service is moving to IPv6, and the only good capture is IPv4.

1
Open the IPv4 capture.
2
Convert the frames to IPv6 with the NAT64 prefix.
3
Rewrite the addresses to your IPv6 test hosts.
4
Export the result as pcap.
An IPv6 version of traffic you already trust.
Web testing

Turning a browser session into packets

A bug only shows up in a recorded browser session, and your tools need a pcap.

1
Import the HAR or Fiddler SAZ file.
2
Edit the request or response in the frame detail.
3
Rewrite the addresses to point at the lab server.
4
Export the frames as pcap.
A recorded session you can edit and replay as real TCP and HTTP.
Protocol testing

Crafting a DNS answer for a resolver test

A resolver needs one specific answer, TTL and record set to test against.

1
Build the query and its matching response in the DNS builder.
2
Set the answer records and TTLs.
3
Run the health check.
4
Export the pair as pcap.
A pair of DNS packets with exactly the answer you need.

Bring your own capture

Every scenario above starts the same way - a file, or nothing at all.

Request a license
All Rights Reserved © 2026 Netomize