TracePcap Documentation
TracePcap is a self-hosted PCAP analysis workbench for black-box network analysis — situations where you work from captured traffic alone, with no prior knowledge of the network. It derives device inventory, topology, session content, and behavioural patterns purely from observed packets, making it well-suited for network audits, incident response, penetration test reconnaissance, and research.
Designed for air-gapped and offline deployments — GeoIP lookups use a bundled offline database by default, with optional enrichment via ipinfo.io when internet access is available.
Getting Started
Features
- PCAP Upload & Management
- Network Visualization
- Network Intelligence
- Cross-PCAP Comparison
- nDPI Security Analysis
- Conversations
- Session Reconstruction
- File Extraction
- Geolocation & Device Classification
- MAC Manufacturer Lookup
- Timeline Analysis
- AI Filter Generator
- Story Mode
- Custom Signature Rules
- PDF Report Export
- Network Monitor
- Streaming / Automated PCAP Upload
Configuration
Reference