Skip to content
PacketSense
Packet forensics

Evidence that survives a second opinion.

Packet forensics is reconstructing what happened on a network from captured traffic — in a way another analyst can verify. PacketSense keeps every conclusion linked to the frames behind it, and runs entirely on your machine, so the evidence never has to leave the building.

The short version

Logs show what a device chose to record. Packets show what actually crossed the wire — which is why capture evidence so often settles the question during an incident, an insider investigation or a dispute with a vendor. The hard part is not reading packets; it is producing a reconstruction someone else can check. PacketSense is built around that: findings carry their packet references, gaps are stated rather than glossed over, and the whole workflow runs locally.

The workflow

Four stages, one chain of reasoning.

A forensic pass is not a faster triage — it is a different standard of proof. Each stage exists to keep the next one verifiable.

01

Preserve the evidence

Work from a copy, not the original. PacketSense reads captures without rewriting them, and local integrity hashes let you confirm the file you are analysing today is the file you were given.

02

Establish scope

Determine what the capture actually covers — the time window, the vantage point, the interfaces. Knowing what the evidence cannot show is as important as knowing what it can.

03

Reconstruct the sequence

Follow the conversations that matter: streams, flows, timing and protocol behaviour, assembled into an order of events you can walk another analyst through.

04

Package the finding

Produce a report where each conclusion carries the packet references behind it, so a reviewer can re-open the capture and check the claim rather than take it on trust.

Defensibility

What separates a finding from a guess.

Three properties decide whether a reconstruction holds up when someone pushes back on it.

Every claim links to frames

A finding that cannot be traced back to specific packets is an opinion. PacketSense keeps the reference attached, so any conclusion can be re-opened against the original capture.

Integrity you can re-check

Local integrity hashing lets you confirm a capture has not changed between sessions — useful when evidence passes between people or sits untouched for weeks.

Honest about the gaps

Where a stream cannot be reconstructed or the capture is partial, PacketSense says so. Silence about a gap is how a reconstruction quietly becomes wrong.

PacketSense supports your evidence process — it does not make legal admissibility determinations, which remain a matter for your organisation and jurisdiction.

Evidence sources

Whatever the evidence arrived as.

Investigations rarely hand you a clean PCAP. Every supported source normalises into one inspectable packet model.

PCAP & PCAPNG

The files you already collect from Wireshark, tcpdump, a SPAN port or a capture appliance.

Live capture

Capture directly from an interface when the evidence is still on the wire.

Text evidence

FortiGate-style sniffer output and hex dumps, normalised into the same inspectable packet model.

Where it applies

When the packets are the deciding evidence.

Forensic packet work tends to show up at the moments where being approximately right isn't good enough.

  • Incident response — establishing what an attacker reached, and what they did not.
  • Insider and internal investigations, where the capture cannot leave the organisation.
  • Regulated and air-gapped environments under legal hold or audit.
  • Vendor and carrier disputes, where each side has a different account of events.
  • Post-incident review, turning a resolved outage into evidence others can learn from.
FAQ

Packet forensics — common questions.

What is packet forensics?

Packet forensics is the practice of reconstructing what happened on a network from captured traffic, in a way that another analyst can verify. Unlike log analysis, which shows what a device chose to record, packet evidence shows what actually crossed the wire — which is why it is often the deciding source during an incident or a dispute.

How is packet forensics different from packet analysis?

Packet analysis asks "what is happening?" — packet forensics asks "what happened, and can I prove it?" The difference is traceability. A forensic workflow keeps every conclusion linked to the specific frames that support it, records what the evidence does not cover, and produces output another analyst can independently re-check against the original capture.

How does PacketSense keep packet evidence defensible?

Every finding stays linked to the frames it came from, so any conclusion can be re-opened and checked against the original packets. Captures are processed on your own machine, local integrity hashes let you confirm a file has not changed between sessions, and reports carry the packet references rather than screenshots. PacketSense supports your evidence process — it does not make legal admissibility determinations, which remain a matter for your organisation and jurisdiction.

Can PacketSense analyze captures from a firewall or IDS instead of a PCAP?

Yes. Alongside PCAP and PCAPNG files and live capture, PacketSense imports text-based evidence such as FortiGate-style sniffer output and hex dumps, normalising them into the same inspectable packet model. That means evidence recovered from a firewall console is as traceable as a native capture file.

Does a network forensics investigation need to send captures to the cloud?

Not with PacketSense. Raw captures are processed locally by default, which is what makes it usable on evidence that cannot leave a building — regulated environments, air-gapped networks, internal investigations, or anything under legal hold. Optional cloud AI stays off unless an organisation explicitly enables it.

Put a real capture through the workflow.

Bring a capture from an investigation you've already closed and see whether the reconstruction holds. PacketSense is in active pilot for network, SOC and IR teams.