Enterprise packet investigation · Security

Find what your NDR missed. Prove it in the packets.

Upload a PCAP and combine signatures, offline threat intelligence, behavioral C2, tunnels, attack paths, and east-west findings with explicit coverage and exact packet evidence. PacketSafari complements live NDR, EDR, and XDR—it is not a continuous network monitor.

Security investigationdns-tunnel-iodine.pcap

Capture evidence available

Current evidence candidate

Encoded TXT queries form a sustained outbound transfer pattern.

Signal
Long labels · small replies · steady retries
Detector
Deterministic DNS behavior
Coverage
Complete capture evidence
Evidence
Frames 104–402
dns.qry.type == 16 && ip.addr == 10.12.4.18

Contain 10.12.4.18 and investigate the queried domain.

A signature, tunnel, or periodic connection is evidence to investigate—not automatic proof of compromise.

DNS view uses the public sample; other tabs explain implemented detection paths.

Living off the Network

Attackers stay off the endpoint. The network still records the path.

Advanced actors increasingly target firewalls, VPN appliances, hypervisors, IoT, cameras, VoIP, and infrastructure where EDR cannot run or has weak visibility. Compromised systems become bridges through trusted protocols and encrypted paths.

Endpoint-visibleEDR coverage
Workstation Server Admin host
Endpoint blind spotPacket visibility matters
Firewall / VPN Hypervisor Camera / IoT VoIP
  1. 1Internet
  2. 2VPN edge
  3. 3Management plane
  4. 4Internal service
PacketSafari evidenceNetwork path reconstructed
  • IDS match
  • Unexpected management connection
  • New internal target
  • Exact packet pivots

Explanatory attack paths—not customer findings. Packet evidence complements endpoint and infrastructure telemetry.

Explanatory map contrasting EDR-covered endpoints with network-device blind spots and the packet evidence preserved along four modern attack paths.

SSH and SOCKS pivots

SMB, DCERPC, RDP, WinRM, and WMI

DNS, VPN, and encrypted sessions

Packet evidence beside endpoint telemetry

Security proof, counted

Ten named paths. One defensible investigation.

The PacketSafari Core Engine finds and preserves deterministic evidence. Agent focuses the investigation, explains the result, and guides the analyst back to exact packets.

54k+
Loaded signaturesSuricata-compatible signatures in the last qualified production profile.
27k+
ATT&CK-enrichedActive-feed signatures carrying MITRE ATT&CK metadata.
10
Named evidence pathsNine available paths plus one explicitly qualification-only cadence lead.
30
Protocol specialistsRelevant specialists activate for supported traffic in the capture.
150+
Curated investigationsExpert-reviewed PCAP investigations and protocol playbooks.
20+ years
Analysis experiencePractical packet and network-analysis experience shaping the workflow.
01Signatures and intelligence

Known indicators retain their source, revision, coverage, and exact packet or connection pivot.

  • Suricata-compatible signature detection
  • Stamus east-west and lateral-movement rules
  • Offline IP, network, domain, URL, and file-hash intelligence
02Behavior and attack paths

Independent packet behavior finds suspicious activity that a signature-only review can miss.

  • Behavioral and periodic C2 detection
  • DNS tunnel and covert-channel analysis
  • Active Directory and RDP proxy attack-path correlation
  • Aggregate scan and flood detection
  • OT command anomalies
03Correlation and qualification

Cross-connection findings remain reviewable while emerging signals stay clearly qualified.

  • Exact east-west findings with bounded packet pivots
  • Payload-cadence leads — qualification only

Prove the business case

Measure the reduction during evaluation.

Compare the team’s current investigation baseline with the same captures and questions in PacketSafari. No invented “faster” percentage.

  1. 01Time to first defensible finding
  2. 02Analyst minutes to validate a candidate
  3. 03Manual packet pivots avoided
  4. 04Escalation cycles reduced
  5. 05Verifier disposition and evidence acceptance

The 54k+ and 27k+ claims remain the last qualified PacketSafari production-profile counts. Feed revisions and compatibility filtering can change both counts. Payload cadence remains qualification-only.

Detection foundation

Fast direction when needed. Complete coverage when required.

The PacketSafari Core Engine combines deterministic packet processing with AI investigation. It does not replace required IDS or behavioral processing with a model guess.

  1. 01Every-packet IDS

    Choose quick partial screening or a separately tracked complete-capture verification milestone.

  2. 02Behavior over signatures

    Correlate beaconing, DNS tunnels, covert channels, scans, lateral movement, and suspicious connection behavior.

  3. 03Reproducible intelligence

    Preserve local, ET Open, Stamus, and enabled Abuse.ch source provenance, revision, severity, and exact alerts.

  4. 04Truthful coverage

    Clean, partial, unavailable, and failed outcomes stay distinct; missing evidence never becomes a clean scan.

30,000+PCAPs across the full corpus

PacketSafari trains and tests its Agent on 150+ expert-curated PCAP investigations and protocol playbooks, shaped by 20+ years of real-world packet analysis.

The compact periodic-C2 model is accepted on a curated capture corpus with deliberately limited validation and fails closed if its artifact is unavailable or invalid. It is not claimed to be trained on the full PacketSafari corpus.