PacketSafari Triage · Documentation · PacketSafariPacketSafari Triage How PacketSafari builds right-sized, evidence-backed context for small and huge PCAPs. PacketSafari Triage is the non-AI evidence layer that turns a raw PCAP into a reusable map of connections, protocol signals, rule matches, security findings, and exact packet evidence. Agent, Copilot, dashboards, and analysts use that map without asking a model, a browser, or an analyst to read every packet as text. What triage means Triage is not a generic summary. PacketSafari organizes the capture, extracts metadata, runs rule and protocol analysis, ranks signals, and prepares reusable evidence outputs that remain tied to reproducible packet evidence. Those outputs can include: packet counts, timing, encapsulation, and open-ready metadata endpoint, conversation, protocol, DNS, TLS, security, VoIP, Wi-Fi, OT, telco, file-object, and infrastructure signals when the capture supports them PacketStats rule findings ranked by triage priority packet hotspots and frame ranges that help an analyst pivot into evidence Agent-ready context for Fast + verification follow-ups and Triage then report runs Why it matters for large captures Large PCAPs fail when every workflow assumes the whole file must be fully scanned or converted into text before anything useful can happen. PacketSafari separates the work into right-sized stages: Stage Purpose Open ready Store the PCAP, collect enough metadata, and open packet-level tools quickly. PacketSafari Triage Build the packet evidence map: rules, protocol landmarks, priorities, and reusable evidence outputs. Refinement and on-demand work Prepare deeper evidence when policy, size, entitlement, and user action justify it. Full scan Run every-packet PacketStats rule coverage when an owner or admin needs authoritative full-capture rule stats. The upload policy gives small captures complete rule stats below 50 MiB. Larger captures use the first 1,000,000 frames for upload-time PacketStats rule coverage so analysts get useful triage context without blocking first use on very large files. A full scan can still be started later when every packet needs rule coverage. How triage supports the Agent workflows Triage then report waits for triage context before Agent starts. Use it when the first answer needs broad correlation, priority flows, protocol context, or security signals. Its first report is the Final Report after fresh adjudication over that indexed context. Agent breadth is adaptive by default: it expands into broader exploration only when ranked evidence is weak, conflicting, or unresolved. Advanced settings can force broader exploration; that changes Agent work after Triage, not the Triage coverage itself. Fast answer starts Agent as soon as the file is safely readable. Use it for urgent, bounded packet questions when speed matters more than complete triage context. It requires a concrete operator-entered question or focused starting point, not a generic preset-only request. A specific symptom may qualify without an exact selector; a large unfocused root-cause capture should use structured focus or Triage first. Fast answer produces one preliminary report and does not automatically create an independent Verification or Final Report. Fast + verification deliberately uses both paths: a bounded preliminary Agent starts from a concrete operator question while PacketSafari Triage runs. A preset alone does not enable this early start. A fresh Targeted Verifier checks every strong preliminary candidate without waiting for full Triage. Triage continues independently, then Final Report adjudication checks all typed evidence against the wider map and can supersede an earlier outcome. See Investigation Path Guide. Confidential analysis story PacketSafari Triage is also part of the confidential-analysis model. Teams can choose the right evidence boundary for the case: use hosted SaaS for lower-risk captures use anoncap when an anonymized sibling capture is enough use private AI paths or on-prem deployment when raw PCAP evidence must stay inside a controlled environment use PacketSafari Triage to give Agent and analysts a consistent evidence map on PCAPs of many sizes The practical goal is confidential PCAP analysis that is right-sized for the capture: anonymized or private where needed, evidence-backed by PacketSafari Triage, and not limited to traces small enough for manual review. Related pages PacketSafari Triage overview Upload PCAPs Agent Raw-First Captures Analysis Readiness and Refinement Processing Runtime and Adaptive Analysis