Packet Recon

Packet Recon

Read-only pcap analyzer

0 ratings
$9.99

Rating summary

Details

  • Released
  • Updated
  • June 16, 2026
  • September 13, 2026
Packet Recon screenshot #1 for iPhone
Packet Recon screenshot #2 for iPhone
Packet Recon screenshot #3 for iPhone
Packet Recon screenshot #4 for iPhone
Packet Recon screenshot #5 for iPhone
Packet Recon screenshot #6 for iPhone
Packet Recon screenshot #7 for iPhone
Packet Recon screenshot #8 for iPhone
Packet Recon screenshot #9 for iPhone
Packet Recon screenshot #10 for iPhone
iphone
ipad
🖼️Get Icon
Icons↘︎

About

Packet Recon opens pcap and pcapng captures and tells you what is in them. A capture arrives as a mail attachment or a shared link, and you are nowhere near your desk. The questions are the same as always. Is this the traffic I think it is? Does the thing I am looking for appear anywhere in it? Can this wait until Monday? Open the file and you land on a summary instead of row one of four hundred thousand. What stands out comes first: credentials sent in the clear, unencrypted HTTP, files that can be pulled out of the capture, TCP that went wrong. Below that sits the protocol mix, the busiest hosts, and who talked to whom. Tap any of it. The packet list narrows, and the filter it wrote appears in the bar above, so you can see what it did and change it. WHAT IT DOES • Opens .pcap, .pcapng and gzipped captures from Mail, Files, iCloud Drive and any share sheet • Handles captures far larger than memory. The index lives on disk, and two million packets scroll smoothly • The full display-filter grammar, with field autocomplete and mistakes marked as you type • Decode tree and hex view, with the bytes of the selected field lit up • Follow Stream for TCP and UDP, both directions or one at a time • Conversation, endpoint and protocol statistics, every row of them a filter • TLS without keys: server names, ALPN, JA3 and JA3S, offered cipher suites, the whole handshake tree • MAC vendor names from a table inside the app, so nothing is looked up over the network • Export the packets you filtered to as a new capture, or the list as CSV or JSON • Relative, local or UTC timestamps • Capture properties, including per-interface drop counts, so you know when the file itself is short iPad puts the packet list, decode tree and bytes on screen together. iPhone shows you the same three one at a time. Neither is missing anything the other has. WHAT THE MAC DOES THAT THIS DOES NOT Same engine, same decoders, same filter grammar. Two differences worth knowing before you buy. The Mac version decrypts TLS and QUIC when you have a key log from the client that made the connection. iOS does not, because a key log only exists if you instrumented that client, which means you were sitting at a workstation. Everything TLS tells you without keys is here. Pulling files and credentials out of a capture, coloring rules, custom columns and the HTML report are Mac features today. PRIVACY Packet Recon makes no network connections and collects no data. No analytics, no account, no telemetry, no server. Your captures stay on your device unless you export and share them yourself. It reads captures. It cannot make them, because iOS does not allow that.
Show more

What's New in Packet Recon

1.0

September 13, 2026

Developer apps