# Packet Recon — Read-only pcap analyzer

> Read-only pcap analyzer (iPhone/iPad app by Brian Reed.)

- Source: https://appshunter.io/ios/app/packet-recon/id6779393192 (this page in markdown: same URL + `.md`)
- Developer: [Brian Reed](https://appshunter.io/developer/6775352024)
- Category: Utilities, Developer Tools
- Price: $9.99
- Age rating: 4+
- Requires: iOS 18.0 · 4 MB
- Languages: American English
- Released: 2026-06-16
- Data updated: 2026-09-18
- User reviews in markdown: https://appshunter.io/ios/app/packet-recon/id6779393192/reviews.md

## What is Packet Recon?

Packet Recon opens pcap and pcapng captures and tells you what is in them.

A capture arrives as a mail attachment or a shared link, and you are nowhere near your desk. The questions are the same as always. Is this the traffic I think it is? Does the thing I am looking for appear anywhere in it? Can this wait until Monday?

Open the file and you land on a summary instead of row one of four hundred thousand. What stands out comes first: credentials sent in the clear, unencrypted HTTP, files that can be pulled out of the capture, TCP that went wrong. Below that sits the protocol mix, the busiest hosts, and who talked to whom. Tap any of it. The packet list narrows, and the filter it wrote appears in the bar above, so you can see what it did and change it.

WHAT IT DOES

• Opens .pcap, .pcapng and gzipped captures from Mail, Files, iCloud Drive and any share sheet
• Handles captures far larger than memory. The index lives on disk, and two million packets scroll smoothly
• The full display-filter grammar, with field autocomplete and mistakes marked as you type
• Decode tree and hex view, with the bytes of the selected field lit up
• Follow Stream for TCP and UDP, both directions or one at a time
• Conversation, endpoint and protocol statistics, every row of them a filter
• TLS without keys: server names, ALPN, JA3 and JA3S, offered cipher suites, the whole handshake tree
• MAC vendor names from a table inside the app, so nothing is looked up over the network
• Export the packets you filtered to as a new capture, or the list as CSV or JSON
• Relative, local or UTC timestamps
• Capture properties, including per-interface drop counts, so you know when the file itself is short

iPad puts the packet list, decode tree and bytes on screen together. iPhone shows you the same three one at a time. Neither is missing anything the other has.

WHAT THE MAC DOES THAT THIS DOES NOT

Same engine, same decoders, same filter grammar. Two differences worth knowing before you buy.

The Mac version decrypts TLS and QUIC when you have a key log from the client that made the connection. iOS does not, because a key log only exists if you instrumented that client, which means you were sitting at a workstation. Everything TLS tells you without keys is here.

Pulling files and credentials out of a capture, coloring rules, custom columns and the HTML report are Mac features today.

PRIVACY

Packet Recon makes no network connections and collects no data. No analytics, no account, no telemetry, no server. Your captures stay on your device unless you export and share them yourself.

It reads captures. It cannot make them, because iOS does not allow that.


## Version history (last 1 release)

### 1.0 — 2026-09-13

No release notes.

## More apps by Brian Reed

- [IP Recon](https://appshunter.io/ios/app/ip-recon/id6775352022)
- [Cert Recon](https://appshunter.io/ios/app/cert-recon/id6779392135)
- [DNS Recon](https://appshunter.io/ios/app/dns-recon/id6779392375)
- [SNMP Recon](https://appshunter.io/ios/app/snmp-recon/id6779393528)
- [Egress Recon](https://appshunter.io/ios/app/egress-recon/id6779964708)

All apps by Brian Reed: https://appshunter.io/developer/6775352024

---

*Data collected daily from the US App Store and indexed by [AppsHunter](https://appshunter.io/). User reviews are verbatim App Store reviews. Ratings, prices and chart positions refresh continuously; this snapshot is from 2026-09-18.*
