PCAP analysis

Trace the failure back to the app.

Turn live traffic or a PCAP into focused sessions, decoded packets, and evidence support can act on.

  • PCAP + PCAPNG
  • Local analysis
  • macOS 14+

ONE PATH TO THE ANSWER

Capture. Isolate. Explain.

Throughput, sessions, app context, filters, and packet details stay in one view. Less tab switching. Faster answers.

Tracexy light interface showing live sessions grouped by application with a packet inspector
Tracexy dark interface showing live sessions grouped by application with a packet inspector

Capture

See the spike

Watch live traffic on the Mac interface carrying the failure.

Isolate

Find the owner

Jump to the app, domain, IP, or protocol behind the noise.

Prove

Read the packet

Use decoded layers, timing, and raw bytes to explain what failed.

CONTROL THE NOISE

Capture only what matters.

Choose the interface, apply BPF, and cap retention before recording. Smaller capture. Shorter investigation.

INTERFACE PICKER

Pick the path.

Wi-Fi, Ethernet, Thunderbolt, VPN, tunnels, or loopback.

Tracexy interface picker listing Wi-Fi, Ethernet, Thunderbolt, tunnel, VPN, and loopback capture sources
Tracexy capture settings with BPF filter, snap length, promiscuous mode, and packet retention controls

CAPTURE SETTINGS

Set limits before capture.

Control BPF, snap length, promiscuous mode, and retained packet count.

REPRODUCIBLE EVIDENCE

One capture. Fewer back-and-forths.

Open PCAP or PCAPNG. Save live traffic as PCAP. Give support a trace they can reproduce—after redacting secrets.

Capture

Record the failure

Collect the right interface with an optional BPF filter.

Reopen

Continue from PCAP

Rebuild sessions and packet details without recapturing.

Handoff

Give support evidence

Share the same reviewed trace with a teammate or packet tool.

PACKET INSPECTION

Read the packet. Explain the failure.

Decoded fields and raw bytes stay together. No context switching.

Tracexy horizontal packet inspector with decoded Ethernet, IPv4, UDP fields and hexadecimal bytes
Tracexy source tree grouping captured sessions by application, domain, and IP address

SOURCE ATTRIBUTION

Know which app opened the connection.

Start with the app, domain, or IP—not an anonymous endpoint.

THREE INSPECTOR VIEWS

Fields, timing, layers. One click apart.

Search the selected packet, then move between decoded values, timing, protocol layers, and hex.

Ethernet II IPv4 TCP / UDP Hex + ASCII
Tracexy vertical timing inspector showing total session duration

QUESTIONS TRACEXY CLOSES

Answer before the support thread goes cold.

DNS and routing

Which interface and host did the app use?

Correlate the route and address with the originating app.

Transport

Where did TCP, TLS, or QUIC fail?

Inspect ports, lengths, timing, and raw frames below HTTP.

Ownership

Which process created the traffic?

Separate browsers, CLIs, editors, agents, and helpers.

Handoff

Can someone else reproduce the evidence?

Save the trace, redact it, and attach the same PCAP to the ticket.

USE THE RIGHT TOOL

Compare the workflow. Pick your column.

Brands run across the top. Follow one column from capture to diagnosis, action, and support handoff.

Workflow comparison with criteria as rows and Tracexy, Wireshark, tcpdump, Little Snitch, Rockxy, and Charles as columns.
Decision point Tracexy Wireshark tcpdump Little Snitch Rockxy Charles
Primary jobMac app-aware packet triageDeep protocol analysis and forensicsShell and remote packet captureApp connection monitoring and firewall policyAPI and web traffic debuggingHTTP proxy inspection and intervention
Traffic sourceLive interfaces; PCAP and PCAPNGLive interfaces; many capture formatsSelected interface or saved captureLive Mac process connectionsProxy-captured HTTP(S), WebSocket, and GraphQLProxy-captured HTTP(S)
Context modelApps, sessions, domains, IPs, and protocolsPackets, streams, endpoints, and protocolsInterfaces, hosts, ports, and BPF expressionsApps, processes, servers, ports, and rulesSessions, domains, requests, errors, and logsHosts, paths, requests, and responses
Inspection depthDecoded layers, timing, fields, and raw bytesDeep dissectors, decryption, filters, and statisticsPacket summaries or raw output; analyze saved PCAP elsewhereConnection metadata and history, not decoded packetsHTTP fields, payloads, errors, and performance insightHTTP headers, bodies, cookies, and query data
Act on trafficEvidence-first; does not modify trafficAnalysis onlyCapture onlyAllow or deny connections with rulesReplay, intercept, compare, and rewrite flowsRepeat, breakpoints, rewrite, and throttling
Operating styleNative Mac UI with fast protocol and app filtersCross-platform GUI plus TShark CLIHeadless CLI, scripts, and pipelinesNative Mac UI with persistent firewall rulesNative debugging workspaceDesktop proxy workspace
Support handoffExport a focused PCAP for review and redactionShare captures, filters, and protocol findingsSave a reproducible PCAP from any shellShare connection history, rules, or screenshotsShare focused HTTP evidence and reproduction stepsExport proxy sessions for another analyst
Pick it whenYou know the failing Mac app, but not the failing network layerThe protocol itself needs expert-level inspectionA terminal is the fastest or only capture surfaceThe decision is whether an app should connectThe bug lives inside an API or web flowYou need to inspect or manipulate an HTTP exchange

A practical route: start in Tracexy when the failing Mac app is known but the network layer is not. Export to Wireshark for deeper protocol analysis; switch to Rockxy or Charles when the bug is clearly inside an HTTP flow. Product names are trademarks of their owners.

LOCAL BY DEFAULT

Your capture stays on your Mac.

No cloud account. No automatic upload to an AI service.

SHARE WITH INTENT

Send evidence, not guesswork.

Redact the PCAP, then hand the same trace to a teammate, support desk, Wireshark, or an AI assistant. Tracexy never sends it for you.

EARLY BIRD PRICING PREVIEW

Early Bird prices, with the final price in plain sight

One-time purchase. No subscription. Checkout is not open yet; these planned launch prices may change before sales begin.

No payment today
EARLY BIRD

Personal

1 Mac

Early Bird

$18

Final price

$28

Save $10· one time

One macOS activation with 12 months of updates and support.

LIFETIME UPDATES

Lifetime

2 Macs

Early Bird

$58

Final price

$98

Save $40· one time

Two macOS activations with lifetime app updates and 12 months of support.

No checkout today. Prices shown are planned launch targets. Joining the list does not reserve a license or guarantee the offer.

PRODUCT POLICY

The terms behind the price.

Tracexy is prelaunch. These rules explain what the preview means today and what a paid license will include when checkout opens.

Launch list

Joining sends your email, product choice, and launch-cohort metadata. It does not charge a card, create an account, reserve a license, or lock a price.

License scope

Personal covers 1 Mac. Multi-Mac and Lifetime cover 2 Macs. Activations apply to Macs you own or control.

Updates and support

Personal and Multi-Mac include 12 months of updates and support. Lifetime includes lifetime app updates and 12 months of support.

Payment and refunds

Prices are USD launch targets and may change. Tax and the final total appear at checkout. Paid licenses have a 14-day refund window.

Packet privacy

Analysis is local by default. Tracexy does not automatically upload packets to Rockxy or an AI service.

Responsible capture

Capture only networks and devices you own or are authorized to inspect. Review and redact PCAP files before sharing.

Terms · Privacy · Refund policy · Support

FAQ

Before you join

What is Tracexy?

A native macOS app for turning live traffic or saved captures into app-aware sessions, decoded packets, and shareable evidence.

Who is Tracexy for?

Developers, network engineers, QA teams, and support teams diagnosing Mac network failures.

Can Tracexy open PCAP and PCAPNG files?

Yes. It opens PCAP and PCAPNG files and exports retained live packets as classic PCAP.

Does Tracexy send packet data to the cloud or an AI service?

No. Analysis is local by default. Sharing a redacted capture is an explicit user action.

Is Tracexy available to buy now?

No. Joining the launch list records interest only. Nothing is charged today.

Which live interfaces and protocol views are included?

The preview captures selected Wi-Fi, Ethernet, Thunderbolt, VPN, tunnel, and loopback interfaces. It includes all-traffic, DNS, TCP, UDP, TLS, HTTP, HTTP/2, QUIC, WebSocket, and error views.

What should I check before capturing or sharing traffic?

Capture only traffic you are authorized to inspect. Packet files can contain credentials, tokens, and private payloads, so review and redact them before sharing.

How is Tracexy different from Rockxy?

Tracexy starts at a network interface for packet and session analysis across protocols. Rockxy is the HTTP debugging proxy for intercepting, inspecting, replaying, modifying, and comparing API traffic.

What does each planned license include?

Personal covers 1 Mac. Multi-Mac and Lifetime cover 2 Macs. Personal and Multi-Mac include 12 months of updates and support; Lifetime includes lifetime app updates and 12 months of support.

How will price, tax, delivery, and refunds work?

Displayed prices are USD launch targets and may change. Checkout shows the final total and tax before payment. A successful order is delivered to the checkout email and includes a 14-day refund window.

Spend less time proving the network problem.

Join the launch list. We will email you when Tracexy is ready—nothing is charged today.

Join Tracexy early bird