Capture
See the spike
Watch live traffic on the Mac interface carrying the failure.
PCAP analysis
Turn live traffic or a PCAP into focused sessions, decoded packets, and evidence support can act on.
ONE PATH TO THE ANSWER
Throughput, sessions, app context, filters, and packet details stay in one view. Less tab switching. Faster answers.
Capture
Watch live traffic on the Mac interface carrying the failure.
Isolate
Jump to the app, domain, IP, or protocol behind the noise.
Prove
Use decoded layers, timing, and raw bytes to explain what failed.
CONTROL THE NOISE
Choose the interface, apply BPF, and cap retention before recording. Smaller capture. Shorter investigation.
INTERFACE PICKER
Wi-Fi, Ethernet, Thunderbolt, VPN, tunnels, or loopback.
CAPTURE SETTINGS
Control BPF, snap length, promiscuous mode, and retained packet count.
REPRODUCIBLE EVIDENCE
Open PCAP or PCAPNG. Save live traffic as PCAP. Give support a trace they can reproduce—after redacting secrets.
Capture
Collect the right interface with an optional BPF filter.
Reopen
Rebuild sessions and packet details without recapturing.
Handoff
Share the same reviewed trace with a teammate or packet tool.
PACKET INSPECTION
Decoded fields and raw bytes stay together. No context switching.
SOURCE ATTRIBUTION
Start with the app, domain, or IP—not an anonymous endpoint.
THREE INSPECTOR VIEWS
Search the selected packet, then move between decoded values, timing, protocol layers, and hex.
QUESTIONS TRACEXY CLOSES
DNS and routing
Correlate the route and address with the originating app.
Transport
Inspect ports, lengths, timing, and raw frames below HTTP.
Ownership
Separate browsers, CLIs, editors, agents, and helpers.
Handoff
Save the trace, redact it, and attach the same PCAP to the ticket.
USE THE RIGHT TOOL
Brands run across the top. Follow one column from capture to diagnosis, action, and support handoff.
| Decision point | Tracexy | Wireshark | tcpdump | Little Snitch | Rockxy | Charles |
|---|---|---|---|---|---|---|
| Primary job | Mac app-aware packet triage | Deep protocol analysis and forensics | Shell and remote packet capture | App connection monitoring and firewall policy | API and web traffic debugging | HTTP proxy inspection and intervention |
| Traffic source | Live interfaces; PCAP and PCAPNG | Live interfaces; many capture formats | Selected interface or saved capture | Live Mac process connections | Proxy-captured HTTP(S), WebSocket, and GraphQL | Proxy-captured HTTP(S) |
| Context model | Apps, sessions, domains, IPs, and protocols | Packets, streams, endpoints, and protocols | Interfaces, hosts, ports, and BPF expressions | Apps, processes, servers, ports, and rules | Sessions, domains, requests, errors, and logs | Hosts, paths, requests, and responses |
| Inspection depth | Decoded layers, timing, fields, and raw bytes | Deep dissectors, decryption, filters, and statistics | Packet summaries or raw output; analyze saved PCAP elsewhere | Connection metadata and history, not decoded packets | HTTP fields, payloads, errors, and performance insight | HTTP headers, bodies, cookies, and query data |
| Act on traffic | Evidence-first; does not modify traffic | Analysis only | Capture only | Allow or deny connections with rules | Replay, intercept, compare, and rewrite flows | Repeat, breakpoints, rewrite, and throttling |
| Operating style | Native Mac UI with fast protocol and app filters | Cross-platform GUI plus TShark CLI | Headless CLI, scripts, and pipelines | Native Mac UI with persistent firewall rules | Native debugging workspace | Desktop proxy workspace |
| Support handoff | Export a focused PCAP for review and redaction | Share captures, filters, and protocol findings | Save a reproducible PCAP from any shell | Share connection history, rules, or screenshots | Share focused HTTP evidence and reproduction steps | Export proxy sessions for another analyst |
| Pick it when | You know the failing Mac app, but not the failing network layer | The protocol itself needs expert-level inspection | A terminal is the fastest or only capture surface | The decision is whether an app should connect | The bug lives inside an API or web flow | You need to inspect or manipulate an HTTP exchange |
A practical route: start in Tracexy when the failing Mac app is known but the network layer is not. Export to Wireshark for deeper protocol analysis; switch to Rockxy or Charles when the bug is clearly inside an HTTP flow. Product names are trademarks of their owners.
LOCAL BY DEFAULT
No cloud account. No automatic upload to an AI service.
SHARE WITH INTENT
Redact the PCAP, then hand the same trace to a teammate, support desk, Wireshark, or an AI assistant. Tracexy never sends it for you.
EARLY BIRD PRICING PREVIEW
One-time purchase. No subscription. Checkout is not open yet; these planned launch prices may change before sales begin.
No payment todayPersonal
Early Bird
$18
Final price
$28
Save $10· one time
One macOS activation with 12 months of updates and support.
Multi-Mac
Early Bird
$28
Final price
$38
Save $10· one time
Two macOS activations with 12 months of updates and support.
Lifetime
Early Bird
$58
Final price
$98
Save $40· one time
Two macOS activations with lifetime app updates and 12 months of support.
No checkout today. Prices shown are planned launch targets. Joining the list does not reserve a license or guarantee the offer.
PRODUCT POLICY
Tracexy is prelaunch. These rules explain what the preview means today and what a paid license will include when checkout opens.
Joining sends your email, product choice, and launch-cohort metadata. It does not charge a card, create an account, reserve a license, or lock a price.
Personal covers 1 Mac. Multi-Mac and Lifetime cover 2 Macs. Activations apply to Macs you own or control.
Personal and Multi-Mac include 12 months of updates and support. Lifetime includes lifetime app updates and 12 months of support.
Prices are USD launch targets and may change. Tax and the final total appear at checkout. Paid licenses have a 14-day refund window.
Analysis is local by default. Tracexy does not automatically upload packets to Rockxy or an AI service.
Capture only networks and devices you own or are authorized to inspect. Review and redact PCAP files before sharing.
Terms · Privacy · Refund policy · Support
FAQ
A native macOS app for turning live traffic or saved captures into app-aware sessions, decoded packets, and shareable evidence.
Developers, network engineers, QA teams, and support teams diagnosing Mac network failures.
Yes. It opens PCAP and PCAPNG files and exports retained live packets as classic PCAP.
No. Analysis is local by default. Sharing a redacted capture is an explicit user action.
No. Joining the launch list records interest only. Nothing is charged today.
The preview captures selected Wi-Fi, Ethernet, Thunderbolt, VPN, tunnel, and loopback interfaces. It includes all-traffic, DNS, TCP, UDP, TLS, HTTP, HTTP/2, QUIC, WebSocket, and error views.
Capture only traffic you are authorized to inspect. Packet files can contain credentials, tokens, and private payloads, so review and redact them before sharing.
Tracexy starts at a network interface for packet and session analysis across protocols. Rockxy is the HTTP debugging proxy for intercepting, inspecting, replaying, modifying, and comparing API traffic.
Personal covers 1 Mac. Multi-Mac and Lifetime cover 2 Macs. Personal and Multi-Mac include 12 months of updates and support; Lifetime includes lifetime app updates and 12 months of support.
Displayed prices are USD launch targets and may change. Checkout shows the final total and tax before payment. A successful order is delivered to the checkout email and includes a 14-day refund window.
Join the launch list. We will email you when Tracexy is ready—nothing is charged today.
Join Tracexy early bird