Input

Load: port scan sample Load: C2 beaconing sample Load: DNS tunneling sample Load: benign traffic

Filters

Paste packet text and click Parse and Analyze.
Heuristic analyzer — patterns flagged are signals, not verdicts. Real traffic analysis needs full pcap (binary) inspection in Wireshark/tshark/Zeek. This tool serves quick triage and learning.
Sample data uses RFC 5737 / RFC 1918 synthetic IPs. *.example.com hosts. No real traffic.