Import
Select a PCAP or PCAPNG through the system file picker. The current Lite/Sight builds create a protected working copy inside the Kestrel sandbox.
FILE → PROTECTED WORKSPACEKestrel turns PCAP and PCAPNG captures into packets, flows, hosts, DNS, TCP streams, timelines, bookmarks, and reports on iPhone and iPad. Lite and Sight ship today. Pro is the advanced analysis branch in development. Analysis is processed locally rather than sent to a Tracivex cloud service.
Kestrel organizes the capture into progressively more useful layers without turning the workflow into a desktop packet-analyzer clone.
Select a PCAP or PCAPNG through the system file picker. The current Lite/Sight builds create a protected working copy inside the Kestrel sandbox.
FILE → PROTECTED WORKSPACETurn capture records into searchable packets with protocol, endpoint, timing, and payload context.
PACKETS · FILTERS · PROTOCOLSCollapse individual packets into flows, hosts, DNS activity, and timeline context so the capture starts telling a story.
FLOWS · HOSTS · DNSIn the shipping standard path, reconstruct TCP streams for captures under 1 GB. Pro is developing a newer disk-backed reconstruction path.
TCP STREAMSSight adds bookmarks, raw payload text search, enhanced IPv6 display, and refined reports. Pro adds advanced detection and evidence-oriented tooling in development.
BOOKMARKS · REPORTS · PROLite and Sight share the current shipping core. Sight removes the Lite packet cap and adds the professional investigation workflow.
Everything in Lite, without the 50,000-packet display cap, plus the tools for a more deliberate investigation.
At 1 GB and above, Lite and Sight switch to a streaming/header-first path, disable TCP reassembly, and reduce raw payload text-search coverage to the indexed packet region. Detailed limits are published below.
Pro is shown as development work, not as a shipping feature set. It also carries newer revisions of parts of the shared core while that hardening work continues.
Kestrel Pro is the advanced investigation tier in development. It adds detection and artifact workflows on top of the Kestrel core while the underlying flow identity, reconstruction, link-layer handling, and evidence-processing paths are also being hardened.
Swipe through the shipping Sight interface on iPhone and iPad. Click either device to open the full-size viewer.
Swipe or use the arrows · Click an image to enlarge
The matrix keeps shipping capability separate from Pro development claims.
* Pro is in development. Development behavior can change before release.
Packet density, available storage, and the device memory budget can matter more than a capture’s raw file size.
Under 1 GB, the current shipping builds use the standard analysis path with automatic TCP reassembly.
Pro’s development branch can move large reconstructed streams out of RAM, but packet-index memory still scales with packet count.
Captures up to 500 MB receive SHA-256 over the capture contents. Above 500 MB, the current shipping build displays a SHA-256 value derived from file size, filename, and modification date. That larger-file value is a session identifier, not a content evidence hash.
The useful privacy claim is not “nothing can ever leave.” It is that Kestrel does not send your capture to a Tracivex analysis service.
Kestrel is most useful when the capture is already in your hands and the laptop is not.
Open a capture on-site, identify talkers, protocols, DNS activity, and suspicious conversations before you return to a full workstation.
Keep a lightweight analysis surface on the device you already carry while maintaining an explicit boundary around local evidence handling.
Inspect protocol behavior, connectivity problems, and packet structure without needing a desktop analyzer for every question.
Kestrel analyzes pre-captured PCAP and PCAPNG files on iOS and iPadOS; live capture is not part of the shipping mobile application. Kestrel creates a protected sandbox working copy for analysis, so available storage should be roughly at least the capture size plus normal system headroom. Large captures may take substantially longer depending on packet density.
Pro detection features are heuristic and may produce false positives or miss findings. Verify important results independently. Kestrel is not a substitute for a qualified analyst or a dedicated forensic workstation, and should not be used alone where evidentiary admissibility matters.
No software can guarantee absolute security. Users handling sensitive captures should follow their organization’s evidence-handling procedures.