0x01 · KESTREL SECURITY STACK · 2 SHIPPING / 2 IN DEVELOPMENT

Packet capture analysis
for iPhone and iPad.

The Kestrel Security Stack is one analysis engine spanning iOS and iPadOS — and soon, macOS. Lite and Sight ship on iPhone and iPad today. Pro is in active development, and Talon brings the same engine to the Mac — also in development. Processed on device. No accounts, no cloud uploads, no analytics, no third-party dependencies.

PLATFORMS
iOS 18 · iPadOS 18 · macOS (Talon, in development)
EDITIONS
Lite & Sight (shipping) · Pro & Talon (building)
FORMATS
PCAP · PCAPNG
NETWORK
None outbound
PRIVACY
Entirely on device
────── THE STACK ──────
00000100 · EDITIONS

One engine. Multiple editions.

On iOS and iPadOS, Kestrel is a progression of three editions — free field triage, professional analysis with bookmarks and raw search, and detailed reports with audit log. Lite and Sight are shipping today; Pro is in active development. On macOS, Talon adds live capture from any interface.

I. ● LITE

Kestrel Lite

Free · Up to 50,000 packets · Always free

Packet capture analysis for iPhone and iPad, capped at the first 50,000 packets per file. Dashboard, packets, flows, hosts, DNS, streams, timeline, and audit log with SHA-256 evidence hashing. TCP stream reassembly for files under 1 GB. Ideal for field triage, quick inspections, and learning the app.

Kestrel Lite dashboard
II. ● SIGHT

Kestrel Sight

Unlimited packets · Raw data search · Analyst bookmarks

Everything in Lite, with no 50,000-packet cap. Adds analyst bookmarks (flag any packet, flow, host, DNS query, or stream with a note — included in PDF export), raw data search across arbitrary byte sequences, enhanced IPv6 with canonical RFC 5952 display, and refined PDF reports with paginated bookmarks and properly sized columns. TCP stream reassembly is automatic for captures under 1 GB.

Kestrel Sight dashboard
III. ● PRO · BUILDING

Kestrel Pro

In development · Advanced detection · Audit · Findings Mode

Everything in Sight, with advanced detection and reporting. Sensitive Data Scanner reports credentials and API keys as salted SHA-256 fingerprints — raw values never touch disk. Anomaly detection covers beaconing, DGA domains, exfiltration, NXDOMAIN bursts, port scans, and reconnaissance tooling patterns. File carving extracts JPEG, PNG, GIF, PDF, ZIP, HTML, JavaScript, JSON, and XML with dual SHA-256/MD5 fingerprints. Session events are linked into a cryptographic hash chain following Schneier–Kelsey 1999 — the chain is verifiable from any exported PDF.

Kestrel Pro dashboard
In Development
────── COMPARISON ──────
00000110 · CAPABILITIES

What each edition includes.

The core analysis engine is identical across all three. Each tier adds capabilities on top.

Dashboard & protocols
Lite · Sight · Pro
Packets & filtering
Lite (50,000-packet cap) · Sight · Pro
Flows · hosts · DNS
Lite · Sight · Pro
TCP stream reassembly
Lite & Sight (automatic under 1 GB) · Pro adds disk-backed streaming reassembly for multi-GB captures
Timeline & audit log
Lite · Sight · Pro
Analyst bookmarks
Sight · Pro
Raw data search
Sight · Pro
Enhanced IPv6 (RFC 5952)
Sight · Pro
Refined PDF reports
Sight · Pro
Sensitive data scanner
Pro only
Advanced anomaly detection
Pro only (beaconing, DGA, NXDOMAIN, exfiltration, recon UAs)
File carving & media extraction
Pro only
Cryptographic audit chain
Pro only
Findings Mode (any file size)
Pro only
────── CAPACITY ──────
00000120 · LIMITS

What it handles.

Honest, published limits. What happens at each file size and when features degrade.

00

Up to 1 GB

Full feature set across all three editions. Automatic TCP reassembly, complete analysis, optimized in-memory access.

ModeFull in-memory
ReassemblyAutomatic
01

1 GB to ~3 GB Pro only

Pro uses streaming TCP reassembly that spills large streams to protected disk storage with bounded RAM per segment. On Lite and Sight, TCP reassembly automatically disables above 1 GB to protect device memory — packets, flows, hosts, DNS, and timeline remain fully functional.

ProtectionNSFileProtectionComplete
RAMBounded (Pro)
02

Beyond device memory budget Pro only

Pro’s Findings Mode opens larger captures with explicit user consent. When a file exceeds what the device can safely analyze in memory, you choose how to proceed — Kestrel Pro then analyzes the agreed portion and discloses exactly what was and wasn’t covered in both the audit log and a full-page PDF disclaimer.

Pro onlyHonest coverage disclosure
────── WHO IT'S FOR ──────
00000130 · AUDIENCE

Built for the field.

If your work involves opening PCAPs anywhere other than a secure workstation, Kestrel is built for you.

SOC analysts
Quick triage when you’re away from the workstation
Incident responders
Analysis on the road
Threat hunters
Reviewing suspicious captures in the field
Security consultants
On-site assessments without cloud tool access
Penetration testers
Field reports for client engagements
Network administrators
Troubleshooting connectivity without a laptop
Educators & students
Learning protocol behavior on mobile
────── ON THE MAC ──────
00000140 · MACOS

The Kestrel stack on macOS.

Live capture belongs on a desktop. Kestrel Talon brings the same analysis engines to the Mac, with native packet capture from any interface.

IV.● BUILDING

Kestrel Talon

macOS · In development

Live packet capture on macOS, with the same analysis engines that will power Kestrel on iOS — from protocol parsing through TCP reassembly. Native export to Wireshark-ready PCAPNG. Future integration with Kestrel Link (in development) will let you start a capture on your Mac and view it live on your iPhone.

────── PRIVACY ──────
PRIVACY

100% offline — Every byte processed on-device. No outbound connections. No analytics.

For the full policy, read the privacy policy. For questions, reach out directly.

NOTES

Kestrel analyzes pre-captured PCAP files only — live network capture is not permitted within iOS by the platform itself. Screenshots may combine demo and real data for illustration. Large captures may extend load times. Devices with 6 GB RAM or more are recommended for full-speed multi-gigabyte analysis — Pro’s Findings Mode adapts to the available memory budget and works on smaller devices with a proportionally smaller coverage budget. The demo section uses fabricated sample packets.

Kestrel is designed as an analytical and educational starting point. Detection features — including the Pro sensitive-data scanner and anomaly detection — use heuristic techniques and may produce false positives or miss findings. Always verify results independently before acting on them. Kestrel is not a substitute for a qualified analyst or a dedicated forensic workstation, and should not be used alone where evidentiary admissibility matters.

While Kestrel has been designed with security as a core priority, no software can guarantee absolute security. Users handling sensitive captures should follow their organization’s evidence-handling procedures.