iOS and iPadOS security Tools

Professional Network Analysis,
Right From Your Pocket

Tracivex builds security tools that work where you do. Our flagship app Kestrel brings full PCAP analysis to iPhone and iPad — offline, on-device, no account required.

100% on-device. No data collected. No advertising.
KestrelSIGHT
DashboardPacketsFlowsHosts
181
Total Packets
15.6 KB
Total Data
29.6s
Duration
8
Unique Hosts
8
Flows
0
DNS
8
Hosts
Protocol Distribution
TCP
158
(87.29%)
ICMP
20
(11.05%)
Other
3
(1.66%)
Flow Analysis
8 Conversations
● TCP, ICMP, ARP
TCP Streams
3 Reassembled
● 158 TCP packets

Mobile-first network forensics.

Open captures from email, AirDrop, or Files and start inspecting packets immediately — no laptop, no setup, no account.

Security ProfessionalsNetwork AdminsIncident RespondersPen Testers

Meet Kestrel.

Professional PCAP analysis for iPhone, iPad, and iPadOS — in two editions built for different workflows.

Kestrel Sight

Kestrel Sight

Full Analysis Suite

No software-imposed packet limit*, raw data search, and large file support. Everything in Lite plus the tools for deep analysis.

  • No software packet limit*
  • Raw data search across entire captures
  • Auto TCP reassembly for files under 1 GB
  • Support for files over 1 GB
Get Kestrel Sight →
Kestrel Lite

Kestrel Lite

Essential Packet Inspector

Full-featured PCAP analysis with the first 50,000 packets. Dashboard, flows, hosts, DNS, streams, and timeline — always free.

  • Up to 50,000 packets per capture
  • Dashboard, flow analysis, and host profiling
  • TCP stream reassembly for files under 1 GB
  • Always free — no trial, no expiration
Get Kestrel Lite →

Kestrel Talon

macOS · In Development

Full-depth PCAP analysis built natively for Mac. The same Kestrel engine with a desktop-class interface — sidebar navigation, expanded dashboard, top sources and destinations, encryption summary, and room for even larger captures.

  • Native macOS application
  • Desktop-class dashboard with sidebar navigation
  • Currently in active development
Learn More →

Kestrel Cipher

macOS · In Development

11 professional security tools in one native macOS app. Hashing, encoding, JWT decoding, certificate inspection, password analysis, regex testing, IP/subnet calculation, and more — all 100% offline.

  • 11 cryptography and security tools
  • CryptoKit and CommonCrypto powered
  • App Sandbox enabled, zero network connections
Learn More →

Built for the field.

Every panel engineered to give you real answers from raw packets — entirely on your device.

Both Editions

Eight analysis panels from a single capture file.

Load a PCAP or PCAPNG and Kestrel automatically parses packets, reconstructs flows, profiles hosts, extracts DNS queries, and builds a visual timeline.

Dashboard

Protocol distribution, encryption statistics, top talkers, and session summary.

Packet Inspection

Browse and filter packets with headers, flags, and hex/ASCII payload view.

Flows, Hosts, and DNS

Bidirectional flow reconstruction, IP profiling, and DNS query extraction.
KestrelSIGHT
DashboardPacketsFlowsHosts
8 flows
TCP
192.168.8.2 ⇄ 4.236.82.215
40 pkts7.9 KB28.5s
TCP
192.168.8.3 ⇄ 4.236.82.215
42 pkts8.7 KB27.0s
ICMP
192.168.8.3 ⇄ 192.168.8.1
10 pkts0.7 KB<1s
Both Editions

TCP stream reassembly and timeline view.

Reconstruct full TCP conversations from segmented packets. View every event on a filterable visual timeline.

Stream Reassembly

Reassemble TCP streams for captures under 1 GB.

Event Timeline

Visual timeline with filtering and detailed event information.

Chain of Custody

Forensic session tracking for an auditable analysis record.
KestrelSIGHT
DNSStreamsCustodyTimeline
3 TCP streams
#0View Packets76 pkts
4.236.82.215:8883 ⇄ 192.168.8.10:61171
↑ 2.3 KB↓ 4.0 KB
#1View Packets40 pkts
192.168.8.2:56301 ⇄ 4.236.82.215:8883
↑ 5.4 KB↓ 31 B
#2View Packets42 pkts
192.168.8.3:59225 ⇄ 4.236.82.215:8883
↑ 6.2 KB↓ 0 B
Sight Exclusive

Unlimited packet loading* and raw data search.

Kestrel Sight removes the 50,000-packet cap and adds raw data search across the entire capture.

Raw Data Search

Search for any string or pattern across all packets.

Large File Support

Files up to 1 GB with full features. Files over 1 GB still loadable.

No Packet Limit*

Load every packet in the capture. Performance depends on device memory and file size.
KestrelSIGHT
DashboardPacketsFlowsHosts
181 of 181
#000:19:58.604TCP4.236.8... → 192.168...193
#100:19:58.684TCP192.168... → 4.236.8...56
#200:19:58.753TCP192.168... → 4.236.8...437
#300:19:58.846TCP4.236.8... → 192.168...54
#400:19:59.667TCP192.168... → 4.236.8...437
#500:19:59.808TCP4.236.8... → 192.168...54
#600:20:00.077TCP192.168... → 4.236.8...435
#700:20:00.170TCP4.236.8... → 192.168...54
#800:20:00.487TCP192.168... → 4.236.8...192
#900:20:00.579TCP4.236.8... → 192.168...54

Sight vs. Lite at a glance.

Both editions share the same parsing engine. Sight removes limits for deeper analysis.

CapabilityKestrel SightKestrel Lite
Packet LoadingUnlimited*50,000 packets
Dashboard & Statistics
Packet Inspection (headers, flags, hex/ASCII)
Flow Analysis
Host Profiling
DNS Query Extraction
TCP Stream Reassembly (under 1 GB)
Chain of Custody
Timeline View
Raw Data Search
Files Over 1 GB
PricePaidFree

* No software-imposed packet limit. Kestrel Sight will attempt to load all packets in a capture file regardless of count. Very large files may affect performance or stability depending on available device memory and file size. For best results with large captures, ensure sufficient free memory on your device.

IN DEVELOPMENT

Kestrel Pro is on the way.

Advanced analysis features are actively being built for Kestrel Sight.

Sensitive Data Scanner

Credential and secret detection across unencrypted traffic.

File Carving

Extract files from unencrypted network traffic.

Media Extraction

View and export images found in traffic.

Anomaly Detection

Automated detection of possible security issues.

Pro features are in development. Performance may vary and features may be subject to change.

Ready to open your first capture?

Download free. No account required. No data collected.

Available for iPhone, iPad, and iPadOS. Processes pre-captured PCAP files only — no live network sniffing within iOS.