Packet Analyzer
Paste a raw packet as hexadecimal (spaces and colons are fine) and it is decoded into an expandable protocol tree (Ethernet II, IPv4, and TCP or UDP) with the key header fields. Unencrypted payload bytes can hold credentials in clear, so the analyzer is gated behind a short acknowledgement.
This is generated in browser and is not sent to pah.moi servers.
About this tool4 paragraphs
The decode covers Ethernet II (including its VLAN and QinQ tags), ARP, IPv4, IPv6, ICMP and ICMPv6 by name, TCP, UDP, and a first look at DNS, DHCP and NTP payloads. IPv4 goes down to its options and fragment fields, IPv6 follows the extension-header chain, and TCP shows its options and flags. Wherever a header carries a checksum you get a checksum verdict.
Clicking a field lights the exact bytes it was read from, and clicking a byte names the field that covers it. From the keyboard, Inspect next field steps through the fields one at a time and a spoken status line says which bytes are lit.
A .pcap or .pcapng capture can be opened as well as pasted: both byte orders, microsecond and nanosecond stamps, and a frame picker listing each frame's time, addresses, protocol and length. A structured filter builder turns rows for host, port, protocol, TCP flags and VLAN into a tcpdump BPF expression and a Wireshark display filter at the same time, showing which row produced which clause, so the two syntaxes can be compared rather than memorised.
It reads bytes and stops there. A short or malformed packet gives you the layers that did decode plus a note, and never a crash. Remember that a partial tree describes the bytes you pasted, not necessarily the whole frame on the wire. Payload above those first few application protocols is left as bytes; nothing here decrypts anything, follows a stream across frames, or reassembles a fragment. Everything is parsed in this tab and no capture is uploaded.
packet-cli from the site's source with:
cargo build --release --bin packet-cliSource and licence terms