Description
Stop uploading sensitive network captures to online analyzers. pcapLume is a premium, native macOS forensic suite designed for security analysts, network engineers, and incident responders who require absolute privacy and lightning-fast local diagnostics. Designed on a secure, zero-telemetry architecture, pcapLume lets you ingest, dissect, and audit packet captures offline, keeping your proprietary data safe in a local sandbox. IMPORTANT: Core features—including offline packet forensic reassembly, OUI hardware fingerprinting, and YARA payload scanning—require an active Premium Annual Subscription or a one-time Genesis Partner Lifetime License. You can download the app and explore sample packet captures for free, but importing custom PCAP files and running forensic engines requires an In-App Purchase. KEY FORENSIC PILLARS: 1. AUTOMATED FILE CARVING & INTEGRITY PROFILES Recover executables (EXE), HTML, ZIPs, JPEGs, and PDFs dynamically from unencrypted TCP/HTTP flows. pcapLume automatically generates MD5, SHA-1, and SHA-256 integrity checksums for all extracted assets, maintaining strict evidentiary provenance for your chain of custody. 2. LAYER-2 HARDWARE VENDOR & IOT FINGERPRINTING Identify unknown nodes instantly. Map MAC addresses to physical device manufacturers using local, offline OUI prefix tables. Cross-reference endpoints against academic telemetry catalogs to profile connected smart devices, local routers, and suspicious network hardware. 3. BEHAVIORAL TIMING ANOMALY ENGINE Expose stealthy Command & Control (C2) channels. The engine runs timing calculations to flag robotic periodic beaconing (coefficient variance under 5% across 15+ consecutive packets) and calculates Shannon entropy over payload bytes to detect encrypted exfiltration tunnels. 4. AOT YARA PAYLOAD SCANNER Scan payload streams Ahead-of-Time (AOT) for threat patterns. Identify shellcode NOP sleds, obfuscated scripts, credentials, and reverse shell strings without executing code or sending data off-device. 5. RESPONSIVE ASYNCHRONOUS EXPORTS Generate multi-page PDF threat dossiers and Incident Response checklists asynchronously. The non-blocking rendering engine keeps the native AppKit UI fluid and responsive even during large report generation, completely avoiding system freezes. 6. DYNAMIC APPEARANCE MODES Switch seamlessly across Native, System, Light, and Dark modes. All glassmorphic dashboards, interactive protocol filter bar charts, and list views adapt dynamically to your macOS environment. ABSOLUTE PRIVACY GATES: Toggle "Absolute Zero Telemetry" to structurally lock down all external networking. When disabled, you can seamlessly enrich public IPs using live OSINT APIs (Shodan and Censys), sync threat feeds with AlienVault OTX, and query file signatures via MalwareBazaar. When enabled, pcapLume defaults entirely to pre-seeded local databases.
Information
- Seller
- ProfWorkBench, LLC
- Category
- Developer Tools
- Version
- 1.0
- Requires
- iOS 14.0+
- Size
- 4.7 MB
- Age Rating
- 4+