Skip to content

Is It Safe to Upload a PCAP Online? Analyze It Locally

Why packet captures are sensitive under GDPR and client contracts, how in-browser WebAssembly analysis avoids uploads, and how to verify nothing leaves.

Published on 7 min read

TL;DR. A packet capture is a copy of everything that crossed a wire: addresses, hostnames, DNS queries, URLs, file contents and any unencrypted messages. Under the GDPR much of that is personal data, and under a client contract all of it is usually confidential. Uploading a capture to an online analyzer hands a full copy to a third party. Parsing it locally in the browser, with WebAssembly, gives you the convenience of a web tool without that transfer. Do not take anyone's word for it: check the network panel while the file is analysed. PCAP Parser is built so that this check shows no upload.

What a capture really contains

People tend to think of a pcap as "network metadata". It is more than that. Depending on the snaplen and the protocols involved, a single file can hold:

  • internal IP addresses, MAC addresses and hostnames that map your network;
  • DNS queries that reveal which sites and services each person used, and when;
  • full URLs, user agents, and the bodies of unencrypted HTTP requests and responses;
  • documents, images and archives transferred in the clear;
  • the destinations of encrypted sessions, visible through the SNI in the TLS ClientHello;
  • in pcapng, interface names, the capturing machine's OS and, sometimes, embedded TLS session secrets.

TLS hides content, not the fact that a connection happened or where it went. Even a capture that is "all HTTPS" is a detailed log of behaviour.

Why this matters: GDPR and client obligations

Personal data under the GDPR

The GDPR defines personal data (Article 4) as any information relating to an identified or identifiable person, directly or indirectly. In the Breyer case (C-582/14), the Court of Justice of the EU held that a dynamic IP address can be personal data for a website operator that has legal means to identify the person behind it. A capture of employee or customer traffic will usually contain personal data.

Sending that capture to a web service is a disclosure to another party. The service becomes at least a processor, which normally requires a contract under Article 28, and if it is hosted outside the EU, the transfer rules apply as well. Article 32 requires security appropriate to the risk. None of this forbids analysis; it means the upload is a decision to document, not a convenience to take for granted.

Client data and incident response

For consultants and incident responders, captures usually come from a client's network under a contract or an NDA. Many engagements forbid sharing client data with unapproved third parties. An upload-based analyzer, however convenient, is exactly that. The same applies to captures collected under legal hold or for law enforcement, where chain of custody matters.

This is not legal advice. Check your own contracts and your data protection officer's position. The technical point is simple: if the file never leaves your machine, there is no third-party disclosure to justify.

How in-browser analysis works

A web page can read a file you select through the browser's File API without uploading it. What changed in recent years is performance: with WebAssembly, a parser written in a systems language runs in the page at speeds close to native code.

PCAP Parser is built on that model:

  1. The page loads once, including a Rust parser compiled to WebAssembly.
  2. When you drop a capture, a Web Worker reads it in 8 MB slices with File.slice().
  3. Each slice is fed to the parser in the worker; the file is never sent over the network.
  4. Results (conversations, DNS, HTTP, TLS metadata, extracted files, the IOC list) stay in the tab's memory until you close it or click Clear.

The site's Content Security Policy only allows network connections to its own origin and a few analytics endpoints, and the parser has no upload endpoint to call.

How to verify that nothing is uploaded

Claims are cheap. These checks take two minutes and work for any in-browser tool.

Method 1: watch the network panel

  1. Open the tool, then open developer tools (F12, or Cmd+Option+I on macOS) and go to the Network panel. The Chrome DevTools network reference explains the panel.
  2. Tick Preserve log and clear the list.
  3. Drop the capture and wait for the analysis to finish.
  4. Sort by size and look at every request made after the drop. Nothing should come close to the size of your file, and no request body should contain capture data.

On PCAP Parser you will see the parser itself (a .wasm file and a worker script) downloaded from the site the first time you analyse a file, and page-view and performance beacons from the site's analytics, which carry page information, not your file. Those are downloads and small beacons; your capture is not in any of them.

Method 2: go offline

  1. Load the tool page and analyse a small or sample file once, so that any parser code the page loads on demand is already downloaded.
  2. In the Network panel, set throttling to Offline, or disconnect the machine from the network.
  3. Drop the capture.

If the analysis completes, it ran locally. An upload-based service cannot pass this test. If the page fails because the browser will not serve its own code from cache while offline, the test is inconclusive rather than failed: fall back to method 1.

Method 3: read the policy and the code

Check the page's Content-Security-Policy header (in the Network panel, on the document request) to see which hosts it may connect to. When the tool's code is available, look for where the file object goes: to a worker and a parser, or into a fetch or form upload.

Local analysis does not end your responsibilities

Keeping the file on your machine removes one risk, not all of them:

  • Exports are data too. CSV and JSON exports of DNS or HTTP views contain the same personal data. Store them with the case.
  • Extracted files may be malicious. A file recovered from HTTP can be malware. Open it only in a sandbox.
  • Minimise before sharing. If you must share a capture, cut it to the relevant time window and hosts first, for example with Wireshark's editcap or a tshark display filter, and consider anonymisation tools where the use case allows.
  • Retention. Delete working copies when the case closes, according to your policy.

Choosing a tool with privacy in mind

A local parser suits sensitive triage. When you need deeper dissection, Wireshark and tshark also run locally, as do NetworkMiner, Zeek and Zui; the trade-off is installation and, for Zui, a rule-set update that goes online at launch. The tools comparison sets out the options, and how to open a pcap file online covers the practical side of opening a file with no install.

FAQ

Is a packet capture personal data under GDPR?

Very often, yes. IP addresses, hostnames, DNS queries, URLs and message contents can identify people directly or indirectly, and the Court of Justice of the EU has held that even dynamic IP addresses can be personal data. Treat a capture as personal data unless you know it is not.

How can I check that an online pcap viewer does not upload my file?

Open the browser's developer tools, go to the Network panel, clear it, then load the capture. Look for any request whose size is close to the file size or whose body contains capture data. You can also analyse a sample once, switch the tab to offline, and confirm the analysis of your file still works.

Does local analysis remove the need to protect the capture?

No. It removes one copy, the one a web service would receive. The capture on your disk, the exports you create and the files you extract still need the same access control, encryption and retention rules as the rest of the case.

Related articles

A fair comparison of Wireshark, tshark, NetworkMiner, Zeek, Zui and PCAP Parser for pcap analysis: strengths, limits, and which tool fits which job.
Step-by-step guide to PCAP Parser: load a capture, then read conversations, protocol hierarchy, DNS, HTTP, TLS, extracted files and IOCs, and export results.
How to open a pcap or pcapng file online without installing anything: upload vs in-browser viewers, formats that fail, and what a browser tool can't do.