Skip to main content

TCP Viewer Features

TCP Viewer brings the most common packet-analysis tasks into a focused native Mac app. Choose a workflow below.

Capture, filter, and inspect packets in the native Mac workspace.

1. Choose a TCP Viewer workflow

FeatureUse it when you need to…
Live packet captureWatch new TCP and UDP traffic from a Mac network interface.
Open capture filesInspect PCAP, PCAPNG, or TCP Viewer session files.
Capture overviewCheck traffic totals, protocols, top apps, domains, and IP addresses.
EndpointsCompare packet and byte totals by app, domain, address, or port.
Group trafficFind packets from one app, domain, IP address, or imported file.
Filter packetsNarrow a large packet list by protocol or exact field rules.
Wireshark display filtersUse Wireshark syntax to search protocol fields, addresses, ports, and packet content.
Follow TCP and UDP streamsReassemble a TCP conversation or inspect a UDP flow, separate its directions, and return to source packets.
Packet inspectionRead decoded protocols, field values, and raw bytes.
Organize and customizePin sources, save packets, add comments or colors, and change columns.
Save, copy, and exportShare selected packets, a full capture, or readable table data.
TCP Viewer MCPLet Codex, Claude Code, or another MCP client inspect and control TCP Viewer.
Command lineControl TCP Viewer from Terminal, scripts, and other apps with tcpviewer-cli.

If this is your first time using the app, start with the Overview and Live packet capture.