Compare TCP and UDP Packets with Diff on Mac
Diff shows what changed between two captured packets. Compare decoded protocol fields, or switch to raw bytes when you need an exact binary comparison. It works with packets from live captures and opened capture files.
Choose Left and Right packets, switch between Side By Side and Unified, then compare the captured bytes.
1. The problem
Two packets can look similar in the table but contain different flags, field values, or payload bytes. Moving between inspector rows makes small changes easy to miss. Copying both packets into another tool adds another step.
When checking two TCP connections or UDP flows, choose a representative packet from each. Diff puts their details together and highlights the changes.
2. What is Packet Diff?
Diff opens a separate native Mac window. The packet table at the top holds your Diff pool. The Left and Right checkboxes choose the two packets to compare below it.
Choose what to compare with Diff on:
| Option | What you see |
|---|---|
| Packet Details | Decoded protocol fields as indented text, including nested detail rows. |
| Packet Bytes | Captured frame bytes in two read-only hex and ASCII panes. |
Diff compares two pool items at a time. To read a complete TCP conversation or UDP exchange, use Follow TCP and UDP streams.
3. Benefits
- ✅ Spot changes in addresses, ports, flags, lengths, and decoded field values.
- ✅ Compare a packet from a working flow with one from a failing flow.
- ✅ Read packet details Side By Side or as a Unified inline diff.
- ✅ Find exact byte changes with hex offsets and an ASCII preview.
- ✅ Switch Left and Right sources without leaving the Diff window.
- ✅ Keep packet snapshots available after closing the source capture.
4. How to compare two packets
- Start a live packet capture or open a capture file.
- Select two packet rows. Hold Command to select separate rows.
- Right-click the selection and choose Diff, or press Command-Y.
- TCP Viewer adds the packets to the Diff pool. In an empty pool, the first packet becomes Left and the second becomes Right.
- Leave Diff on set to Packet Details to compare decoded fields.
- Choose Side By Side for two text panes, or Unified for one inline view.
To compare packets from different captures, add one packet from the first capture, then add a packet from the second. Use packet filters to find the TCP connection or UDP flow you need before adding its packet.
You can also open the window from Diff → Open Diff View… with Option-Command-Y. Use Diff → Add selected items to Diff Pool… to add the current selection.
5. Choose another comparison
Use the Left and Right checkboxes in the pool to change either source. Each side holds one packet. Adding more packets keeps the current comparison selected, so you can choose the next pair when ready.
- Select a pool row and press Command-[ to assign it to Left.
- Press Command-] to assign it to Right.
- Use the row's context menu for Left Side or Right Side.
- Press Delete to remove selected pool items.
Pool entries retain packet snapshots for the current app session. Closing a source capture or reopening the Diff window keeps those entries available.
6. Compare binary bytes
Choose Diff on → Packet Bytes. TCP Viewer shows the captured frame bytes in two hex and ASCII panes and highlights differing ranges.
- Use Next or F7 to jump to the next difference.
- Use Previous or Shift-F7 to return to the previous difference.
- Press Command-F to search for a hex byte sequence.
Packet Bytes uses two panes. Unified is available for Packet Details. Binary comparison includes the complete captured frame, including headers. A truncated packet contains only the bytes that were captured. Encrypted payloads remain encrypted.
7. Free and PRO
| Version | Diff pool |
|---|---|
| Free | Up to 2 items. Compare their packet details or bytes. |
| PRO and Team | Unlimited items. Switch between any two packets in the pool. |
Both versions compare two items at a time. PRO lets you keep more candidates in the pool while investigating several flows.
See TCP Viewer pricing for the full feature comparison.