Easy packet capture
Simple, but powerful. Choose an interface, start recording, and keep packet capture calm even when the network is busy.
TCP Viewer vs Wireshark
TCP Viewer is a focused, Mac-native alternative for everyday capture. Wireshark remains the stronger choice for deep, cross-platform analysis.
Download TCP Viewer for MacOnly Apple Silicon - macOS 15+
Side-by-side
Both inspect packets. The main difference is how much analysis depth and setup you want in your daily Mac workflow.
Area
TCP Viewer
Wireshark
Native macOS
TCP Viewer
Designed and built for macOS 26, with a Mac-first look and feel that is easy to use every day.
Wireshark
A powerful cross-platform desktop app with a dense interface designed for advanced network analysis.
Capture all interfaces
TCP Viewer
Capture activity across all available network interfaces in one place, so important traffic is less likely to be missed.
Wireshark
Can capture from many interfaces, with an advanced setup for broad network investigation.
Detailed packets
TCP Viewer
Built on top of Wireshark, so you get familiar, Wireshark-grade packet details in a native Mac app.
Wireshark
Provides its full packet analysis workspace with extensive detail for specialist work.
Display by apps / domains
TCP Viewer
Groups traffic by app and domain, turning a busy capture into clearer conversations to scan.
Wireshark
Shows packet rows and lets you use filters to find the addresses and protocols you need.
Advanced filters
TCP Viewer
Build focused multi-rule filters in a clear form, so everyday checks do not require complex filter syntax.
Wireshark
Offers a powerful filter language for precise, detailed analysis.
TCP Viewer MCP
TCP Viewer
Connect Codex or another MCP client to check capture status, explore interfaces, and find packets with a plain-language request. Available with TCP Viewer PRO.
Wireshark
Does not include a built-in MCP connection.
Choose by workflow
Choose based on the work you do most often. Neither tool needs to replace the other.
Use TCP Viewer for a quick Mac capture, then export the relevant packets to Wireshark when the investigation needs deeper protocol analysis or team collaboration.
Simple, but powerful. Choose an interface, start recording, and keep packet capture calm even when the network is busy.
Powered by Wireshark
TCP Viewer is built on Wireshark's packet analysis engine. Explore decoded protocols, field values, and raw bytes in a native Mac interface.
TCP Viewer is distributed under GPL v2 or later, in line with Wireshark's license. See the open-source acknowledgements.
TCP Viewer MCP
Connect TCP Viewer to Codex or another MCP client. Check capture status, explore interfaces, and find the packets that matter with a plain-language prompt.
Available with TCP Viewer PRO.

Saved captures
Bring an existing capture into TCP Viewer and preview the packets right away, with no fresh recording session required.
Drag in a trace
Drop PCAP or PCAPNG files straight onto TCP Viewer.
Preview immediately
Open the packet list and decoded detail view without a live capture.
Keep the workflow native
Review saved evidence in the same Mac-first packet interface.
Drop capture.pcapng to preview
Follow TCP Stream
Get the familiar Wireshark Follow TCP workflow in a focused, Mac-native window—reassembled, direction-aware, and easy to trace back to the source packets.
Whatever you capture, TCP Viewer keeps the important traffic readable. Filter noise, open decoded fields, and save evidence for the next debug session.
Grouped traffic
Collapse busy captures into readable conversations by domain or client, then jump straight to the traffic that matters.
Protocol filters
Tap protocol chips to focus the packet list without rebuilding a complex filter every time the capture changes.
Export captures
Package the exact packets you need into standard capture files for Wireshark, teammates, or the next debug session.
Export selected packets
Capture range
File format
Filename
filtered-capture.pcapng
Packet detail
Open decoded fields, protocol trees, byte ranges, and field values with Wireshark-grade depth in a focused Mac interface.
Open source
Read the source, build the app yourself, or contribute on GitHub. TCP Viewer uses the GPL v2 or later license.