Easy packet capture
Simple, but powerful. Choose an interface, start recording, and keep packet capture calm even when the network is busy.
TCP Viewer vs Wireshark
A native macOS alternative to Wireshark - easy to use, with Wireshark-grade packet details.
Download TCP Viewer for MacOnly Apple Silicon - macOS 15+
Side-by-side
Wireshark is excellent for deep, detailed work. TCP Viewer keeps the common Mac jobs clear and quick.
Area
TCP Viewer
Wireshark
Native macOS
TCP Viewer
Designed and built for macOS 26, with a Mac-first look and feel that is easy to use every day.
Wireshark
A cross-platform app with an outdated interface and a steep learning curve.
Capture all interfaces
TCP Viewer
Capture activity across all available network interfaces in one place, so important traffic is less likely to be missed.
Wireshark
Can capture from many interfaces, with an advanced setup for broad network investigation.
Detailed packets
TCP Viewer
Built on top of Wireshark, so you get familiar, Wireshark-grade packet details in a native Mac app.
Wireshark
Provides its full packet analysis workspace with extensive detail for specialist work.
Display by apps / domains
TCP Viewer
Groups traffic by app and domain, turning a busy capture into clearer conversations to scan.
Wireshark
Shows packet rows and lets you use filters to find the addresses and protocols you need.
Advanced filters
TCP Viewer
Build focused multi-rule filters in a clear form, so everyday checks do not require complex filter syntax.
Wireshark
Offers a powerful filter language for precise, detailed analysis.
TCP Viewer MCP
TCP Viewer
Connect Codex or another MCP client to check capture status, explore interfaces, and find packets with a plain-language request. Available with TCP Viewer PRO.
Wireshark
Does not include a built-in MCP connection.
Simple, but powerful. Choose an interface, start recording, and keep packet capture calm even when the network is busy.
TCP Viewer MCP
Connect TCP Viewer to Codex or another MCP client. Check capture status, explore interfaces, and find the packets that matter with a plain-language prompt.
Available with TCP Viewer PRO.

Saved captures
Bring an existing capture into TCP Viewer and preview the packets right away, with no fresh recording session required.
Drag in a trace
Drop PCAP or PCAPNG files straight onto TCP Viewer.
Preview immediately
Open the packet list and decoded detail view without a live capture.
Keep the workflow native
Review saved evidence in the same Mac-first packet interface.
Drop capture.pcapng to preview
Whatever you capture, TCP Viewer keeps the important traffic readable. Filter noise, open decoded fields, and save evidence for the next debug session.
Grouped traffic
Collapse busy captures into readable conversations by domain or client, then jump straight to the traffic that matters.
Protocol filters
Tap protocol chips to focus the packet list without rebuilding a complex filter every time the capture changes.
Export captures
Package the exact packets you need into standard capture files for Wireshark, teammates, or the next debug session.
Export selected packets
Capture range
File format
Filename
filtered-capture.pcapng
Packet detail
Open decoded fields, protocol trees, byte ranges, and field values with Wireshark-grade depth in a focused Mac interface.
GPL open source
TCP Viewer is open source under the GPL license, so developers and security-sensitive teams can review how capture, decoding, and packet handling work.
ProxymanApp/TCPViewer
license: GPL v2
source: github.com/ProxymanApp/TCPViewer
review: capture pipeline, decoders, packet UI
Built in the open for people who want their network tools to be understandable.
Audit the code, follow releases, or contribute directly from GitHub.
From the makers of Proxyman and Tiny Shield. TCP Viewer carries the same Mac-first care into packet capture, filtering, and inspection.