Network capture
Start a capture
Section titled “Start a capture”Enable NAT for the VM, start it, and start Network capture. You can also start a capture from the Network panel. Stop the capture to finish it.
Each start creates a separate pcap in the boot recording. Capture runs outside the guest, and starting or stopping it does not require restarting the VM. Disconnected networking does not provide this NAT capture path.
Inspect packets
Section titled “Inspect packets”Select a live or saved capture from the panel’s history. The packet list shows protocols and endpoints with category colors. Depending on the packet, summaries can include DNS names, TCP flags, HTTP request lines and TLS server names.
Select a packet to inspect its captured bytes. Encrypted traffic remains encrypted; packet summaries do not decrypt application payloads.
Filter the list
Section titled “Filter the list”Click an address, port or protocol, or use the counted dropdowns. The text filter accepts examples such as:
| Filter | Selects |
|---|---|
| port 443 | Either endpoint using port 443 |
| ip 10.0.2.15 | Either endpoint with that address |
| proto DNS | Packets labelled DNS |
| example.com | Matching text in packet columns |
Clear the filter to restore the full list.
Open another packet tool
Section titled “Open another packet tool”Open in Wireshark opens the selected capture when Wireshark is installed on the host. Wireshark is optional and separate from Antinomie’s runtime requirements.
Packet captures count against the boot recording quota. A running network capture stops when that quota is full. See recordings and history for retention.