Skip to content

Network capture

Enable NAT for the VM, start it, and start Network capture. You can also start a capture from the Network panel. Stop the capture to finish it.

Each start creates a separate pcap in the boot recording. Capture runs outside the guest, and starting or stopping it does not require restarting the VM. Disconnected networking does not provide this NAT capture path.

Select a live or saved capture from the panel’s history. The packet list shows protocols and endpoints with category colors. Depending on the packet, summaries can include DNS names, TCP flags, HTTP request lines and TLS server names.

Select a packet to inspect its captured bytes. Encrypted traffic remains encrypted; packet summaries do not decrypt application payloads.

Click an address, port or protocol, or use the counted dropdowns. The text filter accepts examples such as:

Filter Selects
port 443 Either endpoint using port 443
ip 10.0.2.15 Either endpoint with that address
proto DNS Packets labelled DNS
example.com Matching text in packet columns

Clear the filter to restore the full list.

Open in Wireshark opens the selected capture when Wireshark is installed on the host. Wireshark is optional and separate from Antinomie’s runtime requirements.

Packet captures count against the boot recording quota. A running network capture stops when that quota is full. See recordings and history for retention.