Launch list open Native macOS packet capture

See every packet. Understand the session.

Tracexy is a native macOS packet capture and network session analyzer. Capture Wi-Fi, Ethernet, VPN, and loopback traffic; trace it back to an app, domain, or IP; then inspect protocol layers, timing, and raw bytes in one workspace.

macOS 13+ · local-first capture · no account required · no checkout today

TRACEXY AT A GLANCE

Packet evidence with Mac-native context

Product type
Packet capture and network session analyzer
Capture sources
Wi-Fi, Ethernet, Thunderbolt, VPN, and loopback
Source context
Applications, domains, and IP addresses
Inspection
Decoded fields, timing, and raw hex bytes
Availability
Launch list open; checkout not available

THE CAPTURE WORKSPACE

Move from a traffic spike to the packet that caused it

A live throughput graph, session table, source tree, protocol filters, and packet inspector stay visible together. Start broad, narrow the evidence, then read the selected frame without changing tools.

Tracexy light interface showing live sessions grouped by application with a packet inspector
Tracexy dark interface showing live sessions grouped by application with a packet inspector

Browse

Scan the whole capture

Review live sessions and filter by DNS, TCP, UDP, TLS, HTTP, HTTP/2, QUIC, WebSocket, or errors.

Focus

Follow the source that matters

Narrow traffic to an application, domain, or IP address and keep its related sessions together.

Inspect

Read fields and bytes side by side

Expand Ethernet, IP, TCP or UDP fields, check timing where available, and verify the underlying packet bytes.

CAPTURE CONTROL

Choose the interface, filter, and buffer before the noise arrives

Select the network path you need, or let Tracexy choose automatically. Capture settings expose BPF expressions, snap length, promiscuous mode, launch behavior, and a bounded packet-retention limit.

INTERFACE PICKER

Capture the Mac path that carries the problem

Choose Wi-Fi, Ethernet adapters, Thunderbolt, VPN and generic tunnels, or loopback from the capture toolbar.

Tracexy interface picker listing Wi-Fi, Ethernet, Thunderbolt, tunnel, VPN, and loopback capture sources
Tracexy capture settings with BPF filter, snap length, promiscuous mode, and packet retention controls

CAPTURE SETTINGS

Keep collection explicit and bounded

Set a BPF expression, full-packet or shorter snap length, promiscuous mode, and the number of packets retained in the workspace.

PACKET INSPECTION

Decoded structure when you need meaning. Raw bytes when you need proof.

The inspector expands link, network, and transport layers into named fields while preserving the hexadecimal payload. Switch between horizontal and vertical layouts to fit the investigation.

Tracexy horizontal packet inspector with decoded Ethernet, IPv4, UDP fields and hexadecimal bytes
Tracexy source tree grouping captured sessions by application, domain, and IP address

SOURCE ATTRIBUTION

Trace an address back to the application that opened it

Packets become easier to explain when the source tree keeps applications, domains, and IP addresses next to their session counts. Follow traffic from Chrome, Firefox, a CLI process, an editor, or a background helper without starting from an anonymous endpoint.

THREE INSPECTOR VIEWS

Fields, timing, and packet layers stay one click apart

Use the document view for decoded values, the timing view for duration and available handshake or TTFB measurements, and the layer view to follow the protocol stack. Search a key or value inside the selected packet.

Ethernet II IPv4 TCP / UDP Hex + ASCII
Tracexy vertical timing inspector showing total session duration

WHEN TRACEXY EARNS ITS PLACE

Packet-level questions a proxy cannot answer alone

DNS and routing

Find what resolved, which interface carried it, and where the packet went

Capture the active Wi-Fi, Ethernet, or tunnel interface and correlate address-level traffic with the originating application.

QUIC, TLS, and transport

Inspect traffic below the request-and-response layer

Filter the capture by transport or encrypted-session protocol, then inspect addresses, ports, lengths, timing, and raw frames.

App and helper behavior

Separate browser, editor, CLI, agent, and background-process traffic

Use the source tree before opening the packet inspector so endpoint evidence keeps its application context.

Intermittent performance

Keep the live rate, session duration, and packet evidence together

Review the throughput graph, isolate the affected source or protocol, and inspect timing measurements available for the selected session.

TRACEXY OR ROCKXY?

Start at the layer where the failure lives

The two native Mac tools cover different debugging jobs. Use Tracexy for interface and packet evidence. Use Rockxy for HTTP and API workflows.

Question
Tracexy
Rockxy
Capture point
Selected Mac network interface
Configured HTTP(S) proxy
Best evidence
Packets, protocol layers, addresses, ports, timing, raw bytes
HTTP requests and responses, replay, diff, rewrite, redaction
Typical use
DNS, TCP, UDP, TLS, QUIC, WebSocket, routing, app attribution
API debugging, interception, mocks, comparison, shareable HTTP evidence
Availability
Launch list

Looking for a native Wireshark alternative on macOS? Tracexy is designed around Mac interface capture, app-aware session grouping, and a simpler investigation path. Wireshark remains a broader cross-platform protocol analyzer.

LOCAL-FIRST BOUNDARY

Captured traffic stays with the Mac producing it

Capture is explicit, storage is local, and Tracexy does not require a cloud account for packet analysis. Save evidence as local capture files when you need to keep or move it.

CAPTURE RESPONSIBLY

Network traces can contain credentials and private payloads

Choose the narrowest interface and BPF filter that answer the question. Review capture files before sharing them and follow the rules for networks and devices you do not own.

PRICING PREVIEW

Founding-price targets, not an open checkout

Tracexy is planned as a one-time purchase. These targets may change before launch; joining the list records interest only.

Founding Personal

1 Mac

$29 one-time target

One macOS activation with 12 months of updates and support.

Join launch list

Founding Multi-Mac

2 Macs

$39 one-time target

Two macOS activations with 12 months of updates and support.

Join launch list

Founding Lifetime

2 Macs

$79 one-time target

Two macOS activations with lifetime app updates.

Join launch list

No payment today. A launch-list registration does not reserve a license or guarantee final pricing.

FAQ

Tracexy questions, answered directly

What is Tracexy?

Tracexy is a native macOS packet capture and network session analyzer. It captures traffic from a selected Mac interface, groups it by application, domain, and IP address, and exposes protocol, timing, decoded field, and raw byte views.

Which network interfaces can Tracexy capture?

The current preview can select Wi-Fi, Ethernet, Thunderbolt, VPN and other tunnel interfaces, and loopback. Capture settings also expose BPF expressions, snap length, promiscuous mode, and a packet retention limit.

Which protocols does Tracexy organize?

The current interface provides dedicated views for DNS, TCP, UDP, TLS, HTTP, HTTP/2, QUIC, WebSocket, and errors, alongside an all-traffic view.

How is Tracexy different from Rockxy?

Tracexy starts at the network interface and is intended for packet and session analysis across multiple protocols. Rockxy is the HTTP debugging proxy for intercepting, inspecting, replaying, modifying, and comparing API traffic.

Is Tracexy available to buy now?

No. Tracexy is collecting launch-list registrations. Joining records interest only and does not charge a card, reserve a license, or guarantee final pricing.

Make packet evidence readable on macOS.

Join the Tracexy launch list for availability updates. No checkout, payment, or product account is created today.

Join Tracexy launch list