← Docs

CLI Reference

pcapai · 21 command groups, 151 verbs

Generated from the shipped binaries — not written by hand.

pcapai convert

Convert PCAP/PCAPNG files to PCAPAI format

pcapai convert-batch

Convert MANY PCAP/PCAPNG files to PCAPAI, several at a time

pcapai dissect

Dissect PCAP/PCAPNG files with full protocol analysis

pcapai analyze

Analyze packet files

pcapai analyze-bundle

Assemble the stable analysis bundle for a .pcapai as JSON (health report, capture summary, protocol hierarchy…

pcapai filter

Filter packets based on criteria

pcapai desktop

Launch desktop GUI

pcapai performance

Show performance metrics and reports

pcapai parquet

Parquet file operations

VerbWhat it does
pcapai parquet convertConvert PCAP/PCAPNG to optimized PCAPAI parquet format
pcapai parquet infoView parquet file information and statistics
pcapai parquet viewView packets from parquet file
pcapai parquet validateValidate parquet file integrity
pcapai parquet benchmarkBenchmark parquet file performance

pcapai netinsights

PCAPAI NetInsights network inventory and topology tools

VerbWhat it does
pcapai netinsights license-statusShow NetInsights license availability
pcapai netinsights workspaceCreate or inspect NetInsights workspaces
pcapai netinsights workspace createCreate or initialize a NetInsights workspace directory
pcapai netinsights workspace statusShow NetInsights workspace status
pcapai netinsights workspace encryptEncrypt an existing plaintext workspace in place (backs up the database first)
pcapai netinsights workspace deleteDelete a workspace directory and remove its OS-keychain encryption key
pcapai netinsights artifactImport, classify, or list raw evidence artifacts
pcapai netinsights artifact importImport files, directories, and archives (.zip/.tgz/.tar/.gz) into the workspace artifact store.
pcapai netinsights artifact listList imported artifacts
pcapai netinsights artifact preview-safeShow a redacted text preview of an imported artifact
pcapai netinsights artifact classifyClassify artifacts and extract first-pass device identity facts
pcapai netinsights inventoryList or search inventory facts produced from artifacts
pcapai netinsights inventory listList current devices built from classified artifacts
pcapai netinsights inventory searchSearch current devices by identity, metadata, services, resources, or topology hints
pcapai netinsights inventory interfacesList current interfaces built from classified artifacts
pcapai netinsights inventory policy-tagsAGENT TAGS-1024 (migration v32): policy tags with the SSIDs they carry and the VLAN each lands on — the C9800…
pcapai netinsights inventory site-tagsAGENT TAGS-1024 (migration v32): site tags and their AP-join bindings
pcapai netinsights inventory ssid-coverageAGENT TAGS-1024 (migration v32): which APs broadcast an SSID
pcapai netinsights inventory client-countsAGENT CLIENTS-1024 (migration v33): the aggregate client counts a Cisco C9800 show-tech carries — total clien…
pcapai netinsights inventory rogue-clientsAGENT CLIENTS-1024 (migration v33): the rogue-client inventory from show wireless wps rogue client summary
pcapai netinsights inventory radiosAGENT NIUI-1020: Wi-Fi radios (migration v26) — band, channel, width, tx power.
pcapai netinsights inventory clientsAGENT NIUI-1020: clients from the shared v28 tables, each joined with its newest sample
pcapai netinsights inventory ip-addressesList current IP addresses built from classified artifacts
pcapai netinsights inventory vlansList current VLAN facts built from classified artifacts
pcapai netinsights inventory vlan-subnet-catalogList paged VLAN and subnet catalog records with canonical network derivation
pcapai netinsights inventory neighborsList current LLDP/CDP neighbor facts built from classified artifacts
pcapai netinsights inventory mac-tableList current MAC table facts built from classified artifacts
pcapai netinsights inventory arp-tableList current ARP table facts built from classified artifacts
pcapai netinsights inventory routesList current route facts built from classified artifacts
pcapai netinsights inventory servicesList current service and control-plane feature facts built from classified artifacts
pcapai netinsights inventory resource-profilesList current forwarding profile and resource capacity facts built from classified artifacts
pcapai netinsights inventory topology-edgesList current topology edges derived from neighbor, MAC, ARP, and route evidence
pcapai netinsights inventory topology-edge-evidenceList protocol evidence attached to current topology edges
pcapai netinsights inventory topology-edge-detailShow both-sides detail for a single topology edge (link)
pcapai netinsights inventory topology-neighborhoodShow a bounded topology neighborhood around a device
pcapai netinsights inventory topology-pathFind a basic resolved topology path between two devices
pcapai netinsights inventory topology-graphExport a scoped, renderable topology graph (nodes + edges, optional layout)
pcapai netinsights inventory topology-overrideAdd or list manual topology override records
pcapai netinsights inventory topology-override addAdd a manual topology override record
pcapai netinsights inventory topology-override listList manual topology override records
pcapai netinsights inventory refresh-topology-resolutionsRefresh topology edge resolution using the latest device and IP facts
pcapai netinsights deviceShow detailed inventory state for one device
pcapai netinsights device showShow a device and its current interfaces, services, resources, and topology facts
pcapai netinsights evidenceBrowse source evidence and current fact explanations
pcapai netinsights evidence listList current fact evidence with source artifact links
pcapai netinsights evidence deviceShow fact evidence, parser observations, and quality issues for one device
pcapai netinsights evidence snippetShow a redacted source snippet around one parser observation
pcapai netinsights configStore redacted config snapshots and compare config drift
pcapai netinsights config snapshotCreate, list, or show redacted config snapshots
pcapai netinsights config snapshot createCreate a redacted config snapshot from an imported artifact
pcapai netinsights config snapshot listList redacted config snapshots
pcapai netinsights config snapshot showShow one redacted config snapshot
pcapai netinsights config templateSave or list redacted intended config templates
pcapai netinsights config template saveSave or replace a redacted intended config template from a file
pcapai netinsights config template listList config templates
pcapai netinsights config compareCompare redacted configs and captured parsed facts
pcapai netinsights config compare snapshotsCompare two config snapshot IDs
pcapai netinsights config compare devicesCompare latest config snapshots for two devices
pcapai netinsights config compare templateCompare a config snapshot to a saved template
pcapai netinsights config driftDetect drift against a template or previous snapshot
pcapai netinsights data-qualityReport missing, weak, stale, or conflicting data-quality states
pcapai netinsights data-quality reportShow derived data-quality summary and issue rows
pcapai netinsights healthReport assertion-style device, topology, and capacity health checks
pcapai netinsights health reportShow derived assertion and health-check results
pcapai netinsights health infraAGENT NIUI-1020 (roadmap #27b / §14.10): run the Infra Health engine (IC config + IL controller-log + IB base…
pcapai netinsights exportExport inventory, catalog, quality, and topology report datasets
pcapai netinsights aiPrepare redacted AI extraction input and evidence-backed troubleshooting briefs
pcapai netinsights ai prepare-extractionPrepare a bounded redacted artifact excerpt plus schema for AI extraction
pcapai netinsights ai troubleshootBuild an evidence-backed troubleshooting brief for one device
pcapai netinsights diagnosticsExport a redacted parser-diagnostics report for remote debugging
pcapai netinsights diagnostics exportWrite the redacted parser-diagnostics JSON report.
pcapai netinsights benchSynthetic scale benchmark: generate N devices and measure import and query latency

pcapai workspaces

AGENT WORKSPACE-1020 (#27a): global workspaces — list, discover, inspect

VerbWhat it does
pcapai workspaces listList every known workspace and its live state
pcapai workspaces discoverFind workspaces on disk and add anything new to the list
pcapai workspaces showShow one workspace's contents (captures, designs, logs, inventory)
pcapai workspaces addAdd a folder to the workspace list (it is never modified)
pcapai workspaces forgetRemove a workspace from the list. The folder and its contents are kept
pcapai workspaces relocatePoint a workspace at its new folder after it has been moved
pcapai workspaces activePrint or set the active workspace

pcapai device-cards

AGENT P45-1021 (§P4/§P5): your own savable AP device cards, for models the bundled RUCKUS catalog does not ha…

VerbWhat it does
pcapai device-cards listList your saved device cards, with each band's provenance
pcapai device-cards showShow one card in full
pcapai device-cards addAdd or update a card with a hand-entered peak gain
pcapai device-cards import-antennaImport a vendor antenna file (MSI / Planet .msi / .pln / .ant) onto a card.
pcapai device-cards removeDelete a card

pcapai planner

AGENT P1-1021 (§P1): Wi-Fi Planner designs — build a plan from what a workspace already knows

VerbWhat it does
pcapai planner new-from-workspaceBuild an OpenIntent plan from a workspace's floor plans and AP positions
pcapai planner import-esxConvert Ekahau .esx files into OpenIntent plans, one per BUILDING

pcapai fleet

Fleet SSH automation: device inventory, login profiles, runbooks, runs

VerbWhat it does
pcapai fleet import-textImport devices from a plain text list (one host[:port] per line)
pcapai fleet import-csvImport devices from a CSV (auto-maps host/name/vendor/...
pcapai fleet import-netinsightsImport devices from a NetInsights workspace (pre-enriched inventory)
pcapai fleet devicesList/search the device inventory
pcapai fleet profilesManage login profiles (credential sets)
pcapai fleet profiles listList login profiles
pcapai fleet profiles addAdd a login profile. --auth: password \
pcapai fleet profiles set-passwordStore the password for a profile (reads one line from stdin)
pcapai fleet profiles set-enable-secretStore the enable secret for a profile (reads one line from stdin).
pcapai fleet profiles deleteDelete a login profile (and its keychain secrets)
pcapai fleet runbooksList saved runbooks
pcapai fleet validateValidate a runbook YAML file (structure, expressions, read-only classifier)
pcapai fleet runRun a runbook against fleet devices (read-only enforced)
pcapai fleet resultsShow run results (defaults to the most recent run)
pcapai fleet rerun-failedRe-run only the failed devices of a previous run
pcapai fleet cancelCancel an active run

pcapai ssh

SSH client utilities (host-key trust store)

VerbWhat it does
pcapai ssh known-hostsManage the SSH host-key trust store (ssh_known_hosts.json)
pcapai ssh known-hosts listList every trusted host key
pcapai ssh known-hosts showShow the trusted key for one host (host, host:port, or [v6]:port)
pcapai ssh known-hosts probeFetch and print the host key a device is currently offering (no auth)
pcapai ssh known-hosts approveTrust the key a device is currently offering, replacing any previous one
pcapai ssh known-hosts removeForget a trusted host key (the next connect re-does trust-on-first-use)

pcapai console

Serial / USB-serial console: list ports, probe a cable, run read-only commands over a console when SSH cannot…

VerbWhat it does
pcapai console listList serial ports (USB-serial console adapters first).
pcapai console probeOpen a console, press Enter, and report what the device is showing.
pcapai console runRun read-only commands over a console and print their output

pcapai goto

Test Go-to-Packet jump scrolling performance on a .pcapai file

pcapai export

Export a .pcapai back out to pcap/pcapng or dissection formats (Wireshark-style)

pcapai notes

Wireshark-style capture/packet comments + capture provenance in a .pcapai

VerbWhat it does
pcapai notes showShow capture comment, capture method/provenance, and packet comments
pcapai notes set-packetSet (replace) a packet's comment
pcapai notes remove-packetRemove a packet's comment
pcapai notes set-captureSet the capture-level (file) comment
pcapai notes set-methodSet the capture method / provenance (e.g.

pcapai dns

DNS analyzer: transactions, servers, sites, health, security, name resolution

VerbWhat it does
pcapai dns summaryCapture-wide DNS totals, variant mix, latency, rcode/qtype histograms
pcapai dns serversPer-server stats: query/response counts, latency, classification
pcapai dns sitesSite/domain inventory (eTLD+1 rollup)
pcapai dns transactionsIndividual DNS transactions (recomputed live from the capture)
pcapai dns healthDNS health report (checks, per-server/per-client grades, QoE)
pcapai dns securityDNS security findings (Pro). Requires the SecurityScanner license feature
pcapai dns resolveResolve an IP to its best passive-DNS name, or a name to its IPs

pcapai merge

AGENT MERGE-1021 (§I2): find captures that are plausibly one event, and merge the ones you confirm. ---

VerbWhat it does
pcapai merge detectPropose merge groups. Read-only — nothing is merged, nothing is written
pcapai merge runMerge captures into one pcapng. Explicit file list — this never acts on a proposal by itself