pcapai convertConvert PCAP/PCAPNG files to PCAPAI format
pcapai convert-batchConvert MANY PCAP/PCAPNG files to PCAPAI, several at a time
pcapai dissectDissect PCAP/PCAPNG files with full protocol analysis
pcapai analyzeAnalyze packet files
pcapai analyze-bundleAssemble the stable analysis bundle for a .pcapai as JSON (health report, capture summary, protocol hierarchy…
pcapai filterFilter packets based on criteria
pcapai desktopLaunch desktop GUI
pcapai performanceShow performance metrics and reports
pcapai parquetParquet file operations
| Verb | What it does |
|---|---|
pcapai parquet convert | Convert PCAP/PCAPNG to optimized PCAPAI parquet format |
pcapai parquet info | View parquet file information and statistics |
pcapai parquet view | View packets from parquet file |
pcapai parquet validate | Validate parquet file integrity |
pcapai parquet benchmark | Benchmark parquet file performance |
pcapai netinsightsPCAPAI NetInsights network inventory and topology tools
| Verb | What it does |
|---|---|
pcapai netinsights license-status | Show NetInsights license availability |
pcapai netinsights workspace | Create or inspect NetInsights workspaces |
pcapai netinsights workspace create | Create or initialize a NetInsights workspace directory |
pcapai netinsights workspace status | Show NetInsights workspace status |
pcapai netinsights workspace encrypt | Encrypt an existing plaintext workspace in place (backs up the database first) |
pcapai netinsights workspace delete | Delete a workspace directory and remove its OS-keychain encryption key |
pcapai netinsights artifact | Import, classify, or list raw evidence artifacts |
pcapai netinsights artifact import | Import files, directories, and archives (.zip/.tgz/.tar/.gz) into the workspace artifact store. |
pcapai netinsights artifact list | List imported artifacts |
pcapai netinsights artifact preview-safe | Show a redacted text preview of an imported artifact |
pcapai netinsights artifact classify | Classify artifacts and extract first-pass device identity facts |
pcapai netinsights inventory | List or search inventory facts produced from artifacts |
pcapai netinsights inventory list | List current devices built from classified artifacts |
pcapai netinsights inventory search | Search current devices by identity, metadata, services, resources, or topology hints |
pcapai netinsights inventory interfaces | List current interfaces built from classified artifacts |
pcapai netinsights inventory policy-tags | AGENT TAGS-1024 (migration v32): policy tags with the SSIDs they carry and the VLAN each lands on — the C9800… |
pcapai netinsights inventory site-tags | AGENT TAGS-1024 (migration v32): site tags and their AP-join bindings |
pcapai netinsights inventory ssid-coverage | AGENT TAGS-1024 (migration v32): which APs broadcast an SSID |
pcapai netinsights inventory client-counts | AGENT CLIENTS-1024 (migration v33): the aggregate client counts a Cisco C9800 show-tech carries — total clien… |
pcapai netinsights inventory rogue-clients | AGENT CLIENTS-1024 (migration v33): the rogue-client inventory from show wireless wps rogue client summary |
pcapai netinsights inventory radios | AGENT NIUI-1020: Wi-Fi radios (migration v26) — band, channel, width, tx power. |
pcapai netinsights inventory clients | AGENT NIUI-1020: clients from the shared v28 tables, each joined with its newest sample |
pcapai netinsights inventory ip-addresses | List current IP addresses built from classified artifacts |
pcapai netinsights inventory vlans | List current VLAN facts built from classified artifacts |
pcapai netinsights inventory vlan-subnet-catalog | List paged VLAN and subnet catalog records with canonical network derivation |
pcapai netinsights inventory neighbors | List current LLDP/CDP neighbor facts built from classified artifacts |
pcapai netinsights inventory mac-table | List current MAC table facts built from classified artifacts |
pcapai netinsights inventory arp-table | List current ARP table facts built from classified artifacts |
pcapai netinsights inventory routes | List current route facts built from classified artifacts |
pcapai netinsights inventory services | List current service and control-plane feature facts built from classified artifacts |
pcapai netinsights inventory resource-profiles | List current forwarding profile and resource capacity facts built from classified artifacts |
pcapai netinsights inventory topology-edges | List current topology edges derived from neighbor, MAC, ARP, and route evidence |
pcapai netinsights inventory topology-edge-evidence | List protocol evidence attached to current topology edges |
pcapai netinsights inventory topology-edge-detail | Show both-sides detail for a single topology edge (link) |
pcapai netinsights inventory topology-neighborhood | Show a bounded topology neighborhood around a device |
pcapai netinsights inventory topology-path | Find a basic resolved topology path between two devices |
pcapai netinsights inventory topology-graph | Export a scoped, renderable topology graph (nodes + edges, optional layout) |
pcapai netinsights inventory topology-override | Add or list manual topology override records |
pcapai netinsights inventory topology-override add | Add a manual topology override record |
pcapai netinsights inventory topology-override list | List manual topology override records |
pcapai netinsights inventory refresh-topology-resolutions | Refresh topology edge resolution using the latest device and IP facts |
pcapai netinsights device | Show detailed inventory state for one device |
pcapai netinsights device show | Show a device and its current interfaces, services, resources, and topology facts |
pcapai netinsights evidence | Browse source evidence and current fact explanations |
pcapai netinsights evidence list | List current fact evidence with source artifact links |
pcapai netinsights evidence device | Show fact evidence, parser observations, and quality issues for one device |
pcapai netinsights evidence snippet | Show a redacted source snippet around one parser observation |
pcapai netinsights config | Store redacted config snapshots and compare config drift |
pcapai netinsights config snapshot | Create, list, or show redacted config snapshots |
pcapai netinsights config snapshot create | Create a redacted config snapshot from an imported artifact |
pcapai netinsights config snapshot list | List redacted config snapshots |
pcapai netinsights config snapshot show | Show one redacted config snapshot |
pcapai netinsights config template | Save or list redacted intended config templates |
pcapai netinsights config template save | Save or replace a redacted intended config template from a file |
pcapai netinsights config template list | List config templates |
pcapai netinsights config compare | Compare redacted configs and captured parsed facts |
pcapai netinsights config compare snapshots | Compare two config snapshot IDs |
pcapai netinsights config compare devices | Compare latest config snapshots for two devices |
pcapai netinsights config compare template | Compare a config snapshot to a saved template |
pcapai netinsights config drift | Detect drift against a template or previous snapshot |
pcapai netinsights data-quality | Report missing, weak, stale, or conflicting data-quality states |
pcapai netinsights data-quality report | Show derived data-quality summary and issue rows |
pcapai netinsights health | Report assertion-style device, topology, and capacity health checks |
pcapai netinsights health report | Show derived assertion and health-check results |
pcapai netinsights health infra | AGENT NIUI-1020 (roadmap #27b / §14.10): run the Infra Health engine (IC config + IL controller-log + IB base… |
pcapai netinsights export | Export inventory, catalog, quality, and topology report datasets |
pcapai netinsights ai | Prepare redacted AI extraction input and evidence-backed troubleshooting briefs |
pcapai netinsights ai prepare-extraction | Prepare a bounded redacted artifact excerpt plus schema for AI extraction |
pcapai netinsights ai troubleshoot | Build an evidence-backed troubleshooting brief for one device |
pcapai netinsights diagnostics | Export a redacted parser-diagnostics report for remote debugging |
pcapai netinsights diagnostics export | Write the redacted parser-diagnostics JSON report. |
pcapai netinsights bench | Synthetic scale benchmark: generate N devices and measure import and query latency |
pcapai workspacesAGENT WORKSPACE-1020 (#27a): global workspaces — list, discover, inspect
| Verb | What it does |
|---|---|
pcapai workspaces list | List every known workspace and its live state |
pcapai workspaces discover | Find workspaces on disk and add anything new to the list |
pcapai workspaces show | Show one workspace's contents (captures, designs, logs, inventory) |
pcapai workspaces add | Add a folder to the workspace list (it is never modified) |
pcapai workspaces forget | Remove a workspace from the list. The folder and its contents are kept |
pcapai workspaces relocate | Point a workspace at its new folder after it has been moved |
pcapai workspaces active | Print or set the active workspace |
pcapai device-cardsAGENT P45-1021 (§P4/§P5): your own savable AP device cards, for models the bundled RUCKUS catalog does not ha…
| Verb | What it does |
|---|---|
pcapai device-cards list | List your saved device cards, with each band's provenance |
pcapai device-cards show | Show one card in full |
pcapai device-cards add | Add or update a card with a hand-entered peak gain |
pcapai device-cards import-antenna | Import a vendor antenna file (MSI / Planet .msi / .pln / .ant) onto a card. |
pcapai device-cards remove | Delete a card |
pcapai plannerAGENT P1-1021 (§P1): Wi-Fi Planner designs — build a plan from what a workspace already knows
| Verb | What it does |
|---|---|
pcapai planner new-from-workspace | Build an OpenIntent plan from a workspace's floor plans and AP positions |
pcapai planner import-esx | Convert Ekahau .esx files into OpenIntent plans, one per BUILDING |
pcapai fleetFleet SSH automation: device inventory, login profiles, runbooks, runs
| Verb | What it does |
|---|---|
pcapai fleet import-text | Import devices from a plain text list (one host[:port] per line) |
pcapai fleet import-csv | Import devices from a CSV (auto-maps host/name/vendor/... |
pcapai fleet import-netinsights | Import devices from a NetInsights workspace (pre-enriched inventory) |
pcapai fleet devices | List/search the device inventory |
pcapai fleet profiles | Manage login profiles (credential sets) |
pcapai fleet profiles list | List login profiles |
pcapai fleet profiles add | Add a login profile. --auth: password \ |
pcapai fleet profiles set-password | Store the password for a profile (reads one line from stdin) |
pcapai fleet profiles set-enable-secret | Store the enable secret for a profile (reads one line from stdin). |
pcapai fleet profiles delete | Delete a login profile (and its keychain secrets) |
pcapai fleet runbooks | List saved runbooks |
pcapai fleet validate | Validate a runbook YAML file (structure, expressions, read-only classifier) |
pcapai fleet run | Run a runbook against fleet devices (read-only enforced) |
pcapai fleet results | Show run results (defaults to the most recent run) |
pcapai fleet rerun-failed | Re-run only the failed devices of a previous run |
pcapai fleet cancel | Cancel an active run |
pcapai sshSSH client utilities (host-key trust store)
| Verb | What it does |
|---|---|
pcapai ssh known-hosts | Manage the SSH host-key trust store (ssh_known_hosts.json) |
pcapai ssh known-hosts list | List every trusted host key |
pcapai ssh known-hosts show | Show the trusted key for one host (host, host:port, or [v6]:port) |
pcapai ssh known-hosts probe | Fetch and print the host key a device is currently offering (no auth) |
pcapai ssh known-hosts approve | Trust the key a device is currently offering, replacing any previous one |
pcapai ssh known-hosts remove | Forget a trusted host key (the next connect re-does trust-on-first-use) |
pcapai consoleSerial / USB-serial console: list ports, probe a cable, run read-only commands over a console when SSH cannot…
| Verb | What it does |
|---|---|
pcapai console list | List serial ports (USB-serial console adapters first). |
pcapai console probe | Open a console, press Enter, and report what the device is showing. |
pcapai console run | Run read-only commands over a console and print their output |
pcapai gotoTest Go-to-Packet jump scrolling performance on a .pcapai file
pcapai exportExport a .pcapai back out to pcap/pcapng or dissection formats (Wireshark-style)
pcapai notesWireshark-style capture/packet comments + capture provenance in a .pcapai
| Verb | What it does |
|---|---|
pcapai notes show | Show capture comment, capture method/provenance, and packet comments |
pcapai notes set-packet | Set (replace) a packet's comment |
pcapai notes remove-packet | Remove a packet's comment |
pcapai notes set-capture | Set the capture-level (file) comment |
pcapai notes set-method | Set the capture method / provenance (e.g. |
pcapai dnsDNS analyzer: transactions, servers, sites, health, security, name resolution
| Verb | What it does |
|---|---|
pcapai dns summary | Capture-wide DNS totals, variant mix, latency, rcode/qtype histograms |
pcapai dns servers | Per-server stats: query/response counts, latency, classification |
pcapai dns sites | Site/domain inventory (eTLD+1 rollup) |
pcapai dns transactions | Individual DNS transactions (recomputed live from the capture) |
pcapai dns health | DNS health report (checks, per-server/per-client grades, QoE) |
pcapai dns security | DNS security findings (Pro). Requires the SecurityScanner license feature |
pcapai dns resolve | Resolve an IP to its best passive-DNS name, or a name to its IPs |
pcapai mergeAGENT MERGE-1021 (§I2): find captures that are plausibly one event, and merge the ones you confirm. ---
| Verb | What it does |
|---|---|
pcapai merge detect | Propose merge groups. Read-only — nothing is merged, nothing is written |
pcapai merge run | Merge captures into one pcapng. Explicit file list — this never acts on a proposal by itself |