🐟 v1.0 β€” Self-hosted & on-prem

See the path.
Find the fault.
Prove the cause.

Aquarium turns a raw packet capture into clear answers β€” it inspects packets, models exactly where time was lost, decodes application-layer transactions without decryption, maps host dependencies, and uses a local AI to write a prioritized root-cause report. Nothing ever leaves your network.

5 protocols decoded β€” no decryption 100% on-prem 0 data leaves your network Local AI root-cause reports
Path Delay Model transaction analysis screenshot
Core Capability

PathTraceβ„’ β€” Follow the Life of the Packet

Correlate multi-point packet captures along the transit path. Pinpoint the exact device in your infrastructure that is causing delay or dropping packets.

Aquarium's unique PathTraceβ„’ capability allows engineers to correlate multi-point packet captures along the transit path. By aligning timestamps across captures from Wireshark to tcpdump on any device that can produce standard PCAP files, PathTrace maps out the exact route.

It works seamlessly with Allegro's Edge Visibility agent for easy packet captures at the edge, allowing you to instantly isolate bottlenecks, clock skew, and packet drops between hops.

PathTrace Multi-Hop NAT/Firewall overview diagram showing packet loss and delay between PCAP capture points
Multi-Hop Path Overview: Aquarium aligns PCAP1 and PCAP2 across the NAT/Firewall device, automatically detecting the packet drop rate and transit delay. (All public IPs anonymized).
PathTrace bounce diagram mapping individual packet sequence numbers and retransmissions across capture points
Path Bounce Ladder: Follow individual packet sequences and ACKs as they transit between lanes. Retransmissions and drops are flagged visually with steepness indicating transit speeds.
PathTrace transfer time breakdown chart and donut breakdown separating server processing and network queuing latency
Transfer Time Breakdown: See precisely where time is spent. The donut chart categorizes outbound hold/queuing, drop recovery, and server processing for the selected transfer window.
PathTrace data tables detailing transaction transit statistics and individual lost packet details
Latency & Loss details: Dive deep with sequence-level metrics showing size, transit ms, propagation delay, queuing ms, and loss penalty penalties.
Capabilities

Everything in one capture.

From raw bytes to root-cause report β€” Aquarium covers every layer of analysis without exporting a single packet.

πŸ”¬

WebShark Packet Viewer

A fast, tshark-powered packet list with full display filter support. Drill from a high-level flow view down to individual bytes β€” right in the browser.

↕️

Bounce Diagram

A clean client ⇄ server ladder showing the full conversation packet by packet β€” exactly when each segment was sent and when its ACK arrived.

⏱️

Path Delay Modeling

Deterministic breakdown of where the time went: connection setup, propagation, server processing, data transfer, loss recovery, congestion, zero-window, delayed-ACK. Plus What-If modeling β€” drag RTT and bandwidth sliders and watch bottlenecks shift in real time.

πŸ”“

Application Transactions β€” No Decryption

Decodes SMB1, SMB2, TLS record-level turns, Oracle SQL*Net/TNS (recovering clear-text SQL), and HTTP β€” all without touching a private key. Per-operation breakdown, service times, byte counts, and a per-transaction waterfall.

πŸ“Š

Response-Time Analytics

Scatter plots, p50/p95/p99 percentile bands, histogram, CDF β€” with automatic slow-tail and anomaly flagging. Know exactly which transactions are dragging your averages down.

πŸ•ΈοΈ

Application Dependency Map

A host-to-host traffic matrix: who talks to whom, how much, and at what latency β€” fully filterable. Spot unexpected talkers and unplanned dependencies instantly.

πŸ€–

AI-Assisted Root Cause Local LLM

Generates dual-audience reports locally on your server. Engineers get low-level timing profiles and trace correlations, while managers get clear business impact summaries and prioritized action items β€” all 100% on-premise.

πŸ›€οΈ

PathTraceβ„’

Capture the same transaction at multiple points along the path. Aquarium correlates packet timestamps across capture points to measure real cross-device transit time, localize loss to a specific hop, and detect clock skew β€” ground truth, not single-vantage guesswork.

πŸ”’

Enterprise-Ready & Secure

Self-hosted in Docker. Local accounts with role-based admin, full audit trail of logins and PCAP uploads, configurable per-user idle auto-logout. Your captures β€” and your AI β€” never leave your infrastructure.

Workflow

From PCAP to root cause in three steps.

No agents, no cloud pipelines, no configuration sprawl β€” just a capture file and answers.

01
πŸ“‚

Upload a PCAP or PCAPNG

Drag-and-drop any capture file β€” from Wireshark, tcpdump, or a tap β€” directly into the browser. Aquarium indexes it instantly.

Secure upload
02
πŸ”

Inspect Packets & Timing

Explore the packet list, bounce diagram, delay model, application transactions, dependency map, and response-time analytics β€” all rendered locally in your browser.

8 analysis views
03
πŸ“„

Get a Local-AI Root-Cause Report

Your on-prem LLM reads the combined context, correlates across layers, and generates a structured findings report β€” PDF export in one click, dark theme preserved.

PDF export
Visualizations

Every view your team needs.

Rich, interactive charts built for network engineers β€” not dashboards stitched together from generic BI tools.

Path Delay Model What-If enabled
Path Delay Model transaction analysis screenshot
Response-Time Scatter p50 / p95 / p99
Application Transaction Waterfall SMB2 / TLS / HTTP
0ms 100ms 200ms 300ms NEGOTIATE SESSION SETUP TREE CONNECT CREATE READ #1 READ #2 WRITE CLOSE Server processing Response
Dependency Map 5 hosts
1.2 GB 4.8 GB 840 MB 2.1 GB CLIENT 10.0.1.5 APP SRV 10.0.2.11 DATABASE 10.0.2.20 CACHE 10.0.3.4 SQL-R 10.0.2.22 PROXY 10.0.1.1
Response-Time Distribution
Bounce / Ladder Diagram Packet-by-packet
CLIENT SERVER SYN 0.000s SYN-ACK 0.021s ACK HTTP GET /api/data 0.043s 82ms server HTTP 200 OK (1.4 KB) 0.146s ACK 0.168s FIN
On-Premise Intelligence

Automated AI Reports for Engineers and Managers

Translate raw packet captures into structured, business-ready diagnostics. Instantly pivot between technical root-cause trace analysis and non-technical management summaries.

Dual-Audience Reporting Modes

Stop spending hours translating Wireshark details into management summaries. Aquarium's on-premises AI analyzes packet timing anomalies, application transactions, and path delays to generate tailored views for your entire organization:

  • πŸ› οΈ
    Engineer's Findings

    Detailed analysis of TCP Congestion Sawtooth Spirals, application-layer write latency profiles, and packet loss recovery metrics, coupled with exact buffer tuning guidelines.

  • πŸ’Ό
    Non-Technical Management Summary

    A jargon-free executive overview focusing on application response times, business SLA impacts, and a simplified timeline of concrete remediation next steps.

100% On-Premise LLM Zero External API Calls
TraceMind AI reporting mashup showcasing technical analysis reports overlaid with high-level management summary views and recommended next steps
Interactive local AI analysis report illustrating the automatic pivot from raw TCP/IP traces to executive summaries. (All target IP addresses anonymized).
Privacy & Trust

Your network data
stays on your network.

Aquarium is designed from the ground up for air-gapped and data-sensitive environments. The AI model runs locally β€” no packets, no summaries, no telemetry ever traverse the internet.

🐳 Docker self-hosted Role-based access control Full audit trail Zero cloud dependency Per-user idle logout Local LLM inference
Get started

Ready to see inside your traffic?

Request a demo and we'll walk you through a live analysis of your own capture file β€” on your infrastructure, on your schedule.