free tool — zero signup

pcap-to-ladder

Paste the raw text of a Wireshark Follow TCP/UDP Stream (or tshark export) below, and get a color-coded SIP ladder diagram back. The leg that turns red is the leg that breaks — usually the ACK that never arrives. No forms, no sales follow-up.

How it works

The parser walks your pasted stream, finds SIP requests (INVITE, REGISTER, ACK, BYE, CANCEL, OPTIONS, SUBSCRIBE) and responses (100–699), infers the two endpoints from addresses in the stream or the message order, and lays each message out as a leg on a two-column ladder. Failure legs (4xx/5xx/6xx, lost ACK) render red; 200 OK renders green. Everything runs in your browser — the capture never leaves the page.

Usage — 3 lines

PS> # export the stream first (Wireshark: right-click → Follow → TCP/UDP Stream → raw)
tshark -r .\capture.pcapng -q -z follow,tcp,raw,0
tshark -r .\capture.pcapng -Y "sip" -T fields -e sip.msg_line

Either export works: the raw Follow-Stream text or a per-message field list. Paste it on the right.

Your capture

runs locally — nothing uploads

Reading ladders all day is our job too — our orchestration layer renders them per tenant, live.

Deploy Free 14-Day Sandbox — No Credit Card Required