DEV Community

Sandeep Ahluwalia
Sandeep Ahluwalia

Posted on

One prompt, 33 captioned packets — AI-annotating a DNS capture

A recursive DNS lookup captured behind the resolver is 33 frames in Wireshark. The story in it, a resolver that asks for DNSSEC records with a 512-byte buffer and pays for it with two TCP connections, sits in header bits you read one frame at a time.

VisualEther 9.1 adds AI annotation: Claude Code, working through VisualEther's MCP server, writes a plain-English caption onto every arrow of the sequence diagram. We tested the simplest form. A folder held one file, Chris Greer's dns_full_recursion.pcapng from his video "How DNS Works Under the Hood (Packet by Packet)", and the whole prompt was:

annotate dns_full_recursion.pcapng
Enter fullscreen mode Exit fullscreen mode

What the run did

It built its own template. No bundled sample covers DNS over TCP, so Claude started from the TCP sample, added five DNS templates (one for truncated replies), and validated them: 33 of 33 frames matched.

It read the flow before writing. It rendered the diagram with every packet's field tree and read all 33 frames before writing a caption.

It checked its claims against the packets. Field queries confirmed the 512-byte EDNS buffer with DO=1 in frames 2, 3, 21, and 24, and the truncation flag in frames 4 and 5. One check caught its own slip: the 392 bytes it first wrote for frame 23 is the UDP length, and the DNS message is 384.

It named the servers from evidence. The lanes read g.root-servers.net, g.gtld-servers.net, and ns5.infoblox.com because the capture's own glue records tie those names to the addresses in frames 15, 19, and 23.

It found the story. Its caption on the client's answer breaks the 159 ms lookup down by step: the truncation and TCP retry at the root cost about 56 ms, more than a third of the total.

A dark slide titled

A slide titled

The session took about six minutes and 14 VisualEther tool calls. It produced an annotated PDF, an interactive viewer that opens each packet's full field tree, and the captions as a Markdown file with one section per frame. Edit one and re-render.

The captions are an AI draft. Each claim was checked against the packets, but the result still deserves an expert read before anyone publishes it.

A reviewed walkthrough of the same capture: https://www.eventhelix.com/networking/dns-recursive-resolution/

To annotate your own capture, Track 3 of the getting-started guide covers it: https://www.eventhelix.com/visualether/getting-started/

Top comments (0)