cd /news/ai-agents/one-prompt-33-captioned-packets-ai-a… · home › topics › ai-agents › article
[ARTICLE · art-142116] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=↑ positive

One prompt, 33 captioned packets — AI-annotating a DNS capture

EventHelix's VisualEther 9.1 added AI annotation that uses Claude Code through the tool's MCP server to caption every arrow of a packet sequence diagram. Given a single prompt to annotate a 33-frame DNS recursion capture, the system built its own DNS-over-TCP templates, validated all 33 frames, and produced an annotated PDF, an interactive viewer, and per-frame Markdown captions in about six minutes and 14 tool calls. The vendor notes the captions are an AI draft that still warrants expert review before publication.

by read2 min views3 publishedSep 29, 2026

A recursive DNS lookup captured behind the resolver is 33 frames in Wireshark. The story in it, a resolver that asks for DNSSEC records with a 512-byte buffer and pays for it with two TCP connections, sits in header bits you read one frame at a time.

VisualEther 9.1 adds AI annotation: Claude Code, working through VisualEther's MCP server, writes a plain-English caption onto every arrow of the sequence diagram. We tested the simplest form. A folder held one file, Chris Greer's dns_full_recursion.pcapng from his video "How DNS Works Under the Hood (Packet by Packet)", and the whole prompt was:

annotate dns_full_recursion.pcapng

It built its own template. No bundled sample covers DNS over TCP, so Claude started from the TCP sample, added five DNS templates (one for truncated replies), and validated them: 33 of 33 frames matched.

It read the flow before writing. It rendered the diagram with every packet's field tree and read all 33 frames before writing a caption.

It checked its claims against the packets. Field queries confirmed the 512-byte EDNS buffer with DO=1 in frames 2, 3, 21, and 24, and the truncation flag in frames 4 and 5. One check caught its own slip: the 392 bytes it first wrote for frame 23 is the UDP length, and the DNS message is 384.

It named the servers from evidence. The lanes read g.root-servers.net, g.gtld-servers.net, and ns5.infoblox.com because the capture's own glue records tie those names to the addresses in frames 15, 19, and 23.

It found the story. Its caption on the client's answer breaks the 159 ms lookup down by step: the truncation and TCP retry at the root cost about 56 ms, more than a third of the total.

The session took about six minutes and 14 VisualEther tool calls. It produced an annotated PDF, an interactive viewer that opens each packet's full field tree, and the captions as a Markdown file with one section per frame. Edit one and re-render.

The captions are an AI draft. Each claim was checked against the packets, but the result still deserves an expert read before anyone publishes it.

A reviewed walkthrough of the same capture: https://www.eventhelix.com/networking/dns-recursive-resolution/

To annotate your own capture, Track 3 of the getting-started guide covers it: https://www.eventhelix.com/visualether/getting-started/

── more in #ai-agents 4 stories · sorted by recency
── more on @visualether 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/one-prompt-33-captio…] indexed:0 read:2min 2026-09-29 · —