# Naming **Decided: packeteer.** packet + `-eer` (the agent-noun suffix in *engineer*, *puppeteer*, *musketeer*, *auctioneer* - "one who wields the thing"), landing on a practitioner/character feel rather than a plain descriptive tool name. Checked before committing: no existing open-source packet-capture/analysis project uses it. Two known, non-blocking collisions worth remembering if this ever comes up - **Packeteer, Inc.** (1996-2008, NASDAQ: PKTR) was a real networking company that made *PacketShaper*, a WAN traffic-shaping appliance, acquired by Blue Coat Systems and fully absorbed since - defunct, no live trademark, but it'll surface in searches; and the bare `packeteer` username/org on GitHub is already held by an unrelated individual, so the repo lives under this project's own namespace rather than as a top-level org name. The rest of this file is the brainstorm that led here, kept for the record rather than pruned. Landscape checked for collisions / conventions: tcpdump, Wireshark, tshark, termshark, ngrep, ettercap, etherape, snoop, bmon, iftop, nethogs, bandwhich, trippy, gping, dog, ntap, netwatch. ## Conventions those projects use - **Unix terseness**: tcpdump, ngrep, ss, ip - short, lowercase, often a syscall or protocol abbreviation mashed with a verb (dump, grep, top). - **-shark family**: Wireshark → tshark (terminal) → termshark (TUI). A recognizable brand extended by prefixing the interface type. - **Verb-as-noun branding**: bandwhich, trippy, dog, bat, fd, ripgrep - a plain English word or pun, repurposed, no domain jargon in the name itself. This is the modern Rust-CLI convention. - **Portmanteau of domain nouns**: etherape (ether + ape), snoop, ettercap (etter + cap, Italian "hetter" + capture). - **Agent-noun branding**: packeteer (packet + -eer, "one who wields packets") - the convention this project's name actually landed on; not represented in the landscape checked above, which leaned Unix-terse/portmanteau/plain-word instead. ## Names considered along the way (not chosen) ### Wire/frame lineage (the project's working name for most of its build) `wireframe` - wire (network) + frame (Ethernet/IP frame, also a UI "wireframe" pun) - was the working name up to this point. Dropped in favor of packeteer once the project had grown well past "one narrow decoder" into full L2-L7 dissection, reassembly, checksums, privilege dropping, and dual frontends - packeteer's agent-noun framing fit that breadth better than a still-literal wire/frame pun. ### Unix-style short (syscall/tool-terse) - `pktap` - packet + tap - `nettap` - `rawtap` - `spantap` - nods to `std::span`, the project's core learning device - `ethtap` - `frmtap` - frame + tap ### -shark / portmanteau branding (extends the Wireshark lineage like tshark/termshark did) - `frameshark` - `spanshark` - `wiresnoop` - `packsnoop` - `bytewire` - `netframe` - `packframe` - `framewire` - `layershark` / `stackshark` - added later, once L2-L7 were all decoded - `wirehawk` - same wire+animal cadence as Wireshark, swapping the predator for "hawk-eyed" (keen observation) instead - `wirespider` - a spider senses everything through vibrations along silk threads, a close metaphor for sensing traffic on a wire; arguably the tightest metaphor fit in this whole lineage - `orca` - orcas are one of the few animals that hunt sharks; considered as a way to "supersede" the Wireshark pun rather than extend it ### Evocative single word (bandwhich/trippy/dog convention - plain word, no jargon) - `peek` - `probe` - `glimpse` - `sift` - `trawl` - `snare` - `prowl` - `siphon` - `dissect` - plain, describes exactly what the tool does at every layer; risk is it's a generic verb likely to collide with something ### References `std::span` directly (the project's actual technical hook) - `spancap` - `spanview` - `bytespan` - `octospan` - `netspan` ### Byte/octet lane (surfaced once the L2-L4 decoders read one octet at a time by hand) - `octet` - the actual networking term for a byte; precise, unclaimed in the landscape checked - `octetap` - `byteframe` - `framecap` - `tapframe` - `pcapview` ### Reassembly/privilege-dropping lane (surfaced once those features landed) - `flowtap` - "flow" is the real industry term for a TCP 4-tuple's worth of tracked state, more precise than "stream" - `stitchtap` - literal description of reassembly - `reflow` - collides conceptually with CSS/text "reflow" - `dropcap` - pun on dropping root/CAP_NET_RAW right after opening the capture handle, which also happens to be a real typography term (an oversized first letter) - two genuine meanings on one word, the strongest pun found in this whole search - `polytap` - poly- (the many protocols dissected: DNS/HTTP/TLS/mDNS/ SSH/ICMP) + tap ### Playful / punny - `Framed` - "you've been framed" (packet frames) - `Packeteer` - **chosen**, see top of file - `Sniffy` - `wiretap` - plain-word option; flagged as possibly already taken somewhere given how common the word is, never fully checked - `flagship` - pun on TCP flags (SYN/ACK/FIN); cute but unclear at a glance that it's a network tool