
GITNUXSOFTWARE ADVICE
SecurityTop 10 Best Usb Analyzer Software of 2026
Ranked picks for usb analyzer software based on port visibility, device controls, and logging depth, with Total Phase and Teledyne LeCroy noted.
How we ranked these tools
Core product claims cross-referenced against official documentation, changelogs, and independent technical reviews.
Analyzed video reviews and hundreds of written evaluations to capture real-world user experiences with each tool.
AI persona simulations modeled how different user types would experience each tool across common use cases and workflows.
Final rankings reviewed and approved by our editorial team with authority to override AI-generated scores based on domain expertise.
Score: Features 40% · Ease 30% · Value 30%
Gitnux may earn a commission through links on this page — this does not influence rankings. Editorial policy
Total Phase Data Center Software is the best pick if you run repeatable USB enumeration and protocol-level debugging in a lab with matching hardware, while Device Monitoring Studio fits IT and lab teams that need identity and transfer-level investigation across multiple protocols.
Editor’s top 3 picks
Three quick recommendations before you dive into the full comparison below — each one leads on a different dimension.
Total Phase Data Center Software
Descriptor tree view keeps interface, endpoint, and request context synchronized during trace navigation.
Built for fits when labs need repeatable USB trace decode for enumeration and protocol-level debugging during test bench work..
Device Monitoring Studio
Editor pickInspector-style capture review that links VID and PID identity to subsequent transfer activity over time.
Built for fits when IT and lab teams need USB device identity plus transfer-level investigation..
Teledyne LeCroy Voyager
Editor pickDescriptor parsing plus request-level correlation supports fast mapping from device identity to exact failing transactions.
Built for fits when engineering teams need repeatable USB decoding for enumeration and class-level debugging..
Comparison Table
Total Phase Data Center Software
enterpriseProtocol analysis software bundled with Total Phase Beagle USB hardware analyzers for real-time USB capture and decoding.
Descriptor tree view keeps interface, endpoint, and request context synchronized during trace navigation.
Total Phase Data Center Software is built around systematic USB capture and inspection workflows. The UI presents device and configuration context using a descriptor tree view so investigators can map VID and PID to enumeration behavior and follow class requests through the trace. Capture review supports export-style interoperability with common USB capture formats, which helps teams move sessions into secondary tooling for deeper packet inspection.
A tradeoff is that the workflow relies on an attached capture setup and capture session management rather than pure software-only sniffing in every environment. A common usage situation is a test bench where a flaky device enumerates inconsistently, and the goal is to compare descriptor outcomes across runs and pinpoint the specific control request or transfer sequence that changes.
- +Descriptor tree view links device identity to configuration and interface context
- +Timestamped decode helps correlate control requests with subsequent data transfers
- +Capture session replay supports repeatable USB behavior investigations
- +Class request decoding improves trace readability versus raw packet lists
- –Requires a compatible capture setup and careful session handling for repeatability
- –Deep filtering needs procedural setup rather than a fully freeform query builder
USB validation engineers
Diagnose enumeration regressions across firmware builds
Faster fault localization
Device driver developers
Review host request patterns for bulk transfers
Clear transfer sequence
Show 1 more scenario
QA test automation leads
Establish USB behavior baselines per device variant
Repeatable regression checks
Record capture sessions and replay traces to spot drift in descriptors and class requests.
Best for: Fits when labs need repeatable USB trace decode for enumeration and protocol-level debugging during test bench work.
Device Monitoring Studio
vertical specialistMulti-protocol monitoring suite from HHD Software with a dedicated USB monitoring module for traffic capture and decoding.
Inspector-style capture review that links VID and PID identity to subsequent transfer activity over time.
Device Monitoring Studio centers on USB analyzer workflows that start with device enumeration and continue through ongoing traffic observation, so issues can be traced from VID and PID identification to later activity. The interface emphasizes inspection of device identity fields and transfer context during a capture session. Capture review is geared toward repeating an investigation cycle, not only grabbing a single snapshot. Export support helps when deeper protocol analysis or collaborative review requires standard USB capture formats.
The main tradeoff is that deep interpretation depends on the captured traffic scope, so USB edge cases that do not reach full descriptor or request coverage yield less actionable detail. Device Monitoring Studio works best in lab and staging environments where a specific failing USB device or hub topology can be reproduced and captured. For ongoing administration at scale, it fits better as an investigative analyzer than as a primary fleet-wide control plane.
- +Clear device identity inspection with VID and PID surfaced during capture review
- +Capture-to-review workflow supports iterative troubleshooting sessions
- +Export supports moving USB captures into external analysis workflows
- +Transfer context helps correlate later activity with enumerated devices
- –Deep protocol interpretation depends on capture scope and successful enumeration coverage
- –Automation and API surface are limited compared with control-focused endpoint products
- –High-volume bus traffic can make interactive review slower
Endpoint engineering teams
Diagnose recurring USB device failures
Root cause narrowed to device behavior
IT helpdesk escalation
Verify whether a USB device enumerates
Faster yes or no triage
Show 1 more scenario
Security analysts
Investigate suspicious USB activity traces
Event timeline supports incident review
Reviews capture context to determine which VID and PID performed later transfers after connection.
Best for: Fits when IT and lab teams need USB device identity plus transfer-level investigation.
Teledyne LeCroy Voyager
enterpriseHardware USB protocol analyzer platform with companion software for capturing and decoding USB 2.0, 3.x, and Type-C traffic.
Descriptor parsing plus request-level correlation supports fast mapping from device identity to exact failing transactions.
Voyager is designed for USB packet capture workflows where endpoint enumeration and descriptor tree inspection are central to troubleshooting and validation. It provides structured protocol decoding for common transfer types, which reduces time spent mapping raw captures to device behavior. The interface supports drilling from high-level device information into individual requests and responses for tighter root-cause analysis.
A key tradeoff is that Voyager is oriented around capture and decode workflows rather than device-side enforcement, so it does not replace purpose-built USB control or endpoint blocking tools. It fits best when engineers need repeatable inspection of a failing enumeration sequence or a specific class interaction, especially when multiple captures must be compared during regression testing.
- +Descriptor tree view speeds up VID PID and configuration checks
- +Transfer request tracking keeps control and data flows tied together
- +Timestamp correlation supports sequence reconstruction during failures
- +USB pcap export enables offline review in standard tooling
- –USB capture requires careful driver and host configuration
- –Automation coverage is lighter than general enterprise telemetry tools
USB firmware engineers
Debug failing enumeration sequence
Faster root-cause isolation
QA validation teams
Compare captures across builds
Reduced investigation time
Show 1 more scenario
System integration teams
Inspect class interaction issues
Quicker compatibility fixes
Class request decoding and request tracking help narrow timing and behavioral mismatches.
Best for: Fits when engineering teams need repeatable USB decoding for enumeration and class-level debugging.
Wireshark
open sourceOpen-source protocol analyzer with USB capture support via USBPcap on Windows and native USB monitoring on Linux.
USB-capable dissectors turn captured frames into a structured protocol tree with descriptor details.
Wireshark delivers packet-centric USB analysis by importing USB traces into the same timeline and protocol-tree model used for network traffic.
Descriptor parsing and class-level decoding become practical when USB-specific capture tools produce compatible pcap structures that Wireshark can dissect.
- +Protocol tree view supports deep USB descriptor parsing per frame
- +Filter language lets narrow analysis to control transfers and endpoints
- +Wireshark USB pcap export workflows fit existing pcap review pipelines
- +Extensible dissectors support USB class traffic decoding via add-ons
- –USB capture fidelity depends on the capture backend and adapter driver
- –Large traces can slow UI performance without careful display filter use
- –Automation is limited compared with endpoint-focused USB control suites
- –USB 3.x capture details require consistent capture settings to decode well
Best for: Fits when teams need repeatable USB packet forensics from recorded pcaps, not device blocking.
USBTrace
vertical specialistUSB protocol and device analyzer from SysNucleus supporting capture, filtering, and decoding of USB traffic.
Descriptor tree view ties identity and endpoint enumeration to the same session timeline for faster request correlation.
USBTrace records USB traffic with host-side capture suitable for enumeration trace and later inspection of descriptors and requests. The tool groups events into a descriptor tree view and connects them to endpoint enumeration so analysts can follow device identity to transfer behavior.
It supports USB packet capture export workflows for sharing captures and inspecting timing and errors across sessions. USBTrace is geared toward transfer-request tracking for diagnosing failures in control and data paths rather than only listing raw packets.
- +Descriptor tree view links VID and PID to endpoint enumeration
- +Capture-to-analysis flow supports USB packet capture export
- +Transfer-request tracking improves traceability from setup to data
- –Workflow depth depends on correct capture filters and host setup
- –Deep class decoding coverage is narrower than full dissector tooling
Best for: Fits when teams need repeatable USB host-side captures and descriptor driven debugging without full packet dissector overhead.
Ellisys USB Explorer
enterpriseHigh-end USB protocol analysis system pairing Ellisys Explorer hardware with analysis software for USB 2.0 and SuperSpeed traffic.
Enumeration trace view that ties descriptor parsing results directly to class request and endpoint enumeration events.
Ellisys USB Explorer targets USB traffic analysis with an emphasis on host-side visibility, descriptor parsing, and per-transfer inspection. It combines enumeration trace views with protocol-level decoding for control, bulk, and isochronous traffic so specific device behavior can be tied back to captured transactions.
The workflow centers on capturing from supported USB interfaces, browsing a descriptor tree, and exporting captured data into formats compatible with packet analysis tools. For teams that need repeatable inspection of problematic enumeration, class requests, and endpoint activity, its trace-first UI and export pipeline reduce time spent correlating events across views.
- +Descriptor tree view speeds mapping VID and PID to endpoint behavior
- +Enumeration trace correlates class requests with endpoint enumeration events
- +USBPcap-compatible capture export supports packet-level external analysis
- +Per-transfer inspection keeps control, bulk, and isochronous timelines readable
- –Capture workflow depends on supported USB hardware interfaces and drivers
- –Advanced decoding and export use cases require more setup discipline
- –Large captures can slow interactive navigation in descriptor and trace views
- –Automation surface is limited compared with products offering full scripting APIs
Best for: Fits when engineering teams need deep USB protocol inspection from capture through decoded evidence export.
PulseView
open sourceOpen-source signal analysis software from the sigrok project with protocol decoders including USB.
Descriptor parsing renders a structured descriptor tree that stays connected to captured transfer timestamps.
PulseView pairs a libsigrok workflow with a GUI that focuses on USB bus traffic inspection and timing-aligned views. It decodes descriptor content into a browsable tree and ties captured transfers to enumeration traces, which helps isolate the point where host and device diverge.
PulseView can export USB packet capture output formats that interoperate with common USB analysis tooling. The workflow is oriented around capture session configuration, decode selection, and timestamp correlation rather than a closed device-control system.
- +Descriptor tree view turns enumeration data into navigable structure
- +USB packet capture exports support downstream analysis workflows
- +Filter expressions narrow traffic before heavy decoding
- +Timestamp correlation links transfers across capture views
- –USB host-side driver interception and URB interception are not supported
- –High-speed and SuperSpeed decoding coverage depends on available decoders
Best for: Fits when teams need software-only USB packet capture analysis with decode-first workflows.
Bus Hound
enterpriseCommercial bus analyzer capturing USB, SCSI, SATA, and NVMe I/O traffic for Windows.
Descriptor tree view that ties parsed configuration details to the captured enumeration trace for faster endpoint-level diagnosis.
Bus Hound is a USB analyzer utility focused on capturing host-side USB traffic, mapping devices to topology details, and producing readable inspection views during troubleshooting. It provides descriptor parsing with a descriptor tree view so engineers can trace how interfaces and endpoints are defined.
It also supports export workflows that move captures into Wireshark using USBPcap capture format for deeper packet-level inspection. Compared with lighter analyzers, Bus Hound is geared toward sustained debugging sessions where repeated enumeration trace review and transfer inspection are required.
- +Descriptor tree view shows interface and endpoint relationships clearly
- +Wireshark-compatible export using USBPcap capture format supports advanced analysis
- +Topology-aware device mapping reduces time spent correlating traffic to endpoints
- +Timestamped views help track enumeration trace and subsequent traffic patterns
- –Limited depth for isochronous stream decoding compared with specialized tools
- –USB-C alternate mode analysis needs manual interpretation from raw descriptors
- –USB-C and high-speed behavior coverage can require careful capture setup
- –Automation and scripting options lag behind products with wider API surface
Best for: Fits when engineers need repeatable USB descriptor and traffic inspection with Wireshark export for root-cause work.
PicoScope
SMBOscilloscope and logic analyzer software with built-in USB protocol decoding for low-speed and full-speed USB traffic.
Descriptor tree view tied to the live capture timeline during enumeration and subsequent traffic inspection.
PicoScope provides USB capture and analysis via Pico Technology tooling that focuses on protocol-level inspection alongside waveform-style views. It supports descriptor parsing and VID/PID extraction during enumeration, which helps map bus activity to devices without external converters.
The workflow centers on capture, correlate timestamps, and inspect transfers, including bulk and interrupt style traffic depending on target hardware support. USB packet capture output can be exported for deeper inspection in other analyzers that accept USB capture formats.
- +Enumeration inspection with descriptor parsing and VID/PID extraction
- +Timestamp correlation between captured transactions and inspection views
- +USB packet capture exports for downstream Wireshark USB workflows
- +Transfer inspection that fits device testing and regression runs
- –Capture fidelity depends on supported USB speed and target hardware
- –More analysis depth may require export and external decoding tools
- –Filtering and trace navigation can be slower on long captures
- –Limited automation compared with USB control policy and logging products
Best for: Fits when teams need repeatable USB capture, descriptor inspection, and timestamp correlation for device debugging.
USBPcap
vertical specialistUSBPcap captures USB traffic and exports packets for analysis in compatible capture tools.
Exports USBPcap capture files that Wireshark can dissect using descriptor tree context and USB transfer semantics.
USBPcap focuses on USB packet capture by inserting a host-side capture driver so traffic can be analyzed with standard tooling. It exports captured traffic into a Wireshark-friendly USBPcap capture format with descriptor parsing and protocol dissection for common transfer types.
The workflow is strong for enumeration trace work because it preserves device descriptors, endpoint details, and control exchange context. The main limitation is that USBPcap is capture-oriented rather than a full device control and remediation suite.
- +Wireshark USB dissection with exported PCAP files for repeatable analysis
- +Descriptor parsing supports endpoint enumeration and device identity correlation
- +Filterable capture workflow for isolating transactions by device and endpoint
- +Accurate timestamping suitable for transfer request tracking during debugging
- –Requires a driver-level setup that adds deployment friction
- –Not an in-line endpoint visibility or enforcement tool for device controls
- –Limited in-depth automation and governance compared with enterprise USB control suites
- –Isochronous stream decoding detail can be thinner than specialized analyzers
Best for: Fits when teams need repeatable USB traffic captures in Wireshark for protocol and enumeration debugging.
Conclusion
After evaluating 10 security, Total Phase Data Center Software stands out as our overall top pick — it scored highest across our combined criteria of features, ease of use, and value, which is why it sits at #1 in the rankings above.
Use the comparison table and detailed reviews above to validate the fit against your own requirements before committing to a tool.
How to Choose the Right usb analyzer software
USB analyzer software focuses on turning raw USB activity into navigable evidence for enumeration trace, descriptor parsing, and request-level inspection. This guide covers Total Phase Data Center Software, Device Monitoring Studio, Teledyne LeCroy Voyager, Wireshark, USBTrace, Ellisys USB Explorer, PulseView, Bus Hound, PicoScope, and USBPcap.
These tools are compared by port visibility and capture-to-inspection workflow depth, plus logging detail that helps map identity to transfers. Total Phase Data Center Software leads with a descriptor tree view that keeps endpoint and request context synchronized during trace navigation.
USB analyzer software for descriptor parsing, enumeration tracing, and protocol-level troubleshooting
USB analyzer software captures or imports USB traffic and then parses device descriptors into a descriptor tree view that ties VID and PID identity to configuration and endpoint context. It also correlates control transfers and subsequent transfers using timestamped views and request-level tracking so failing transactions can be mapped to the exact device state.
Total Phase Data Center Software highlights this workflow by keeping device identity, endpoint context, and decoded transactions synchronized in the same navigation surface. Wireshark serves a different role by using USB-capable dissectors to turn captured frames and descriptors into a structured protocol tree that supports repeatable packet forensics from saved pcaps.
USB analyzer software capabilities that decide day-to-day troubleshooting outcomes
These capabilities determine whether a trace can be navigated from identity to transactions without losing context. Total Phase Data Center Software leads this workflow by keeping descriptor tree context synchronized with the trace timeline during review.
The strongest tools also reduce interpretation time by correlating enumeration artifacts with the exact control and data traffic that followed. Ellisys USB Explorer and Teledyne LeCroy Voyager both emphasize request-level or enumeration-level correlation, while Wireshark and USBPcap focus on turning captured evidence into repeatable protocol views.
Synchronized descriptor tree navigation
Total Phase Data Center Software keeps device identity, configuration, and interface context aligned with trace navigation using a descriptor tree view. USBTrace and Bus Hound also provide descriptor tree views, but Total Phase Data Center Software emphasizes tighter correlation during trace navigation rather than export-first workflows.
Request-level correlation from enumeration to transfers
Teledyne LeCroy Voyager ties descriptor parsing to request-level correlation so failing transactions map to the device state. Ellisys USB Explorer uses enumeration trace correlation to link class requests with endpoint enumeration events for faster cause-to-effect mapping.
Capture-to-review workflow for iterative troubleshooting
Device Monitoring Studio supports a capture-to-review workflow that links VID and PID identity to transfer activity over time. PulseView offers a decode-first analysis flow with structured descriptor tree output, but Device Monitoring Studio targets iterative identity-to-activity investigation.
PCAP export for downstream protocol forensics
Wireshark uses USB-capable dissectors to transform captured frames and descriptors into a structured protocol tree suitable for saved pcaps. USBPcap exports USB traffic into USBPcap capture files that Wireshark can dissect with descriptor tree context for repeatable analysis.
Capture dependency and driver setup tolerance
Total Phase Data Center Software and Teledyne LeCroy Voyager both require compatible capture setup and host configuration to achieve repeatable traces. USBPcap and PulseView differ by placing more burden on capture backend drivers or available decoders rather than providing in-line device control or enforced visibility.
Pick the tool that matches the capture shape and the investigation workflow
Start by matching the review workflow to how the team diagnoses failures. A synchronized descriptor tree tied to the trace timeline fits bench debugging where identity and transaction context must stay visible at once, which is where Total Phase Data Center Software is strongest.
Then decide whether the environment needs a decode and navigation engine in one package or a capture-and-export pipeline. Wireshark and USBPcap favor repeatable offline forensics from pcaps, while Ellisys USB Explorer and Voyager prioritize structured decoding and evidence mapping inside the capture review experience.
Choose trace-native navigation when evidence must stay synchronized
If the workflow requires moving through enumeration and then immediately inspecting subsequent transactions, select Total Phase Data Center Software for synchronized descriptor tree and timestamped decode navigation. If enumeration trace linkage is the priority, Ellisys USB Explorer provides an enumeration trace view that correlates descriptor parsing with class requests and endpoint enumeration events.
Choose request-level correlation when failures must map to specific transactions
If the team needs fast mapping from device identity to exact failing transactions, Teledyne LeCroy Voyager’s request-level correlation supports that review style. If the investigation starts with device identity and then requires transfer activity over time, Device Monitoring Studio’s VID and PID surfaced during capture review supports that path.
Choose Wireshark-style protocol tree output when evidence will be shared or replayed
If the organization standardizes on saved pcaps and repeatable packet-level forensics, Wireshark’s USB-capable dissectors provide a protocol tree view with descriptor details. If the requirement includes exporting USB traffic into USBPcap capture files for Wireshark dissection, select USBPcap for that repeatable pipeline.
Choose capture-friendly software-only decode when hardware interception is off-limits
If host-side driver interception and URB interception are not available, PulseView is a software-only USB packet capture analysis option that does not support those interception methods. If the team can rely on host-side captures and needs descriptor driven debugging without full packet dissector overhead, USBTrace can fit that workflow via capture-to-analysis export.
Choose tools based on capture interface compatibility and session repeatability constraints
If repeatability depends on session handling and compatible capture hardware, Total Phase Data Center Software requires careful session handling for repeatable traces. If capture fidelity and supported USB speeds are variable based on target hardware, PicoScope’s descriptor parsing and timestamp correlation depend on the capture fidelity provided by supported USB speed and target hardware.
Who should buy USB analyzer software
USB analyzer software buyers usually need either lab-grade decode navigation or IT-grade visibility workflows anchored to identity. Total Phase Data Center Software fits teams that run repeatable trace decode for enumeration and protocol-level debugging on test benches.
Tools like Wireshark and USBPcap fit teams that store evidence as pcaps and want structured decoding across captures. Device Monitoring Studio fits teams that need VID and PID identity surfaced alongside transfer activity for iterative investigation.
USB test benches and engineering labs running enumeration and class-level debugging
Total Phase Data Center Software supports descriptor tree navigation that keeps interface and request context synchronized during trace navigation, which helps pinpoint enumeration and subsequent transaction failures.
IT and support teams investigating endpoint-level USB identity and activity over time
Device Monitoring Studio exposes VID and PID identity during capture review and uses a capture-to-review workflow to connect identity to transfer activity during troubleshooting sessions.
Engineering teams standardizing on saved pcaps for repeatable packet forensics
Wireshark provides USB-capable dissectors that turn captured frames into a structured protocol tree, while USBPcap exports USB traffic into USBPcap capture files for Wireshark dissection.
Teams needing enumeration evidence tied to decoded class requests
Ellisys USB Explorer uses an enumeration trace view that correlates class requests with endpoint enumeration events for faster evidence-to-cause mapping.
Common USB analyzer software mistakes that waste investigation time
A common failure mode is selecting tooling by descriptor parsing claims without checking capture and driver dependencies. Multiple tools provide descriptor tree views, but capture fidelity and host configuration determine whether the tree reflects the real enumeration and transfer behavior.
Another frequent issue is assuming export-first tooling can replace trace-native context during root-cause work. Wireshark and USBPcap can dissect well, but in-line evidence mapping and synchronized navigation matter when time-to-failure mapping is the goal.
Assuming any tool with descriptor parsing will show request-to-transfer cause and effect
Teledyne LeCroy Voyager and Ellisys USB Explorer emphasize request-level or enumeration trace correlation, while some descriptor tree experiences still depend on capture scope and successful enumeration coverage to provide actionable mapping.
Choosing an export-centric workflow and expecting it to support interactive trace navigation
Wireshark and USBPcap are strong for saved pcaps and repeatable protocol tree output, but USBPcap requires driver-level setup and does not provide in-line endpoint visibility or enforcement of device controls.
Buying without checking capture backend requirements and repeatability constraints
Total Phase Data Center Software and Teledyne LeCroy Voyager both require careful capture setup and host configuration, while PulseView’s decode coverage and USB speed support depend on the available decoders and software-only capture path.
Ignoring UI performance limits on large traces
Wireshark can slow down UI performance on large traces, so relying on filter language to narrow analysis to control transfers and endpoints prevents the review view from becoming unmanageable.
How We Selected and Ranked These Tools
We evaluated USB analyzer software on trace navigation clarity, descriptor navigation synchronization, and evidence mapping speed from device identity to transactions. Features accounted for 40% of the score because tools like Total Phase Data Center Software tie descriptor tree navigation to timestamped decode so endpoint, configuration, and request context stay visible during review.
Ease of use and value each accounted for 30% of the score because teams still need repeatable capture handling without excessive procedural overhead. Total Phase Data Center Software set the benchmark by keeping interface and request context synchronized during trace navigation through its descriptor tree view and timestamped decode correlation.
Frequently Asked Questions About usb analyzer software
How does Total Phase Data Center Software structure traces for USB enumeration debugging?
Which tool best supports mapping VID and PID identity to transfer events over time?
When does Wireshark become a better choice than a vendor analyzer focused on device controls?
What breaks if a USB analyzer records only packet lists without request-level reconstruction?
How does USBTrace connect descriptor parsing results to endpoint enumeration during review?
When should Ellisys USB Explorer be used for class request decoding across control and data traffic?
How do PulseView decode-first workflows change the way USB analysis sessions are configured?
What integration path is used to move captured USB traffic from Bus Hound into Wireshark?
How does USBPcap capture differ from analysis suites that focus on device control or remediation?
How does PicoScope help correlate descriptor inspection to bus activity during enumeration?
Tools reviewed
Primary sources checked during evaluation.
Referenced in the comparison table and product reviews above.
Keep exploring
Comparing two specific tools?
Software Alternatives
See head-to-head software comparisons with feature breakdowns, pricing, and our recommendation for each use case.
Explore software alternatives→In this category
Security alternatives
See side-by-side comparisons of security tools and pick the right one for your stack.
Compare security tools→