Skip to content

Packet Capture (PCAP)

Definition

The interception and recording of network packets as they traverse an interface. The raw data is stored in PCAP format and analysed with tools such as Wireshark or tcpdump. PCAP files contain headers (source/destination IP, port, protocol) and, where traffic is unencrypted, payload content.

Common tools
Wireshark, tcpdump, tshark
Format
libpcap or PCAPNG binary format
Captures
Headers plus payload if unencrypted
Layer
Network interface, below the application layer
Limitation
Encrypted payloads reveal metadata only

Common questions

Can PCAP data be captured without alerting the person being monitored?+

Yes, packet capture is typically passive and does not alter traffic, so it leaves no trace on the monitored device itself. Detection would require noticing the tap point, a mirrored switch port, or a device physically inline on the network.

Why is PCAP evidence often less useful on modern web traffic?+

Most web and app traffic today is encrypted with TLS, so a capture shows connection metadata such as source, destination, port, and timing, but not the message content. Investigators then rely on endpoint logs, DNS records, or certificate details rather than payload inspection.

How is PCAP integrity preserved for court use?+

Analysts hash the capture file immediately after collection and preserve it read-only, then work from a copy. Chain of custody documentation records who captured the traffic, when, and with what tool and interface settings.

Related terms

Chain of Custody
The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
Logical Acquisition
An extraction method that uses the device's own operating system interfaces, such as iTunes backup or Android Debug Bridge, to export the...
Physical Acquisition
An extraction method that reads the raw flash storage of a mobile device, bypassing the operating system. Produces a bit-for-bit image of...
Beaconing
Periodic outbound connections from a compromised host to a command-and-control server, typically at regular intervals. The regularity of the interval, measured in...
Cell Site Analysis
The use of records from mobile network operators showing which cell towers a device connected to and when, allowing investigators to establish...
DNS Tunnelling
Encoding data inside DNS queries and responses to exfiltrate information or carry command-and-control traffic through a network that permits DNS but blocks...
Faraday Isolation
Shielding a mobile device from radio frequency signals (cellular, Wi-Fi, Bluetooth, GPS) using a Faraday bag or cage, preventing network connections that...
IMEI (International Mobile Equipment Identity)
A unique 15-digit number permanently assigned to a mobile device's hardware. Used by networks to identify and block stolen devices, and by...
Network Flow (NetFlow/IPFIX)
A summary record of a network conversation, storing source IP, destination IP, source port, destination port, protocol, byte count, and timestamps, without...
Port Number
A 16-bit integer in the TCP or UDP header that identifies the application-layer service at each endpoint. Well-known ports are assigned by...
TCP Three-Way Handshake
The connection establishment sequence in TCP: the client sends SYN, the server responds SYN-ACK, and the client completes with ACK. The timestamps...
Write Blocker
A hardware or software device interposed between a digital storage medium and the forensic workstation that prevents any write commands from reaching...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.