PCAP
Definition
Packet capture file. The standard format for storing captured network frames, originally defined by the libpcap library. Each record contains the raw frame bytes, a timestamp, and the captured length. The newer pcapng format extends this with interface metadata and block annotations.
- Full name
- Packet capture
- Origin
- libpcap library format
- Record contents
- Raw frame bytes, timestamp, captured length
- Newer variant
- PCAPng, adds interface metadata and block annotations
Common questions
Why does a PCAP record store a captured length separate from the frame bytes?+
Captures are sometimes taken with a snap length limit that truncates each frame to save space, so the captured length field tells analysis tools how many bytes of the frame were actually saved, distinct from the frame's original on-wire length.
Is a PCAP file evidence of the full conversation or just what passed the capture point?+
Only what passed the capture point. Traffic on other network segments, encrypted payloads, or packets dropped before reaching the sensor never appear in the file, so a PCAP represents one vantage point, not the entire communication.
Related terms
- Artefact Carving
- Extracting embedded content from raw data by locating known file signatures (magic bytes) at byte boundaries. In PCAP analysis, this means reassembling...
- Beaconing
- Periodic outbound connections from a compromised host to a command-and-control server, typically at regular intervals. The regularity of the interval, measured in...
- Display Filter
- A Wireshark filter expression applied to an already-captured PCAP file to show only packets matching specified criteria. Display filters do not delete...
- Protocol Dissector
- A software component in a packet analyser that recognises a specific protocol and parses its header fields into named, readable values. Wireshark...
- Stream Reassembly
- The process of collecting all the TCP segments belonging to a single connection and reordering them by sequence number to reconstruct the...