PCAP File
Definition
A packet capture file storing raw network frames in the libpcap format. PCAP files are the standard exchange format between network forensic tools. Wireshark, NetworkMiner, Zeek, and most other network analysis platforms can read PCAP files as input.
- Format
- libpcap
- Role
- Standard exchange format between network forensic tools
- Compatible tools
- Wireshark, NetworkMiner, Zeek and most network analysis platforms
Common questions
Why does interoperability between tools matter for a PCAP file in an investigation?+
An investigator can capture traffic with one tool and hand the same file to a colleague running a different analysis platform without conversion, which supports independent verification of findings and lets different tools be used for different parts of the same analysis.
Does opening a PCAP file in a different tool change the underlying evidence?+
No, reading a PCAP file is non-destructive; the tool parses the stored bytes without altering them. Chain-of-custody concerns instead centre on how the file was captured, transferred and hashed, not on which viewer opened it.
Related terms
- Device Profile
- A vendor-maintained database entry describing how to communicate with a specific make, model, and firmware version of a mobile device. The profile...
- Logical Extraction
- NIST SP 800-101 R1 Level 2 acquisition. Uses the OS-exposed backup APIs (Android ADB backup, iOS iTunes/Finder backup, MTP for media) to...
- NIST CFTT
- The National Institute of Standards and Technology Computer Forensics Tool Testing programme. It publishes independent test reports for digital forensic tools, including...
- Physical Extraction
- An acquisition method that reads the raw storage medium, producing a bit-for-bit image from which allocated and deleted data can both be...
- Zeek (Formerly Bro)
- An open-source network analysis framework that processes live traffic or PCAP files and produces structured per-session log files covering DNS, HTTP, SSL,...