PCAP (Packet Capture)
Definition
A file format (and the process of creating it) that records every byte of every network packet passing a capture point, including headers and payload. Provides the most complete possible network evidence but generates large volumes of data and raises interception-law considerations in many jurisdictions.
- Captures
- Every byte of every packet at the capture point, headers and payload
- Evidentiary value
- Most complete network evidence available
- Volume
- Generates large data volumes
- Legal concern
- May trigger interception-law requirements in many jurisdictions
Common questions
Why does full packet capture raise legal issues that flow-level logging does not?+
Recording full payload content, not just metadata like source, destination and volume, can fall within wiretap or interception statutes in many jurisdictions, which typically require prior authorisation such as a warrant or statutory exception before payload is captured or reviewed.
What is the practical downside of always running full packet capture?+
Full capture generates data volumes that grow quickly on busy links, creating storage and retention costs, so many organisations capture full packets only for targeted investigations or short retention windows and rely on flow logs the rest of the time.
Related terms
- DHCP Lease Log
- A record maintained by a Dynamic Host Configuration Protocol server that maps each IP address assignment to the requesting device's MAC address,...
- Intrusion Detection System (IDS)
- A network or host-based monitoring system that analyses traffic or system behaviour against a rule set (signature-based) or a statistical baseline (anomaly-based)...
- NetFlow
- A network protocol (originally Cisco, now standardised as IPFIX under RFC 7011) that records metadata about IP traffic flows: source and destination...
- RADIUS Log
- An authentication, authorisation, and accounting record produced by a Remote Authentication Dial-In User Service server. Each entry records the username, authenticating device...
- Syslog
- A standardised protocol (RFC 5424) for transmitting log messages from network devices to a centralised log server. Routers, switches, firewalls, and servers...