Skip to content

PCAP / PCAPng

Definition

The standard file formats for storing captured packets. PCAP (libpcap format) is the legacy standard supported by virtually all tools. PCAPng (Next Generation) extends it with per-interface metadata, nanosecond timestamps, and the ability to store captures from multiple interfaces in a single file. Wireshark and tshark write PCAPng by default; tcpdump writes legacy PCAP.

Legacy format
PCAP (libpcap), supported by virtually all tools
Newer format
PCAPng, per-interface metadata, nanosecond timestamps, multi-interface support
Default writers
Wireshark and tshark write PCAPng; tcpdump writes legacy PCAP

Common questions

Why would an analyst prefer PCAPng over legacy PCAP for a multi-interface capture?+

PCAPng can store captures from several network interfaces in a single file with per-interface metadata, so traffic from different vantage points stays organised and timestamped consistently, something legacy PCAP cannot represent in one file.

Does a tool that only reads legacy PCAP lose data from a PCAPng file?+

It typically cannot open a PCAPng file at all, or it ignores the extended blocks such as name resolution and per-packet comments if a compatibility layer allows partial reading, so format mismatches can silently strip context an analyst was relying on.

Related terms

BPF (Berkeley Packet Filter)
A kernel-level packet filtering mechanism used by tcpdump, Wireshark, and most capture tools to select which packets are written to disk. BPF...
Network Tap
A hardware device inserted inline in a network cable path that passively copies the electrical or optical signal to one or more...
Promiscuous Mode
A network interface operating mode in which the card passes all received frames to the capture software, not just frames addressed to...
Ring Buffer Capture
A capture mode in which the tool writes successive PCAP files of a fixed size or duration, overwriting the oldest when the...
SPAN Port (Port Mirroring)
A switch feature that copies frames from one or more source ports or VLANs to a designated destination port, where a capture...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.