Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Pcap</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Pcap"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Pcap rootpage-Pcap skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main">pcap</span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1236090951">
/* start https://en.wikipedia.org/ */


.mw-parser-output .hatnote{font-style:italic}.mw-parser-output div.hatnote{padding-left:1.6em;margin-bottom:0.5em}.mw-parser-output .hatnote i{font-style:normal}.mw-parser-output .hatnote+link+.hatnote{margin-top:-0.5em}@media print{body.ns-0 .mw-parser-output .hatnote{display:none!important}}


/* end https://en.wikipedia.org/ */
</style><div role="note" class="hatnote navigation-not-searchable">This article is about the packet sniffing API. For the projected capacitance technology for touchscreens, see <a href="Projected_capacitance" class="mw-redirect" title="Projected capacitance">Projected capacitance</a>. For the chess league, see <a href="Professional_Chess_Association_of_the_Philippines" title="Professional Chess Association of the Philippines">Professional Chess Association of the Philippines</a>.</div>
<style data-mw-deduplicate="TemplateStyles:r1295905060">
/* start https://en.wikipedia.org/ */


.mw-parser-output .infobox-subbox{padding:0;border:none;margin:-3px;width:auto;min-width:100%;font-size:100%;clear:none;float:none;background-color:transparent}.mw-parser-output .infobox-3cols-child{margin:auto}.mw-parser-output .infobox .navbar{font-size:100%}@media screen{html.skin-theme-clientpref-night .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .infobox-full-data:not(.notheme)>div:not(.notheme)[style]{background:#1f1f23!important;color:#f8f9fa}}@media(min-width:640px){body.skin--responsive .mw-parser-output .infobox-table{display:table!important}body.skin--responsive .mw-parser-output .infobox-table>caption{display:table-caption!important}body.skin--responsive .mw-parser-output .infobox-table>tbody{display:table-row-group}body.skin--responsive .mw-parser-output .infobox-table th,body.skin--responsive .mw-parser-output .infobox-table td{padding-left:inherit;padding-right:inherit}}


/* end https://en.wikipedia.org/ */
</style><table class="infobox vevent"><tbody><tr><th colspan="2" class="infobox-above summary">libpcap</th></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Programmer" title="Programmer">Developer(s)</a></th><td class="infobox-data">The Tcpdump team</td></tr><tr style="display: none;"><td colspan="2" class="infobox-full-data"></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_release_life_cycle" title="Software release life cycle">Stable release</a></th><td class="infobox-data"><div style="margin:0px;">1.10.4
/ April&nbsp;7, 2023<span style="display:none">&nbsp;(<span class="bday dtstart published updated">2023-04-07</span>)</span><sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup></div></td></tr><tr style="display:none"><td colspan="2">
</td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Repository_(version_control)" title="Repository (version control)">Repository</a></th><td class="infobox-data"><a rel="nofollow" class="external text" href="https://github.com/the-tcpdump-group/libpcap">libpcap</a> on <a href="GitHub" title="GitHub">GitHub</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;">Written in</th><td class="infobox-data"><a href="C_(programming_language)" title="C (programming language)">C</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Operating_system" title="Operating system">Operating system</a></th><td class="infobox-data"><a href="Linux" title="Linux">Linux</a>, <a href="Solaris_(operating_system)" class="mw-redirect" title="Solaris (operating system)">Solaris</a>, <a href="FreeBSD" title="FreeBSD">FreeBSD</a>, <a href="NetBSD" title="NetBSD">NetBSD</a>, <a href="OpenBSD" title="OpenBSD">OpenBSD</a>, <a href="MacOS" title="MacOS">macOS</a>, other <a href="Unix-like" title="Unix-like">Unix-like</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_categories#Categorization_approaches" title="Software categories">Type</a></th><td class="infobox-data"><a href="Library_(computing)" title="Library (computing)">Library</a> for <a href="Packet_capture" class="mw-redirect" title="Packet capture">packet capture</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_license" title="Software license">License</a></th><td class="infobox-data"><a href="BSD_licenses" title="BSD licenses">BSD</a><sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;">Website</th><td class="infobox-data"><span class="url"><a rel="nofollow" class="external text" href="http://www.tcpdump.org">www<wbr>.tcpdump<wbr>.org</a></span></td></tr></tbody></table>
<table class="infobox vevent"><tbody><tr><th colspan="2" class="infobox-above summary">WinPcap</th></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Programmer" title="Programmer">Developer(s)</a></th><td class="infobox-data"><a href="Riverbed_Technology" title="Riverbed Technology">Riverbed Technology</a></td></tr><tr style="display: none;"><td colspan="2" class="infobox-full-data"></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_release_life_cycle" title="Software release life cycle">Final release</a></th><td class="infobox-data"><div style="margin:0px;">4.1.3
/ March&nbsp;8, 2013<span style="display:none">&nbsp;(<span class="bday dtstart published updated">2013-03-08</span>)</span><sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup></div></td></tr><tr style="display:none"><td colspan="2">
</td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Operating_system" title="Operating system">Operating system</a></th><td class="infobox-data"><a href="Microsoft_Windows" title="Microsoft Windows">Windows</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_categories#Categorization_approaches" title="Software categories">Type</a></th><td class="infobox-data"><a href="Library_(computing)" title="Library (computing)">Library</a> for <a href="Packet_capture" class="mw-redirect" title="Packet capture">packet capture</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_license" title="Software license">License</a></th><td class="infobox-data"><a href="Freeware" title="Freeware">Freeware</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;">Website</th><td class="infobox-data"><span class="url"><a rel="nofollow" class="external text" href="https://www.winpcap.org/">www<wbr>.winpcap<wbr>.org</a></span></td></tr></tbody></table>
<table class="infobox vevent"><tbody><tr><th colspan="2" class="infobox-above summary">Npcap</th></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Programmer" title="Programmer">Developer(s)</a></th><td class="infobox-data">the <a href="Nmap" title="Nmap">Nmap</a> project</td></tr><tr style="display: none;"><td colspan="2" class="infobox-full-data"></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_release_life_cycle" title="Software release life cycle">Stable release</a></th><td class="infobox-data"><div style="margin:0px;">1.79
/ January&nbsp;19, 2024<span style="display:none">&nbsp;(<span class="bday dtstart published updated">2024-01-19</span>)</span><sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup></div></td></tr><tr style="display:none"><td colspan="2">
</td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Operating_system" title="Operating system">Operating system</a></th><td class="infobox-data"><a href="Microsoft_Windows" title="Microsoft Windows">Windows</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_categories#Categorization_approaches" title="Software categories">Type</a></th><td class="infobox-data"><a href="Library_(computing)" title="Library (computing)">Library</a> for <a href="Packet_capture" class="mw-redirect" title="Packet capture">packet capture</a></td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;"><a href="Software_license" title="Software license">License</a></th><td class="infobox-data"><a href="Proprietary_software" title="Proprietary software">Proprietary</a> (<a href="Source-available_software" title="Source-available software">source available</a>)</td></tr><tr><th scope="row" class="infobox-label" style="white-space: nowrap;">Website</th><td class="infobox-data"><span class="url"><a rel="nofollow" class="external text" href="https://npcap.com">npcap<wbr>.com</a></span></td></tr></tbody></table>
<p>In the field of <a href="Computer" title="Computer">computer</a> <a href="Network_administration" class="mw-redirect" title="Network administration">network administration</a>, <b>pcap</b> is an <a href="Application_programming_interface" class="mw-redirect" title="Application programming interface">application programming interface</a> (API) for <a href="Packet_sniffer" class="mw-redirect" title="Packet sniffer">capturing network traffic</a>. While the name is an abbreviation of <i><a href="Packet_capture" class="mw-redirect" title="Packet capture">packet capture</a></i>, that is not the API's proper name. <a href="Unix-like" title="Unix-like">Unix-like</a> systems implement pcap in the <i>libpcap</i> library; for <a href="Microsoft_Windows" title="Microsoft Windows">Windows</a>, there is a <a href="Porting" title="Porting">port</a> of libpcap named <i>WinPcap</i> that is no longer supported or developed, and a port named <i>Npcap</i> for <a href="Windows_7" title="Windows 7">Windows 7</a> and later that is still supported.
</p><p>Monitoring software may use libpcap, WinPcap, or Npcap to capture <a href="Network_packet" title="Network packet">network packets</a> traveling over a <a href="Computer_network" title="Computer network">computer network</a> and, in newer versions, to transmit packets on a network at the <a href="Link_layer" title="Link layer">link layer</a>, and to get a list of network interfaces for possible use with libpcap, WinPcap, or Npcap.
</p><p>The pcap API is written in <a href="C_(programming_language)" title="C (programming language)">C</a>, so other languages such as <a href="Java_(programming_language)" title="Java (programming language)">Java</a>, <a href=".NET_Framework" title=".NET Framework">.NET</a> languages, and <a href="Scripting_language" title="Scripting language">scripting languages</a> generally use a <a href="Wrapper_library" title="Wrapper library">wrapper</a>; no such wrappers are provided by libpcap or WinPcap itself. <a href="C%2B%2B" title="C++">C++</a> programs may link directly to the C API or make use of an <a href="Object-oriented_programming" title="Object-oriented programming">object-oriented</a> wrapper.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Features">Features</h2></div>
<p>libpcap, WinPcap, and Npcap provide the packet-capture and filtering engines of many <a href="Open-source_software" title="Open-source software">open-source</a> and commercial network tools, including protocol analyzers (<a href="Packet_sniffer" class="mw-redirect" title="Packet sniffer">packet sniffers</a>), <a href="Network_monitor" class="mw-redirect" title="Network monitor">network monitors</a>, <a href="Network_intrusion_detection_system" class="mw-redirect" title="Network intrusion detection system">network intrusion detection systems</a>, traffic-generators and network-testers.
</p><p>Most current <a href="Unix-like" title="Unix-like">Unix-like</a> systems provide a mechanism by which a program can capture network traffic to and from the machine running the program and, in some cases, other traffic to which that machine is attached. However, these mechanisms are significantly different from one another; the libpcap library provides a common API to access these mechanisms, allowing programs to be written to capture network traffic without having to worry about the details of all those mechanisms.
</p><p>libpcap, WinPcap, and Npcap also support saving captured <a href="Network_packet" title="Network packet">packets</a> to a file, and reading files containing saved packets; <a href="Application_software" title="Application software">applications</a> can be written, using libpcap, WinPcap, or Npcap, to be able to capture network traffic and analyze it, or to read a saved capture and analyze it, using the same analysis code. A capture file saved in the format that libpcap, WinPcap, and Npcap use can be read by applications that understand that format, such as <a href="Tcpdump" title="Tcpdump">tcpdump</a>, <a href="Wireshark" title="Wireshark">Wireshark</a>, CA NetMaster, or <a href="Microsoft_Network_Monitor" title="Microsoft Network Monitor">Microsoft Network Monitor</a> 3.x. The file format is described by <a href="Internet-Draft" class="mw-redirect" title="Internet-Draft">Internet-Draft</a> draft-ietf-opsawg-pcap;<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> the current editors' version of the draft is also available.<sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>
</p><p>The <a href="MIME_type" class="mw-redirect" title="MIME type">MIME type</a> for the file format created and read by libpcap, WinPcap, and Npcap is application/vnd.tcpdump.pcap. The typical file extension is .pcap, although .cap and .dmp are also in common use.<sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="History">History</h2></div>
<p>libpcap was originally developed by the <a href="Tcpdump" title="Tcpdump">tcpdump</a> developers in the Network Research Group at <a href="Lawrence_Berkeley_Laboratory" class="mw-redirect" title="Lawrence Berkeley Laboratory">Lawrence Berkeley Laboratory</a>. The low-level packet capture, capture file reading, and capture file writing code of tcpdump was extracted and made into a library, with which tcpdump was linked.<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> It is now developed by the same tcpdump.org group that develops tcpdump.<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="pcap_libraries_for_Windows">pcap libraries for Windows</h2></div>
<p>While libpcap was originally developed for Unix-like operating systems, a successful <a href="Porting" title="Porting">port</a> for Windows was made, called WinPcap. It has been unmaintained since 2013,<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> and several competing <a href="Fork_(software_development)" title="Fork (software development)">forks</a> have been released with new features and support for newer versions of Windows.
</p>
<div class="mw-heading mw-heading3"><h3 id="WinPcap">WinPcap</h3></div>
<p>WinPcap consists of:<sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>
</p>
<ul><li><a href="X86" title="X86">x86</a> and <a href="X86-64" title="X86-64">x86-64</a> drivers for the <a href="Windows_NT" title="Windows NT">Windows NT</a> family (<a href="Windows_NT_4.0" title="Windows NT 4.0">Windows NT 4.0</a>, <a href="Windows_2000" title="Windows 2000">2000</a>, <a href="Windows_XP" title="Windows XP">XP</a>, <a href="Windows_Server_2003" title="Windows Server 2003">Server 2003</a>, <a href="Windows_Vista" title="Windows Vista">Vista</a>, <a href="Windows_7" title="Windows 7">7</a>, <a href="Windows_8" title="Windows 8">8</a>, and <a href="Windows_10" title="Windows 10">10</a>), which use <a href="Network_Driver_Interface_Specification" title="Network Driver Interface Specification">Network Driver Interface Specification</a> (NDIS) 5.x to read packets directly from a <a href="Network_adapter" class="mw-redirect" title="Network adapter">network adapter</a>;</li>
<li>implementations of a lower-level library for the listed operating systems, to communicate with those drivers;</li>
<li>a port of libpcap that uses the API offered by the low-level library implementations.</li></ul>
<p>Programmers at the <a href="Politecnico_di_Torino" class="mw-redirect" title="Politecnico di Torino">Politecnico di Torino</a> wrote the original code. As of 2008, CACE Technologies, a company set up by some of the WinPcap developers, developed and maintained the product. CACE was acquired by <a href="Riverbed_Technology" title="Riverbed Technology">Riverbed Technology</a> on October 21, 2010.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>
</p><p>Because WinPcap uses the older NDIS 5.x APIs, it does not work on some builds of Windows 10, which have deprecated or removed those APIs in favor of the newer NDIS 6.x APIs. It also forces some limitations such as being unable to capture <a href="IEEE_802.1Q" title="IEEE 802.1Q">802.1Q VLAN tags</a> in <a href="Ethernet" title="Ethernet">Ethernet</a> headers.
</p><p>The WinPcap project has ceased development and WinPcap and WinDump are no longer maintained. The last official WinPcap release was 4.1.3 released March 8, 2013.<sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Npcap">Npcap</h3></div>
<p>Npcap is the <a href="Nmap" title="Nmap">Nmap</a> Project's packet sniffing library for Windows.<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup> It is based on WinPcap, but written to make use of Windows networking improvements in <a href="Network_Driver_Interface_Specification" title="Network Driver Interface Specification">NDIS</a> version 6. Its authors rewrote the WinPcap NDIS 5 Protocol Driver as a Light-Weight Filter (LWF) driver, a change that reduces processing overhead.<sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup>
Npcap maintenance releases updated the version of the included libpcap library to the latest available, allowing software authors to use the newer API features that Linux software had already supported.<sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup> Most software that used WinPcap can be easily <a href="Porting" title="Porting">ported</a> to use Npcap with minimal changes.<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup>
</p><p>Npcap introduced several innovations that were not available in WinPcap:
</p>
<ul><li>Npcap can be restricted so that only <a href="Superuser#Microsoft_Windows" title="Superuser">Administrators</a> can sniff packets.<sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup></li>
<li>Npcap is able to sniff and inject <a href="Localhost#Loopback" title="Localhost">loopback</a> packets (transmissions between services on the same machine) by using the <a href="Windows_Filtering_Platform" title="Windows Filtering Platform">Windows Filtering Platform</a>.<sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup></li>
<li>Npcap can capture <a href="IEEE_802.11" title="IEEE 802.11">802.11</a> WiFi frames on a variety of commonly-available network adapters.<sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup></li></ul>
<p>Unlike <a href="Nmap" title="Nmap">Nmap</a>, Npcap is proprietary software and requires a special license for use and redistribution except for some limited internal uses.<sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Win10Pcap">Win10Pcap</h3></div>
<p>Win10Pcap implementation is also based on the NDIS 6 driver model and works stably with <a href="Windows_10" title="Windows 10">Windows 10</a>.<sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup> The project, however, has been inactive since 2016.<sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Programs_that_use_or_used_libpcap">Programs that use or used libpcap</h2></div>
<ul><li><a href="Bit-Twist" title="Bit-Twist">Bit-Twist</a>, a libpcap-based Ethernet packet generator and editor for <a href="Berkeley_Software_Distribution" title="Berkeley Software Distribution">BSD</a>, Linux, and Windows.</li>
<li><a href="Cain_and_Abel_(software)" title="Cain and Abel (software)">Cain and Abel</a>, a discontinued password recovery tool for Microsoft Windows</li>
<li><a href="EtherApe" title="EtherApe">EtherApe</a>, a graphical tool for monitoring network traffic and bandwidth usage in real time.</li>
<li><a href="Firesheep" title="Firesheep">Firesheep</a>, a discontinued extension for the <a href="Firefox" title="Firefox">Firefox</a> web browser that captured packets and performed <a href="Session_hijacking" title="Session hijacking">session hijacking</a></li>
<li><a href="Iftop" title="Iftop">iftop</a>, a tool for displaying bandwidth usage (like <a href="Top_(software)" title="Top (software)">top</a> for network traffic)</li>
<li><a href="Kismet_(software)" title="Kismet (software)">Kismet</a>, for 802.11 wireless <a href="Local_area_network" title="Local area network">LANs</a></li>
<li><a href="L0phtCrack" title="L0phtCrack">L0phtCrack</a>, a <a href="Password" title="Password">password</a> <a href="Audit" title="Audit">auditing</a> and <a href="Password_cracking" title="Password cracking">recovery</a> application.</li>
<li><a href="McAfee" title="McAfee">McAfee</a> ePolicy Orchestrator, Rogue System Detection feature</li>
<li><a href="Ngrep" title="Ngrep">ngrep</a>, aka "network <a href="Grep" title="Grep">grep</a>", isolate strings in packets, show packet data in human-friendly output.</li>
<li><a href="Nmap" title="Nmap">Nmap</a>, a <a href="Port_scan" class="mw-redirect" title="Port scan">port-scanning</a> and <a href="TCP/IP_stack_fingerprinting" title="TCP/IP stack fingerprinting">fingerprinting</a> network utility</li>
<li>Pirni, a discontinued network security tool for <a href="IOS_jailbreaking" title="IOS jailbreaking">jailbroken</a> <a href="IOS_(Apple)" class="mw-redirect" title="IOS (Apple)">iOS</a> devices.</li>
<li><a href="Scapy" title="Scapy">Scapy</a>, a packet manipulation tool for computer networks, written in <a href="Python_(programming_language)" title="Python (programming language)">Python</a> by Philippe Biondi.</li>
<li><a href="Snort_(software)" title="Snort (software)">Snort</a>, a network-intrusion-detection system.</li>
<li><a href="Suricata_(software)" title="Suricata (software)">Suricata</a>, a network intrusion prevention and analysis platform.</li>
<li><a href="NortonLifeLock" class="mw-redirect" title="NortonLifeLock">Symantec</a> Data Loss Prevention, Used to monitor and identify sensitive data, track its use, and location. Data loss policies allow sensitive data to be blocked from leaving the network or copied to another device.</li>
<li><a href="Tcpdump" title="Tcpdump">tcpdump</a>, a tool for capturing and dumping packets for further analysis, and WinDump, the Windows port of tcpdump.</li>
<li><a href="Zeek" title="Zeek">Zeek</a>, an <a href="Intrusion_detection_system" title="Intrusion detection system">intrusion detection system</a> and <a href="Network_monitoring" title="Network monitoring">network monitoring</a> platform.</li>
<li><a rel="nofollow" class="external text" href="https://www.techopedia.com/definition/26915/url-snooping">URL Snooper</a>, locate the URLs of audio and video files in order to allow recording them.</li>
<li><a href="WhatPulse" title="WhatPulse">WhatPulse</a>, a statistical (input, network, uptime) measuring application.</li>
<li><a href="Wireshark" title="Wireshark">Wireshark</a> (formerly Ethereal), a graphical packet-capture and protocol-analysis tool.</li>
<li><a href="XLink_Kai" title="XLink Kai">XLink Kai</a>, software that allows various LAN <a href="Console_game" class="mw-redirect" title="Console game">console games</a> to be played online</li>
<li><a href="Xplico" title="Xplico">Xplico</a>, a network forensics analysis tool (NFAT).</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Wrapper_libraries_for_libpcap">Wrapper libraries for libpcap</h2></div>
<ul><li><a href="C%2B%2B" title="C++">C++</a>: <a rel="nofollow" class="external text" href="https://libtins.github.io/">Libtins</a>, <a rel="nofollow" class="external text" href="https://github.com/pellegre/libcrafter">Libcrafter</a>, <a rel="nofollow" class="external text" href="https://pcapplusplus.github.io/">PcapPlusPlus</a></li>
<li><a href="Perl" title="Perl">Perl</a>: <a rel="nofollow" class="external text" href="https://search.cpan.org/~saper/Net-Pcap/Pcap.pm">Net::Pcap</a></li>
<li><a href="Python_(programming_language)" title="Python (programming language)">Python</a>: <a rel="nofollow" class="external text" href="http://sourceforge.net/projects/pylibpcap/">python-libpcap</a>, <a rel="nofollow" class="external text" href="https://www.coresecurity.com/corelabs-research/open-source-tools/pcapy">Pcapy</a>, <a rel="nofollow" class="external text" href="https://github.com/orweis/winpcapy">WinPcapy</a></li>
<li><a href="Ruby_(programming_language)" title="Ruby (programming language)">Ruby</a>: <a rel="nofollow" class="external text" href="https://github.com/packetfu/packetfu">PacketFu</a></li>
<li><a href="Rust_(programming_language)" title="Rust (programming language)">Rust</a>: <a rel="nofollow" class="external text" href="https://github.com/ebfull/pcap">pcap</a></li>
<li><a href="Tcl" title="Tcl">Tcl</a>: <a rel="nofollow" class="external text" href="http://tclpcap.sourceforge.net/">tclpcap</a>, <a rel="nofollow" class="external text" href="https://monkey.org/~jose/software/tcap/">tcap</a>, <a rel="nofollow" class="external text" href="http://home.roadrunner.com/~maccody/pktsrc.html">pktsrc</a></li>
<li><a href="Java_(programming_language)" title="Java (programming language)">Java</a>: <a rel="nofollow" class="external text" href="https://jpcap.sourceforge.net/">jpcap</a>, <a rel="nofollow" class="external text" href="https://web.archive.org/web/20121104024808/http://jnetpcap.com/">jNetPcap</a>, <a rel="nofollow" class="external text" href="https://archive.today/20101017042631/http://netresearch.ics.uci.edu/kfujii/Jpcap/doc/index.html">Jpcap</a>, <a rel="nofollow" class="external text" href="https://github.com/kaitoy/pcap4j">Pcap4j</a>, <a rel="nofollow" class="external text" href="https://github.com/jxnet/Jxnet">Jxnet</a></li>
<li><a href=".NET_Framework" title=".NET Framework">.NET</a>: WinPcapNET, <a rel="nofollow" class="external text" href="https://github.com/chmorgan/sharppcap">SharpPcap</a>, <a rel="nofollow" class="external text" href="http://pcapdot.net">Pcap.Net</a></li>
<li><a href="Haskell_(programming_language)" class="mw-redirect" title="Haskell (programming language)">Haskell</a>: <a rel="nofollow" class="external text" href="https://hackage.haskell.org/package/pcap">pcap</a></li>
<li><a href="OCaml" title="OCaml">OCaml</a>: <a rel="nofollow" class="external text" href="https://web.archive.org/web/20110830000918/http://www.drugphish.ch/~jonny/mlpcap.html">mlpcap</a></li>
<li><a href="Chicken_(Scheme_implementation)" title="Chicken (Scheme implementation)">Chicken</a> Scheme: <a rel="nofollow" class="external text" href="https://wiki.call-cc.org/eggref/3/pcap">pcap</a></li>
<li><a href="Common_Lisp" title="Common Lisp">Common Lisp</a>: <a rel="nofollow" class="external text" href="https://github.com/atomontage/plokami">PLOKAMI</a></li>
<li><a href="Racket_(programming_language)" title="Racket (programming language)">Racket</a>: <a rel="nofollow" class="external text" href="http://planet.racket-lang.org/display.ss?package=SPeaCAP.plt&amp;owner=evanfarrer">SPeaCAP</a></li>
<li><a href="Go_(programming_language)" title="Go (programming language)">Go</a>: <a rel="nofollow" class="external text" href="https://github.com/akrennmair/gopcap">pcap</a> by Andreas Krennmair, <a rel="nofollow" class="external text" href="https://godoc.org/github.com/miekg/pcap">pcap</a> fork of the previous by Miek Gieben, <a rel="nofollow" class="external text" href="http://godoc.org/code.google.com/p/gopacket/pcap">pcap</a> developed as part of the <a rel="nofollow" class="external text" href="https://pkg.go.dev/github.com/google/gopacket">gopacket</a> package</li>
<li><a href="Erlang_(programming_language)" title="Erlang (programming language)">Erlang</a>: <a rel="nofollow" class="external text" href="https://github.com/msantos/epcap">epcap</a></li>
<li><a href="Node.js" title="Node.js">Node.js</a>: <a rel="nofollow" class="external text" href="https://github.com/node-pcap/node_pcap">node_pcap</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="Non-pcap_libraries_that_read_pcap_files">Non-pcap libraries that read pcap files</h2></div>
<ul><li><a href="Python_(programming_language)" title="Python (programming language)">Python</a>: <a rel="nofollow" class="external text" href="https://pypi.python.org/pypi/pypcapfile">pycapfile</a></li>
<li><a href="Python_(programming_language)" title="Python (programming language)">Python</a>: <a rel="nofollow" class="external text" href="https://pypi.python.org/pypi/pypcapkit">PyPCAPKit</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="Other_applications_or_devices_that_read_or_write_pcap_or_pcapng_files">Other applications or devices that read or write pcap or pcapng files</h2></div>
<ul><li><a href="Apache_Drill" title="Apache Drill">Apache Drill</a>, an open source SQL engine for interactive analysis of large scale datasets.<sup id="cite_ref-24" class="reference"><a href="#cite_note-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-25" class="reference"><a href="#cite_note-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup></li>
<li><a href="Endace" title="Endace">Endace</a>'s EndaceProbe, a high scale packet capture system that continuously records weeks or months of network traffic.<sup id="cite_ref-26" class="reference"><a href="#cite_note-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */


.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}


/* end https://en.wikipedia.org/ */
</style><div class="reflist reflist-columns references-column-width" style="column-width: 30em;">
<ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */


.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}


/* end https://en.wikipedia.org/ */
</style><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.tcpdump.org/#latest-release">"tcpdump and libpcap latest release"</a>. tcpdump.org<span class="reference-accessdate">. Retrieved <span class="nowrap">2023-02-08</span></span>.</cite></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.tcpdump.org/license.html">"tcpdump and libpcap license"</a>. tcpdump.org<span class="reference-accessdate">. Retrieved <span class="nowrap">2020-05-02</span></span>.</cite></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.winpcap.org/misc/changelog.htm">"WinPcap Changelog"</a>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/nmap/npcap/blob/master/CHANGELOG.md">"npcap/CHANGELOG.md"</a>. <i><a href="GitHub" title="GitHub">GitHub</a></i>.</cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/draft-ietf-opsawg-pcap"><i>PCAP Capture File Format</i></a>. 23 July 2023. I-D draft-ietf-opsawg-pcap.</cite></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-6">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://ietf-opsawg-wg.github.io/draft-ietf-opsawg-pcap/draft-ietf-opsawg-pcap.html">"PCAP Capture File Format"</a>. 1 March 2024.</cite></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-7">^</a></b></span> <span class="reference-text"><cite id="CITEREFTurner2011" class="citation web cs1">Turner, Glen (2011-03-30). <a rel="nofollow" class="external text" href="https://www.iana.org/assignments/media-types/application/vnd.tcpdump.pcap">"IANA record of application for MIME type application/vnd.tcpdump.pcap"</a>. <i>IANA</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2023-02-25</span></span>.</cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite id="CITEREFMcCanne" class="citation web cs1">McCanne, Steve. <a rel="nofollow" class="external text" href="https://sharkfest.wireshark.org/retrospective/sfus/presentations11/McCanne-Sharkfest'11_Keynote_Address.pdf">"libpcap: An Architecture and Optimization Methodology for Packet Capture"</a> <span class="cs1-format">(PDF)</span><span class="reference-accessdate">. Retrieved <span class="nowrap">December 27,</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.tcpdump.org/">"TCPDUMP/LIBPCAP public repository"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">December 27,</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.winpcap.org/news.htm">"WinPcap News"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">November 6,</span> 2017</span>.</cite></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-11">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.winpcap.org/docs/docs_412/html/group__internals.html">"WinPcap internals"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">December 27,</span> 2013</span>.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite class="citation pressrelease cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20130308100122/http://www.riverbed.com/us/company/news/press_releases/2010/press_102110.php">"Riverbed Expands Further Into The Application-Aware Network Performance Management Market with the Acquisition of CACE Technologies"</a> (Press release). <a href="Riverbed_Technology" title="Riverbed Technology">Riverbed Technology</a>. 2010-10-21. Archived from <a rel="nofollow" class="external text" href="http://www.riverbed.com/us/company/news/press_releases/2010/press_102110.php">the original</a> on 2013-03-08<span class="reference-accessdate">. Retrieved <span class="nowrap">2010-10-21</span></span>.</cite></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-13">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.winpcap.org/news.htm">"WinPcap ยท News"</a>. <i>WinPcap</i>. 2013-03-08.</cite></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-14">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://npcap.com">"Npcap"</a>.</cite></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-15">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://docs.microsoft.com/en-us/windows-hardware/drivers/network/ndis-filter-drivers">"Filter drivers"</a>. 15 December 2021.</cite></span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-16">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/nmap/npcap/releases/tag/v1.20">"Release Npcap 1.20"</a>. <i><a href="GitHub" title="GitHub">GitHub</a></i>.</cite></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-17">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://npcap.com/guide/npcap-devguide.html#npcap-devguide-updating">"Updating WinPcap software to Npcap"</a>. <i>Developing software with Npcap</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2023-02-25</span></span>.</cite></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-18">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://npcap.com/guide/npcap-users-guide.html#npcap-installer-options-gui">"Graphical installer options"</a>. <i>Npcap Users' Guide</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2023-02-25</span></span>.</cite></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-19">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://npcap.com/guide/npcap-devguide.html#npcap-feature-loopback">"For software that uses Npcap loopback feature"</a>. <i>Npcap User's Guide</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2023-02-25</span></span>.</cite></span>
</li>
<li id="cite_note-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-20">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://npcap.com/guide/npcap-devguide.html#npcap-feature-dot11">"For software that uses Npcap raw 802.11 feature"</a>. <i>Npcap User's Guide</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2023-02-25</span></span>.</cite></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><b><a href="#cite_ref-21">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://github.com/nmap/npcap/blob/master/LICENSE">"Npcap License"</a>. <i><a href="GitHub" title="GitHub">GitHub</a></i>.</cite></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-22">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.win10pcap.org">"Win10Pcap: WinPcap for Windows 10"</a>.</cite></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><b><a href="#cite_ref-23">^</a></b></span> <span class="reference-text"><cite class="citation cs2"><a rel="nofollow" class="external text" href="https://github.com/SoftEtherVPN/Win10Pcap"><i>Win10Pcap: WinPcap for Windows 10 (NDIS 6.x driver model): SoftEtherVPN/Win10Pcap</i></a>, SoftEther VPN Project, 2019-12-31<span class="reference-accessdate">, retrieved <span class="nowrap">2020-01-09</span></span></cite></span>
</li>
<li id="cite_note-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-24">^</a></b></span> <span class="reference-text"><cite id="CITEREFBevens2017" class="citation web cs1">Bevens, Bridget (July 31, 2017). <a rel="nofollow" class="external text" href="https://drill.apache.org/blog/2017/07/31/drill-1.11-released/">"Drill 1.11 Released"</a>.</cite></span>
</li>
<li id="cite_note-25"><span class="mw-cite-backlink"><b><a href="#cite_ref-25">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/apache/drill/blob/master/contrib/format-pcapng/src/main/java/org/apache/drill/exec/store/pcap/decoder/Packet.java">Packet.java</a> on <a href="GitHub" title="GitHub">GitHub</a></span>
</li>
<li id="cite_note-26"><span class="mw-cite-backlink"><b><a href="#cite_ref-26">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.endace.com/learn/what-is-a-pcap-file">"What Can Read or Save a PCAP?"</a>. <i>What is a PCAP file?</i>. <a href="Endace" title="Endace">Endace</a>.</cite></span>
</li>
</ol></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1266661725">
/* start https://en.wikipedia.org/ */


.mw-parser-output .portalbox{padding:0;margin:0.5em 0;display:table;box-sizing:border-box;max-width:175px;list-style:none}.mw-parser-output .portalborder{border:1px solid var(--border-color-base,#a2a9b1);padding:0.1em;background:var(--background-color-neutral-subtle,#f8f9fa)}.mw-parser-output .portalbox-entry{display:table-row;font-size:85%;line-height:110%;height:1.9em;font-style:italic;font-weight:bold}.mw-parser-output .portalbox-image{display:table-cell;padding:0.2em;vertical-align:middle;text-align:center}.mw-parser-output .portalbox-link{display:table-cell;padding:0.2em 0.2em 0.2em 0.3em;vertical-align:middle}@media(min-width:720px){.mw-parser-output .portalleft{margin:0.5em 1em 0.5em 0}.mw-parser-output .portalright{clear:right;float:right;margin:0.5em 0 0.5em 1em}}


/* end https://en.wikipedia.org/ */
</style>
<ul><li><span class="official-website"><span class="url"><a rel="nofollow" class="external text" href="https://tcpdump.org">Official website</a></span></span>, libpcap, tcpdump</li>
<li><span class="official-website"><span class="url"><a rel="nofollow" class="external text" href="https://npcap.com">Official website</a></span></span>, Npcap</li>
<li><span class="official-website"><span class="url"><a rel="nofollow" class="external text" href="https://www.winpcap.org/">Official website</a></span></span>, WinPcap, WinDump</li>
<li><a rel="nofollow" class="external text" href="https://www.netresec.com/?page=PcapFiles">List of publicly available PCAP files</a></li></ul></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-07-25" href="https://en.wikipedia.org/wiki/?title=Pcap&amp;oldid=1302438239">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>

</body></html>