Glossary Forensics

PCAP

PCAP is the file format for storing captured network packets, produced by tools such as tcpdump and Wireshark for later analysis.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

A capture records each Packet with a timestamp, letting analysts replay a conversation, see which hosts talked and extract files or credentials sent in clear text. The newer PCAPNG format adds extra metadata. Encrypted traffic (TLS) shows only addresses, sizes and timing, not content.

Try these tools

See also

  • Glossary Packet
    A packet is a small unit of data sent across a network.
  • Glossary TLS
    TLS (Transport Layer Security) is the cryptographic protocol that encrypts and authenticates connections, including HTTPS, email and VPNs.
  • Glossary Indicator of compromise (IOC)
    An indicator of compromise (IOC) is a piece of observable evidence, such as a file hash, IP address or domain.
AdSense Placeholder
Slot: footer_leaderboard