What is the PCAP file format?
.pcap is a binary file format used by applications for monitoring network traffic. A *sniffer* - for example, Wireshark - captures live packet data and saves it into a .pcap file. PCAP files allow users to inspect network traffic for a given capture session in off-line mode, as opposed to real-time mode. Analyzing and auditing network traffic is an essential practice that facilitates network performance optimization and cyberattack prevention.
The format originates from the libpcap/tcpdump project and has become the de-facto standard for packet capture storage. Each file begins with a 24-byte global header whose magic number (D4 C3 B2 A1 in little-endian byte order) identifies the file and signals the byte order to reading tools. The official MIME type is application/vnd.tcpdump.pcap. A newer successor - .pcapng - adds support for multiple interfaces, metadata blocks, and comments; Wireshark auto-detects both formats on open.
What is a sniffer?
A sniffer is a type of software tool that can capture and analyze network traffic. The tool "listens" to network traffic on a given network by switching a network interface into *promiscuous* mode, so it can see all the traffic on that network, including data not addressed to that particular interface. Running a sniffer on a router or network-attached computer does not require promiscuous mode. A *sniffer* may also refer to an electronic device used for monitoring network traffic.
Wireshark
Wireshark is a free, open-source sniffer tool available for Windows, Linux, and macOS. Its breadth of features has made it the most popular network traffic analysis tool, used by professional IT and security teams as well as individual users. Ethereal was the original name for this tool until May 2006, when it was renamed Wireshark. The command-line counterpart tshark and the classic Unix tool tcpdump also read and write .pcap files natively, making the format universally supported across platforms.
Security & safety
RISK: MEDIUMA .pcap is passive data and cannot execute, but it is sensitive: a capture can contain clear-text passwords, session cookies, authentication tokens, internal IPs/hostnames and other private traffic. Treat captures as confidential and do NOT upload sensitive ones to public online analysers. Capturing traffic on networks you don't own or aren't authorised to monitor may be illegal. Also verify the file is really a capture - a file that's .pcap by extension but doesn't match the libpcap/pcapng magic bytes may be mislabeled or a different format.
Format details
in a nutshellPrograms that open PCAP files
Technical details
deep spec| File structure | 24-byte global header followed by sequential packet records, each with a 16-byte per-packet header and raw captured frame data |
| Magic number (little-endian) | 0xD4C3B2A1 at byte offset 0, identifying the file and signaling little-endian byte order to reading tools |
| Magic number (big-endian) | 0xA1B2C3D4 at byte offset 0, used when the capturing machine writes in big-endian byte order |
| Nanosecond-resolution variants | Magic 0x4D3CB2A1 (LE) or 0xA1B23C4D (BE) marks files where timestamps are stored in nanoseconds rather than microseconds |
| Timestamp encoding | Two 32-bit integers per packet: seconds since Unix epoch and microseconds (or nanoseconds in the ns-precision variant) |
| Snaplen field | 32-bit global header field capping the maximum bytes saved per packet; default capture value is 65535 bytes |
| Network (link-layer type) field | 32-bit code in the global header identifying the data-link layer: 1 = Ethernet, 105 = IEEE 802.11 Wi-Fi, 113 = Linux cooked capture |
| Per-packet header fields | ts_sec, ts_usec/ts_nsec, incl_len (bytes actually saved), orig_len (original on-wire packet length) |
| MIME type | application/vnd.tcpdump.pcap |
| Byte-order detection | Fully automatic - tools read the magic number at offset 0 to determine endianness without user input |
| Successor format | .pcapng (PCAP Next Generation) adds multiple-interface support, metadata blocks, packet comments, and enhanced packet records |
| Compression | Format is uncompressed by design; files are commonly distributed as .pcap.gz (gzip) or .pcap.xz for storage and transfer |
| Primary capture tools | tcpdump (command-line, Unix/Windows); tshark (cross-platform command-line); Wireshark (GUI) |
| File size limit | No format-imposed maximum; bounded only by operating-system filesystem limits and available storage |
| Released | Early 1990s (libpcap/tcpdump); IETF draft standard for the on-disk format |
| Open standard | Yes · royalty-free |
| Specification | datatracker.ietf.org |
PCAP conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about PCAP files.