A pcap file records network traffic so you can see what data moved across your connection

A pcap file is a record of network packets — the small chunks of data that travel between computers on a network or the internet. The name comes from "packet capture," the process of recording this traffic. When you open a pcap file, you see a timestamped log of every packet that passed through a network interface during the recording period, including what was sent, where it went, and how much data moved.

Pcap files are plain-text or binary recordings, not encrypted summaries. They capture the actual packet contents, which means they can show you the websites someone visited, the files they downloaded, or the commands sent to a server — depending on what was encrypted at the time of capture. Network administrators, security researchers, and troubleshooters use pcap files to diagnose connection problems, investigate suspicious activity, or understand how a network behaved during a specific moment.

The file format itself is standardized, so any tool that reads pcap files can open files created by any other tool. The most common file extensions are .pcap and .pcapng (the newer format, which stands for "pcap next generation"). Both are text-based enough that you can read parts of them in a regular text editor, though specialized software makes the data far more useful.

Key Takeaways

  • A pcap file is a timestamped record of network packets that passed through a computer or network device during a specific time window.
  • Pcap files can reveal what websites were visited, what files were transferred, and what commands were sent — unless that traffic was encrypted.
  • Network administrators and security professionals use pcap files to troubleshoot connection problems, investigate breaches, or analyze network behavior.
  • The pcap format is standardized, so files created by one tool can be opened and read by any other pcap-compatible software.

How pcap files are created and what they contain

A pcap file is created by a packet sniffer — software or hardware that listens to network traffic and records it. The most widely used packet sniffer is Wireshark, a free, open-source tool available for Windows, macOS, and Linux. When you start a capture in Wireshark, it records every packet it sees on your network interface until you stop the capture. Other tools like tcpdump (a command-line sniffer for Unix and Linux) and Snort (a network security tool) also create pcap files.

Each packet in a pcap file includes several layers of information. The outermost layer shows the physical source and destination — the MAC addresses of the devices on your local network. The next layer shows the IP addresses of the computers sending and receiving data. Inside that is the protocol information — whether the packet is TCP, UDP, or another type — and the port numbers involved. At the center is the actual payload: the data being transmitted, which might be an HTTP request, a DNS query, an email message, or part of a file transfer.

The pcap file also records a timestamp for each packet, usually down to the microsecond. This timing information is crucial for troubleshooting, because it lets you see the exact sequence of events and how long each step took. If a connection is slow, the timestamps show whether the delay is in the request, the response, or the time between them.

Why network professionals capture and analyze pcap files

Network administrators use pcap files to diagnose why a connection is failing or slow. If a user reports that a website is not loading, an administrator can capture traffic from that user's computer, then open the pcap file in Wireshark to see whether the request ever left the computer, whether it reached the server, and whether the server sent a response back. The pcap file shows the exact error message the server returned, which often points directly to the problem.

Security teams use pcap files to investigate suspected breaches or malware infections. If a computer is behaving strangely, a security analyst can capture its network traffic and search the pcap file for connections to known malicious servers, unusual data transfers, or command-and-control communications. Pcap files are also used in forensic investigations, where they serve as evidence of what happened on a network at a specific time.

Developers use pcap files to debug applications that communicate over a network. If an app is not sending data correctly or is receiving unexpected responses, a developer can capture the traffic and examine exactly what the app is transmitting and what it is receiving back. This is often faster than reading through application logs, because the pcap file shows the raw network behavior without any filtering or interpretation by the application itself.

How to open and read a pcap file

Wireshark is the standard tool for opening and analyzing pcap files. After you open a pcap file in Wireshark, the main window shows a list of all packets in the file, with columns for the packet number, timestamp, source IP, destination IP, protocol, and a brief description of what the packet contains. You can click on any packet to see its full contents, broken down layer by layer.

Wireshark also includes filters and search tools. You can filter the packet list to show only traffic from a specific IP address, only a certain protocol (like HTTP or DNS), or only packets containing specific text. This is essential when a pcap file contains thousands of packets — filtering narrows it down to the traffic you actually need to examine.

If you do not want to install software, some online pcap viewers exist, though they are less powerful than Wireshark and may not be suitable for sensitive data. For most professional use, downloading Wireshark is the better choice. It is free and runs on any major operating system.

What you can and cannot see in a pcap file

A pcap file shows unencrypted data in full detail. If someone visited an unencrypted website (one using HTTP instead of HTTPS), the pcap file contains the entire page request and response, including the URL, any form data they submitted, and the page content itself. If someone sent an unencrypted email or instant message, it is visible in the pcap file. If a file was transferred over an unencrypted protocol, the file contents are there.

However, most modern traffic is encrypted. If someone visits a website using HTTPS, the pcap file shows that a connection was made to that server and how much data was transferred, but not the specific pages visited or what was sent. Encrypted email, encrypted messaging apps, and VPN traffic all appear in the pcap file as encrypted blobs — you can see that communication happened, but not what was said.

A pcap file also cannot show traffic that did not pass through the network interface being captured. If you are capturing on one computer, you only see that computer's traffic. If you are capturing on a network switch or router, you see all traffic passing through that device. The location of the capture determines what is visible.

Pcap file formats and compatibility

The original pcap format, still widely used, was developed for the libpcap library on Unix systems. Files in this format use the .pcap extension. The newer pcapng format (pcap next generation) uses the .pcapng extension and adds features like the ability to store multiple interfaces' traffic in one file and to include comments and metadata.

Most modern tools support both formats. Wireshark reads and writes both .pcap and .pcapng files. If you capture traffic with one tool and need to analyze it with another, the standardized format means it will almost always work. Some older tools may not support .pcapng, but they will handle .pcap files without issue.

File size can vary dramatically depending on how much traffic was captured. A short capture on a quiet network might be a few megabytes. A long capture on a busy network can be gigabytes or even larger. Most tools let you set a file size limit so the capture stops or rolls over to a new file when it reaches a certain size.

Legal and privacy considerations when capturing pcap files

Capturing network traffic on a network you own or have permission to monitor is generally legal. Network administrators routinely capture traffic on their company networks for troubleshooting and security purposes. However, capturing traffic on a network you do not own or without the owner's permission is illegal in most jurisdictions and violates wiretapping laws.

Even on your own network, pcap files can contain sensitive information — passwords, private messages, financial data, or health information if that traffic was unencrypted. Pcap files should be treated as confidential and stored securely. If you share a pcap file with someone else for troubleshooting, be aware that they will see everything in that file, including data that may not be relevant to the problem you are asking them to help with.

Some organizations have policies requiring that pcap files be deleted after a certain period or that sensitive data be redacted before files are shared. If you work in a regulated industry like healthcare or finance, check your organization's data retention and privacy policies before capturing or storing pcap files.

Frequently Asked Questions

Can I open a pcap file in a text editor?

Partially. Pcap files contain both binary data and text, so opening one in a text editor will show some readable content mixed with unreadable characters. You will see fragments of unencrypted traffic, but the structure and timing information will be garbled. Wireshark or another pcap viewer is necessary to see the data correctly.

What is the difference between pcap and pcapng?

Pcapng is a newer format that supports multiple network interfaces in one file, allows you to add comments and metadata, and handles some edge cases better than the original pcap format. Most modern tools support both. For most purposes, the difference does not matter — both formats store the same packet data and are widely compatible.

Can I use a pcap file to see what websites someone visited?

Only if the traffic was unencrypted. Modern websites use HTTPS, which encrypts the page content and the specific URLs visited. A pcap file will show that a connection was made to a website's server and how much data was transferred, but not which pages were viewed. Unencrypted HTTP traffic would show the full URLs.

How long should I keep pcap files?

That depends on your organization's policies and legal requirements. Many organizations delete pcap files after 30 days or 90 days to manage storage and protect privacy. If you are investigating a security incident, you may need to keep the relevant pcap files longer. Check with your IT or legal department for guidance specific to your situation.

Do I need special permissions to capture pcap files on my own computer?

On Windows, you typically need administrator privileges to capture traffic. On macOS and Linux, you may need to run the capture tool with elevated permissions (using sudo). On your own computer, you have the right to capture your own traffic. On a shared or corporate network, check with your IT department before capturing, even if you have the technical ability to do so.