viewhack

Open a pcap or pcapng file without Wireshark

Drop a network capture from Wireshark, tcpdump, dumpcap or a router's packet capture to see what is in it: when it starts and ends, every packet in a table you can filter, the DNS lookups and their answers, the web hosts named in TLS and HTTP, and who talked to whom, with packet and byte counts. Save the packet list, conversations, endpoints and DNS log as CSV.

The capture is read on your device. Nothing is uploaded, and no address in it is looked up or contacted.

What it shows

What it reads

LayerDecoded
Filepcap with microsecond or nanosecond timestamps in either byte order; pcapng with several sections (even of different byte order), several interfaces of different link types, enhanced, simple and obsolete packet blocks, name resolution, interface statistics and comments
LinkEthernet (with 802.1Q VLAN tags), Linux cooked capture v1 and v2 (tcpdump -i any), raw IP, BSD and OpenBSD loopback, 802.11 Wi-Fi with or without radiotap; ARP, PPPoE and MPLS
NetworkIPv4 (fragments marked), IPv6 with its extension headers, ICMP and ICMPv6 message names, IGMP
TransportTCP flags, sequence and window; UDP
ApplicationDNS (UDP and TCP), mDNS, LLMNR, DHCP (message type, offered address, host name), TLS record and handshake types with SNI and ALPN, HTTP/1.x requests and responses, SSH banners, QUIC header type, SSDP, syslog; other ports are labelled by their usual service

A worked example: ten DNS queries in 20 milliseconds

gopacket, Google's packet library for Go, ships a capture called test_dns.pcap (1,001 bytes) in its tests. It opens as a little-endian pcap with microsecond timestamps and Ethernet framing: 10 packets, 817 bytes on the wire, from 2014-10-14 17:08:05.708342 UTC to 20.345 ms later. Every packet is a DNS query over UDP to one of two servers, 95.211.92.14 (7 queries) and 95.211.92.15 (3), from 9 different resolvers, so there are 11 endpoints and 10 conversations (one resolver asked twice, from two source ports). The names asked for are things like picslife.ru (A) and mail.guru-net.com (AAAA). The DNS table lists all ten as "no response": the capture was taken on the servers' inbound side only, a fact the DNS table makes plain at a glance.

What this cannot do