Open a pcap or pcapng file without Wireshark
Drop a network capture from Wireshark, tcpdump, dumpcap or a router's packet capture to see what is in it: when it starts and ends, every packet in a table you can filter, the DNS lookups and their answers, the web hosts named in TLS and HTTP, and who talked to whom, with packet and byte counts. Save the packet list, conversations, endpoints and DNS log as CSV.
The capture is read on your device. Nothing is uploaded, and no address in it is looked up or contacted.
What it shows
- The capture summary: format and byte order, timestamp precision, link type, packet count, bytes captured and on the wire, first and last packet in UTC, duration and average rate. For pcapng also each interface's name, the packets it dropped, the capture filter and the program that wrote the file, and any comments.
- Every packet in a scrolling table that stays fast with hundreds of thousands of rows: time from the first packet, protocol, a one-line summary such as
50514 → 443 [SYN] Seq=1000 Win=64240 Len=0orStandard query 0x4a1f A example.org, source, destination and length. Type in the filter to keep the rows that mention an address, a port, a protocol or a word. Tap a row for its layers, one line each, and its first 1,024 bytes in hex. - Web hosts: the server name (SNI) in each TLS Client Hello, which is how HTTPS traffic still names the site it goes to, and the request line and
Hostheader of plain HTTP/1.x requests. - DNS: every query matched with its response, the answer records (A, AAAA, CNAME, MX, TXT, SRV, PTR, HTTPS and more), failures such as "No such name", queries that never got an answer, and the response time. Multicast DNS and LLMNR are included.
- Conversations and endpoints: each address pair (with ports for TCP and UDP) with packets and bytes in each direction and how long it lasted, and each address with what it sent and received, marked private, public, multicast or link-local, and with the names this capture gives it (from DNS answers, SNI, HTTP Host, DHCP or the file's own name records).
What it reads
| Layer | Decoded |
|---|---|
| File | pcap with microsecond or nanosecond timestamps in either byte order; pcapng with several sections (even of different byte order), several interfaces of different link types, enhanced, simple and obsolete packet blocks, name resolution, interface statistics and comments |
| Link | Ethernet (with 802.1Q VLAN tags), Linux cooked capture v1 and v2 (tcpdump -i any), raw IP, BSD and OpenBSD loopback, 802.11 Wi-Fi with or without radiotap; ARP, PPPoE and MPLS |
| Network | IPv4 (fragments marked), IPv6 with its extension headers, ICMP and ICMPv6 message names, IGMP |
| Transport | TCP flags, sequence and window; UDP |
| Application | DNS (UDP and TCP), mDNS, LLMNR, DHCP (message type, offered address, host name), TLS record and handshake types with SNI and ALPN, HTTP/1.x requests and responses, SSH banners, QUIC header type, SSDP, syslog; other ports are labelled by their usual service |
A worked example: ten DNS queries in 20 milliseconds
gopacket, Google's packet library for Go, ships a capture called test_dns.pcap (1,001 bytes) in its tests. It opens as a little-endian pcap with microsecond timestamps and Ethernet framing: 10 packets, 817 bytes on the wire, from 2014-10-14 17:08:05.708342 UTC to 20.345 ms later. Every packet is a DNS query over UDP to one of two servers, 95.211.92.14 (7 queries) and 95.211.92.15 (3), from 9 different resolvers, so there are 11 endpoints and 10 conversations (one resolver asked twice, from two source ports). The names asked for are things like picslife.ru (A) and mail.guru-net.com (AAAA). The DNS table lists all ten as "no response": the capture was taken on the servers' inbound side only, a fact the DNS table makes plain at a glance.
What this cannot do
- No live capture. A web page cannot read your network card. Record with Wireshark,
tcpdump -w file.pcapor your router's packet capture, then open the file here. - No decryption. HTTPS, QUIC (HTTP/3), SSH and WPA-encrypted Wi-Fi stay encrypted: you see who talked to whom, when and how much, plus the TLS server name sent in the clear, but not the content. A key log stored in a pcapng file is noted and not used. Encrypted Client Hello hides even the server name.
- Not Wireshark's dissectors. Wireshark has dissectors for thousands of protocols; this page decodes the common ones above and labels the rest by port. There are no display filters (the filter is a plain text match), no graphs, no expert analysis of retransmissions, and no editing or re-saving of the capture.
- No reassembly. Each packet is read on its own. TLS server names and HTTP request lines are found when they sit in one segment, which they almost always do; files sent over HTTP are not rebuilt, TCP streams are not followed, and IP fragments are marked rather than joined.
- Size. The whole file is read into memory, so captures of up to 1.5 GB open; a capture of a few million packets needs a few GB of memory, which a phone may not have. Gzip-compressed captures must be unpacked first, and other formats (Microsoft Network Monitor .cap, snoop, ERF) are not read.