Pcap Format

Libpcap format, industry default
1 min |  Ross Jacobs |  July 7, 2019

Table of Contents


Pcap as a format was born at the same time as tcpdump/libpcap which used it. Technically, this would place place it at 1988 when tcpdump was created. However, I think it’s fairer to place it at 1999 when tcpdump.org was launched and became more well-known.

Pcap is the most common capture type because libpcap has had support and been around for more than 20 years. As an older format, it allocates fewer fields for packet and capture metadata.

Pcap Docs

Libpcap Programming