Packet Capture
The collection of network packets or frames from an interface or observation point for diagnostics, monitoring, security analysis, or forensic reconstruction.
Networking Context
Packet capture records frames or packets at a particular interface or observation point for diagnostics, monitoring, security analysis, or forensic reconstruction. Snap length, promiscuous mode, NIC offloads, timestamping, and capture position determine what the trace actually contains.
Evidence Boundary
A PCAP is not an absolute record of every packet that traversed the network. Capture drops, interface offloads, mirrored-port configuration, and observation-point placement can hide or transform traffic, so capture statistics should be checked.
Related Networking Concepts
- PCAP
- Network Forensics
- Packet Loss
- Timestamp