Sample PCAP files
PCAP (.pcap, packet capture) - the network traffic dump format: the file holds whole frames exactly as the network card saw them, each one with its own timestamp. Below are ready-made captures for Wireshark, tcpdump and your own parsers
Transport and applications
Link layer and addressing
Whole sessions
Container and edge cases
🧠 How PCAP works
The file opens with a 24-byte header: the magic number, the version, the link type and the snaplen. Then come the records: each one has its own 16-byte header with a timestamp and a length, followed by the frame itself, byte for byte as it travelled down the wire. The magic number is written in the file's own byte order, which is how a reader works out whether it has to swap every other number. The link type matters too: an Ethernet capture has 1, a Wi-Fi monitor capture has 127, and there the frame starts with a radiotap header instead of MAC addresses.
