Sample PCAP files

PCAP (.pcap, packet capture) - the network traffic dump format: the file holds whole frames exactly as the network card saw them, each one with its own timestamp. Below are ready-made captures for Wireshark, tcpdump and your own parsers

Transport and applications

Sample file: Handshake and session close: SYN, SYN-ACK, ACK, FIN
Handshake and session close: SYN, SYN-ACK, ACK, FIN TCP 7 packets
538 b
↓
Sample file: A GET request and a 200 response with the page body
A GET request and a 200 response with the page body HTTP GET 200
1.2 Kb
↓
Sample file: A, AAAA and MX queries plus an NXDOMAIN answer
A, AAAA and MX queries plus an NXDOMAIN answer DNS A AAAA MX
834 b
↓
Sample file: The full address lease: DISCOVER, OFFER, REQUEST, ACK
The full address lease: DISCOVER, OFFER, REQUEST, ACK DHCP DORA
1.3 Kb
↓
Sample file: Four echo request and echo reply pairs, an ordinary ping
Four echo request and echo reply pairs, an ordinary ping ICMP echo
872 b
↓
Sample file: One second of voice, carrying a real 440 Hz tone
One second of voice, carrying a real 440 Hz tone RTP G.711
11.3 Kb
↓

Link layer and addressing

Sample file: A request, a reply and a gratuitous announcement
A request, a reply and a gratuitous announcement ARP
314 b
↓
Sample file: Tagged frames in two different VLANs
Tagged frames in two different VLANs VLAN 802.1Q
684 b
↓
Sample file: Wi-Fi monitor capture: beacons from two access points and a probe
Wi-Fi monitor capture: beacons from two access points and a probe 802.11 radiotap
1022 b
↓
Sample file: An ICMPv6 ping and a DNS query over IPv6
An ICMPv6 ping and a DNS query over IPv6 IPv6 ICMPv6
778 b
↓

Whole sessions

Sample file: One host on the network: ARP, DNS, TCP, HTTP and ping in a row
One host on the network: ARP, DNS, TCP, HTTP and ping in a row mixed 19 packets
1.9 Kb
↓
Sample file: A lost packet, duplicate ACKs and a fast retransmit
A lost packet, duplicate ACKs and a fast retransmit TCP fast retransmit
8.3 Kb
↓
Sample file: Bulk transfer: 5400 full-size packets
Bulk transfer: 5400 full-size packets TCP 5407 packets
5.4 Mb
↓

Container and edge cases

Sample file: The next-generation block format
The next-generation block format PCAPNG
2.5 Kb
↓
Sample file: Timestamp resolution of 1 ns instead of 1 µs
Timestamp resolution of 1 ns instead of 1 µs PCAP 1 ns
1.2 Kb
↓
Sample file: Reversed byte order in the file header
Reversed byte order in the file header PCAP big-endian
1.2 Kb
↓
Sample file: A valid header and zero packets
A valid header and zero packets PCAP 0 packets
24 b
↓
Sample file: The last packet cut off halfway
The last packet cut off halfway PCAP truncated
1.2 Kb
↓

🧠 How PCAP works

The file opens with a 24-byte header: the magic number, the version, the link type and the snaplen. Then come the records: each one has its own 16-byte header with a timestamp and a length, followed by the frame itself, byte for byte as it travelled down the wire. The magic number is written in the file's own byte order, which is how a reader works out whether it has to swap every other number. The link type matters too: an Ethernet capture has 1, a Wi-Fi monitor capture has 127, and there the frame starts with a radiotap header instead of MAC addresses.

pcap file header 24 B 16 B frame 16 B frame 16 B frame ... timestamp Ethernet 14 B IPv4 20 B TCP 20 B payload HTTP, DNS, RTP