Packet Capture (.pcap)
Packet Capture (.pcap)
Offline analysis of a previously captured packet file to extract TLS handshakes and detect classical vs post-quantum key exchange
This source is feature-gated and is only available when the scanner is built with the packet-capture feature enabled.
Overview
The Packet Capture source performs offline analysis of a previously captured .pcap or .pcapng file. It extracts the TLS handshakes from the captured traffic and detects whether the negotiated key exchange groups are classical or post-quantum. Because the analysis is offline, it generates no network activity and can be performed on a host separate from where the traffic was captured.
What It Scans
| Item | Details |
|---|---|
| Capture formats | libpcap (.pcap) and Wireshark (.pcapng) files |
| TLS handshakes | Handshake messages extracted from the captured flows |
| Key exchange groups | Named groups negotiated in each handshake |
| Classification | Each connection classified as classical or post-quantum key exchange |
When to Use
No Live Capture Possible
Analyze traffic on the scanning host when you cannot run a live capture there
Audit Existing Captures
Re-use packet captures already collected by your network or security teams
Use this source when the capture already exists or was collected elsewhere. For an active, live check of a single endpoint, use TLS Probe.
How to Run
Run a Packet Capture analysis from the Cockpit scan wizard:
Open Run a Scan
In the Cockpit, go to Run a Scan.
Select the source
In Step 1 (Source), choose Packet Capture.
Provide the capture file
Supply the .pcap or .pcapng file, then start the scan and review the findings.