Skip to main content

Packet Capture (.pcap)

Applies to:
.pcap / .pcapng FilesOffline AnalysisTLS Handshake ExtractionClassical vs PQ Key Exchange
Feature-gated

This source is feature-gated and is only available when the scanner is built with the packet-capture feature enabled.

Overview​

The Packet Capture source performs offline analysis of a previously captured .pcap or .pcapng file. It extracts the TLS handshakes from the captured traffic and detects whether the negotiated key exchange groups are classical or post-quantum. Because the analysis is offline, it generates no network activity and can be performed on a host separate from where the traffic was captured.

What It Scans​

ItemDetails
Capture formatslibpcap (.pcap) and Wireshark (.pcapng) files
TLS handshakesHandshake messages extracted from the captured flows
Key exchange groupsNamed groups negotiated in each handshake
ClassificationEach connection classified as classical or post-quantum key exchange

When to Use​

📂

No Live Capture Possible

Analyze traffic on the scanning host when you cannot run a live capture there

📋

Audit Existing Captures

Re-use packet captures already collected by your network or security teams

Tip

Use this source when the capture already exists or was collected elsewhere. For an active, live check of a single endpoint, use TLS Probe.

How to Run​

Run a Packet Capture analysis from the Cockpit scan wizard:

1

Open Run a Scan

In the Cockpit, go to Run a Scan.

2

Select the source

In Step 1 (Source), choose Packet Capture.

3

Provide the capture file

Supply the .pcap or .pcapng file, then start the scan and review the findings.