Wireshark handles all capture file I/O in the wiretap library. The proposed file extension for libpcap based files is.
Libpcap, and the Windows port of libpcap, WinPcap, use the same file format.Īlthough it's sometimes assumed that this file format is suitable for Ethernet networks only, it can serve many different network types, examples can be found at the Wireshark's Supported Capture Media page all listed types are handled by the libpcap file format. As the libpcap library became the "de facto" standard of network capturing on UN*X, it became the "common denominator" for network capture files in the open source world (there seems to be no such thing as a "common denominator" in the commercial network capture world at all). This file format is a very basic format to save captured network data.