PCAP is a file containing recorded network traffic.
Tools
- Wireshark — GUI analysis, filters, protocol dissectors.
- tcpdump — CLI capture.
- tshark — CLI Wireshark.
- NetworkMiner — passive file reconstruction.
CTF Tips
Follow TCP Stream, Export HTTP Objects, strings on pcap, hunt flags in DNS queries.