Skip to content

Repository files navigation

PCAP Surgery

Community Edition: Free Windows Linux Local first

Inspect the packet, preview the smallest defensible rewrite, and preserve the original capture as evidence.

Free Community Edition PCAP analyzer and PCAP editor for local packet detail, bounded rewrite previews, checksum repair, and privacy evidence.

Isolate the flow that matters, preview controlled changes, and export a minimal repro or regression fixture without overwriting the source capture.

PCAP Surgery Community Edition is free to download and use. Local capture inspection and validation workflows for small PCAP surgery tasks.

Download Community Edition · Product guide · Help · Report a bug

Download PCAP Surgery 0.1.10

Platform Package Use it when
Linux x64 (APPIMAGE) pcap-surgery-0.1.10-linux-x64.AppImage Portable Linux desktop package
Linux x64 (DEB) pcap-surgery-0.1.10-linux-x64.deb Debian, Ubuntu, Mint, and compatible systems
Linux x64 (RPM) pcap-surgery-0.1.10-linux-x64.rpm Fedora, RHEL, openSUSE, and compatible systems
Windows x64 pcap-surgery-0.1.10-windows-x64-setup.exe Guided Windows installer

Checksums, installation notes, and the complete platform matrix live on the official download page.

System requirements

  • Windows: Windows 10 or Windows 11 on x64.
  • Linux: a mainstream x64 distribution with glibc 2.35 or newer, such as Ubuntu 22.04+, Debian 12+, Fedora, or openSUSE (AppImage, DEB, and RPM packages).
  • Disk space: a few hundred megabytes free for the application and its bundled resources.

Why PCAP Surgery exists

A local capture-transformation workbench for the step after Wireshark analysis and before vendor escalation or lab replay. It is not a live sniffer, a full protocol analyzer, or a complete payload-sanitization system.

Edition boundary: The technical sections below describe the complete product surface and can include optional licensed workflows. The exact free Community Edition scope is listed separately below.

Prepare the capture another engineer actually needs.

PCAP Surgery is a local desktop workbench for opening classic PCAP and basic single-interface Ethernet PCAPNG, narrowing evidence, previewing supported L2-L4 transformations, and exporting a focused classic PCAP. IPv4 header masking is not full payload redaction.

PCAP and basic PCAPNG import

Open classic PCAP and basic single-interface Ethernet PCAPNG, then index packet metadata without uploading capture content.

Packet timeline and filters

Filter by protocol, endpoint, direction, packet number, time range, and text while preserving a dense packet table.

Decoded packet detail

Inspect Ethernet, IP, TCP, UDP, DNS, ICMP, ARP, payload bytes, offsets, and copyable evidence for the selected packet.

Selected-artifact privacy exposure inventory

For the selected full or subset artifact, inventory visible IPv4, IPv6, MAC, DNS, HTTP Host, TLS SNI, and printable payload or unknown exposure. This is a bounded partial review with no decryption, stream reassembly, or safe-to-share verdict.

Inspect before you change anything

  • Classic PCAP and basic Ethernet PCAPNG import feed a dense packet table with protocol, endpoint, direction, packet number, time range, and text filters.
  • Ethernet, IP, TCP, UDP, DNS, ICMP, ARP, offsets, and payload bytes stay tied to the selected packet so edits are grounded in visible evidence.
  • The workflow is built for packet-capture evidence review, not a generic capture viewer with edit commands bolted on.

Edits are explicit and exportable

  • Community can inspect and preview transformations; Optional licensing unlocks writing edited and subset classic PCAP artifacts.
  • Supported edit paths cover fixed-length byte changes, trim/keep decisions, timing changes, IPv4 and MAC rewrites, ports, VLAN fields, and selected TCP/IP fields.
  • Supported header rewrites report IPv4/TCP/UDP checksum repairs. Raw byte edits do not receive automatic checksum repair.

Repair without losing the story

  • Indexed packet windows stay focused through filters, the evidence map, decoded detail, byte evidence, and export scope rather than forcing every task into CLI notes.
  • Subset export helps remove unrelated packets while preserving the sequence and timing evidence needed for DNS, TCP, UDP, ICMP, ARP, and application investigations.
  • Classic PCAP export is the optional licensed workflow today, with a focused workflow for trimming, supported header rewrites, timing repair, and minimal reproduction artifacts.

Free planning; use optional licensing when you need to write the artifact

  • Use Community for local inspection and transformation previews; use Professional when you need to write edited or subset PCAP artifacts.
  • No subscription and no cloud upload are required for customer traces, lab captures, or incident evidence.
  • The value is a reviewable path from noisy evidence to a smaller support or regression artifact, without a fragile command-line pipeline.

Community Edition is genuinely useful

  • Capture metadata review
  • Packet evidence inspection
  • Filter and detail workflows

Optional licensed workflows are available for people who need the expanded feature set. Licensing details belong on the website; the Community Edition remains the free way to evaluate and use the core product.

See the real desktop workflow

Capture transformation start

Capture transformation start — PCAP Surgery

The product opens by explaining the minimal-repro outcome, local processing boundary, and supported formats before exposing the workbench.

Packet detail evidence

Packet detail evidence — PCAP Surgery

Decoded layers, packet metadata, raw bytes, and selected-packet context.

Time workshop

Time workshop — PCAP Surgery

Preview timestamp edits and duration changes before writing a capture.

Export plan

Export plan — PCAP Surgery

Review artifact scope, supported checksum repairs, privacy limitations, and warnings before writing a file.

Local-first by design

PCAP Surgery is a desktop workflow. Your working files stay on the machine unless you deliberately export or share them. The product page documents the exact capability boundary so the focused workflow can be evaluated on real evidence.

Documentation

Frequently asked questions

Community scope: Community Edition previews supported edits and transformations; writing a modified capture is an optional licensed workflow.

What can PCAP Surgery do that Wireshark and editcap can't?

PCAP Surgery is a visual capture-transformation workbench, not a replacement for either tool. It connects evidence scoping, per-rule impact preview, supported checksum-aware rewrites, and classic PCAP export without requiring a fragile command pipeline. It does not yet strip arbitrary payloads or provide Wireshark-level protocol analysis.

Can I download PCAP Surgery today?

Yes. The download page publishes Linux and Windows packages with sizes and SHA-256 checksums.

Who uses PCAP Surgery?

Tier-3 support engineers, network product QA teams, and lab engineers who need to turn a noisy capture into a focused support case or deterministic regression fixture.

Can Wireshark edit PCAP files the way PCAP Surgery can?

Wireshark remains the broad analysis reference. PCAP Surgery starts after that analysis: choose the evidence scope, preview supported transformations, review limitations, and export a focused classic PCAP artifact.

When is editcap enough instead of PCAP Surgery?

editcap is enough when the transformation is known, scripted, and low risk. Use PCAP Surgery when an operator needs visual evidence context, a packet-impact preview, supported checksum-aware rewrites, and an artifact preflight before export.

Does IPv4 header masking make a PCAP safe to share?

No. Header masking does not remove identifiers from payloads, DNS names, HTTP fields, TLS SNI, credentials, IPv6, or unknown protocols. The current release surfaces this limitation and should not be used as a complete sanitization guarantee.

Community, support, and security

Official repository

This is the official public distribution and community repository for PCAP Surgery: verified release links, current screenshots, documentation routes, issue intake, and security guidance. Product development happens in a private workspace; public issues here are the right place to report reproducible product behavior and request focused improvements.

About

Free Community Edition PCAP analyzer and PCAP editor for local packet detail, bounded rewrite previews, checksum repair, and privacy evidence.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

31 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors