What is a .PCAPNG file?
PCAPNG is the modern, richer network-capture format. Opened by Wireshark.
- Did you know
- PCAPNG, read by Wireshark, replaced classic pcap with support for multiple interfaces and richer metadata.
- Every pcapng capture opens with a Section Header Block, the marker that distinguishes it from classic pcap.
- Pcapng became Wireshark’s default save format in 2012 with version 1.8.
- What Analyser reads
- Inspect security and crypto files: PEM private/public keys (RSA/EC/Ed25519, PKCS#1 vs PKCS#8, encryption), OpenSSH .pub with SHA-256 fingerprint, PuTTY .ppk, PKCS#10 CSR, X.509 CRL, PKCS#7 bundles, OpenVPN/WireGuard configs, Java KeyStores, Apple .mobileconfig/.mobileprovision, Windows .reg (with autorun flagging), and pcap/pcapng captures - warning when a private key or secret is present.
- Depth of analysis
- .PCAPNG is an identification-grade format: Analyser recognises it from its bytes and decodes the header metadata it carries, rather than opening it in a full viewer. Formats that do get a full viewer are marked "Full" on the formats page.
- Open a .PCAPNG file
- Drag a .PCAPNG file onto the Analyser home page (or tap to pick one). It is identified entirely in your browser - nothing is uploaded, there is no account, and it works offline once installed.