PCAP
Packet Capture
operationsmedium
A PCAP is a recorded copy of raw network traffic, saved packet by packet for later analysis. Incident responders replay PCAPs in tools like Wireshark to see exactly what data crossed the network during an attack. Full packet data is the ground truth of network activity; logs summarize, but PCAPs show everything.