PCAP
Packet Capture
PCAP is the process of intercepting and recording raw network packets for later analysis. PCAP files contain complete packet headers and payloads, giving analysts full visibility into network communications.
Cómo se usa en ciberseguridad
Incident responders analyze PCAP files to reconstruct attack sequences and extract transferred files or credentials. SOC analysts use PCAP data to verify whether an alert represents a true positive by examining the actual traffic. Penetration testers capture packets during engagements to demonstrate data exposure risks.
Término relacionado en el glosario: packet capture
Las definiciones son explicaciones originales escritas con fines de desarrollo profesional. Para definiciones técnicas autorizadas, consulta NIST, ISO o el organismo de normalización correspondiente.