PCAP
Packet Capture
PCAP is the process of intercepting and recording raw network packets for later analysis. PCAP files contain complete packet headers and payloads, giving analysts full visibility into network communications.
Como é usado em cibersegurança
Incident responders analyze PCAP files to reconstruct attack sequences and extract transferred files or credentials. SOC analysts use PCAP data to verify whether an alert represents a true positive by examining the actual traffic. Penetration testers capture packets during engagements to demonstrate data exposure risks.
Termo relacionado no glossário: packet capture
As definições são explicações originais escritas para fins de desenvolvimento profissional. Para definições técnicas autoritativas, consulte NIST, ISO ou o órgão de normalização correspondente.