Blogs
PCAP Surgery blogs
PCAP Surgery articles for debugging failures, reading evidence, and choosing the next step.
Isolate the flow that matters, preview controlled changes, and export a minimal repro or regression fixture without overwriting the source capture.
A local capture-transformation workbench for the step after Wireshark analysis and before vendor escalation or lab replay. It is not a live sniffer, a full protocol analyzer, or a complete payload-sanitization system.
This index is organized by real problems. Start with the symptom, check the evidence, then choose the next action.
Common starting points include:

PCAP editor
packet analyzer
anonymize PCAP
Latest articles
- Best PCAP Editing Tools: Choose by Artifact, Not Feature Count An honest comparison of Wireshark, editcap, tcprewrite, TraceWrangler, Scapy, and PCAP Surgery for preparing support and regression artifacts. Read article
- Corrupt PCAP Triage: Preserve Evidence Before You Rewrite How to distinguish a damaged capture container from bad packet checksums, and where PCAP Surgery's repair scope stops. Read article
- Packet Capture Preparation: Repair, Sanitization, and Evidence Workflow Prepare a packet capture for support or QA without confusing focused scope, supported header rewrites, checksum repair, and partial privacy inventory with complete sanitization or corrupt-file recovery. Read article
- PCAP Editing FAQ for Support and QA Engineers Practical answers about PCAP editing, checksum warnings, privacy limits, formats, validation, licensing, and PCAP Surgery's real scope. Read article
- PCAP File Analyzer vs Editor: Complete Packet-Evidence Workflow Use a PCAP file analyzer to establish what happened, then use a bounded PCAP editor workflow to prepare a minimal, reviewable support or regression artifact without losing evidence. Read article
- PCAP Privacy Review: What Header Masking Does Not Remove A practical privacy checklist for packet captures and an explicit account of PCAP Surgery's current partial coverage. Read article
- PCAP Surgery vs editcap for Packet Artifact Preparation An evidence-first comparison of PCAP Surgery and editcap for packet capture editing, support handoffs, repeatable conversion, and QA fixtures. Read article
- PCAP Surgery vs TraceWrangler: Redaction and Handoff Choose the right PCAP privacy and handoff workflow: compare bounded evidence preparation in PCAP Surgery with a dedicated sanitization or TraceWrangler-style redaction process, then validate the output before sharing. Read article
- PCAP Surgery vs Wireshark, editcap, and TraceWrangler An honest capability and workflow comparison for analysis, CLI processing, sanitization, and focused PCAP artifact preparation. Read article
- TraceWrangler Alternative? A Capture-Workflow Migration Test Test PCAP Surgery against a real TraceWrangler workflow with an acceptance corpus, exposure review, transformation preview, and output verification. Read article
- Visual editcap Alternative: Decide, Preview, and Verify a PCAP Handoff Choose between editcap automation and PCAP Surgery's visual review path, then verify packet selection, timing, transformations, and output integrity. Read article
- Asymmetric Routing and One-Sided PCAP Analysis How to analyze asymmetric routing and one-sided packet captures, missing replies, NAT/firewall paths, half conversations, capture point mistakes, and misleading retransmission evidence. Read article
- IPv6 DAD and Neighbor Solicitation PCAP Analysis How to analyze IPv6 Duplicate Address Detection, Neighbor Solicitation, Neighbor Advertisement, SLAAC failures, missing NA responses, duplicate IPv6 addresses, and no IPv6 connectivity in packet captures. Read article
- TCP CWR Flag and ECN PCAP Analysis: Diagnose CE, ECE, and Congestion Without Packet Loss Diagnose TCP CWR, ECE, and CE flags in Wireshark PCAPs. Covers ECN congestion without loss, ECN negotiation failure, and middlebox compatibility. Read article
- TCP Nagle and Delayed ACK PCAP Analysis How to analyze TCP Nagle algorithm and delayed ACK interactions in packet captures, small packet latency, request/response stalls, interactive protocol delays, and TCP_NODELAY evidence. Read article
- TCP SACK and DSACK in Wireshark: Diagnose Packet Loss, sack_perm Option, and Retransmission in PCAPs Diagnose TCP SACK, DSACK, and sack_perm options in Wireshark PCAPs. Covers selective acknowledgments, packet loss recovery, reordering, duplicate ACKs, and spurious retransmissions. Read article
- VLAN Tag Missing in PCAP Analysis: 802.1Q Tags, Native VLAN, Trunk Ports, Driver Stripping, and Wrong How to analyze missing VLAN tags in packet captures, 802.1Q tagging, native VLAN behavior, trunk port mistakes, driver tag stripping, capture filters, and VLAN mismatch failures. Read article
- ARP Duplicate IP Address Conflict PCAP Analysis How to diagnose duplicate IP address conflicts, ARP storms, gratuitous ARP, wrong MAC mappings, gateway confusion, and intermittent LAN failures in packet captures. Read article
- DHCP Failure PCAP Analysis: Discover, Offer, Request, ACK, NAK, and No IP Address Problems How to troubleshoot DHCP failure, no IP address, DHCP Discover without Offer, DHCP NAK, relay problems, VLAN issues, and packet capture evidence. Read article
- DNS Retransmission and Timeout PCAP Analysis: Finding Slow Resolvers, Lost Queries, and Broken Responses How to diagnose DNS timeout, retransmission, no response, SERVFAIL, UDP loss, TCP fallback, resolver latency, and application delay with packet captures. Read article
- DNS Timeout, NXDOMAIN, and SERVFAIL in PCAP: How to Tell Slow DNS from a Slow Server How to diagnose DNS timeouts, NXDOMAIN, SERVFAIL, repeated queries, and slow application startup using packet capture evidence. Read article
- HTTP 502 vs 504: PCAP Gateway Timeout Analysis Use packet captures to separate HTTP 502 Bad Gateway from 504 Gateway Timeout: trace client, proxy, and upstream TCP, TLS, request timing, resets, and timeout policy. Read article
- HTTP Slow Request and TTFB in PCAP: Proving Whether the Delay Is DNS, TCP, TLS, or Server Time How to diagnose slow HTTP requests in packet captures by separating DNS delay, TCP handshake, TLS handshake, request upload, server processing, and time to first byte. Read article
- HTTP/2 GOAWAY and RST_STREAM PCAP Analysis: Debugging Reset Streams, Proxy Limits, and gRPC Failures How to diagnose HTTP/2 GOAWAY, RST_STREAM, gRPC unavailable errors, proxy stream limits, TLS ALPN negotiation, connection reuse, and packet capture evidence. Read article
- ICMP Destination Unreachable and Packet Too Big PCAP Analysis: What the Network Is Telling You How to analyze ICMP Destination Unreachable, Port Unreachable, Host Unreachable, Fragmentation Needed, Packet Too Big, policy filtering, and path MTU evidence in PCAP files. Read article
- MTU Black Hole and Fragmentation PCAP Analysis: Finding PMTUD Failures, MSS Problems, and Stalled TCP How to diagnose MTU black holes, path MTU discovery failure, TCP MSS mismatch, fragmentation, ICMP blocked messages, VPN tunnels, and stalled connections in packet captures. Read article
- NTP Clock Drift Packet Capture Analysis: Time Sync Failures, Offset, Delay, Jitter, and Firewall Issues How to analyze NTP time synchronization failures in packet captures, including offset, delay, jitter, missing responses, wrong servers, firewall blocks, and clock drift symptoms. Read article
- Packet Loss PCAP Analysis: Retransmissions, Duplicate ACKs, and Where Packets Disappeared How to use packet captures to diagnose packet loss, TCP retransmissions, duplicate ACKs, capture-point bias, and whether loss happened on the network or host. Read article
- PCAP Checksum Errors Are Not Always Bad Packets: Understanding Offload Evidence Why TCP, UDP, and IP checksum errors in packet captures can be caused by checksum offload, and how to avoid rewriting good evidence. Read article
- PCAP Timestamp Problems: When to Inspect, Normalize, or Rewrite Capture Time How to reason about bad PCAP timestamps, clock drift, capture ordering, and controlled timestamp rewrites without losing evidence. Read article
- PCAPNG vs PCAP: Why Interface Metadata and Timestamp Resolution Matter A practical explanation of PCAPNG versus PCAP for engineers who need capture metadata, timestamp resolution, and reproducible packet evidence. Read article
- QUIC and HTTP/3 Packet Capture Troubleshooting: Evidence Beyond Encrypted UDP Troubleshoot QUIC and HTTP/3 from a PCAP by reviewing UDP flow, timing, connection context, ICMP, TCP fallback, capture placement, and encryption limits. Read article
- SNI vs ALPN: TLS Handshake Analysis and HTTP/2 Negotiation in Wireshark PCAPs Analyze SNI vs ALPN in TLS handshakes. Diagnose HTTP/2 negotiation failure, h2 vs http/1.1 fallback, ClientHello extensions, ServerHello ALPN responses, and proxy termination issues in Wireshark PCAPs. Read article
- Split a Large PCAP and Extract One Conversation Without Losing Troubleshooting Context How to split large PCAP files, extract one TCP or UDP conversation, and preserve enough context for protocol troubleshooting. Read article
- TCP CLOSE_WAIT and FIN_WAIT PCAP Analysis: Finding Connection Leaks, Half-Closes, and Shutdown Bugs How to analyze TCP CLOSE_WAIT, FIN_WAIT, TIME_WAIT, half-close behavior, connection leaks, missing close calls, FIN packets, RST packets, and shutdown timing in packet captures. Read article
- TCP Keepalive and Idle Timeout PCAP Analysis: Firewalls, NAT, Load Balancers, and Long-Lived Connections How to analyze TCP keepalive packets, idle timeout, NAT session expiry, firewall connection drops, load balancer resets, long-lived API connections, and packet capture evidence. Read article
- TCP MSS Clamping and VPN PCAP Analysis: Finding Oversized Segments, MTU Mismatch, and Slow Tunnels How to analyze TCP MSS clamping problems in VPNs and tunnels, including SYN MSS values, MTU mismatch, oversized segments, retransmissions, fragmentation, and packet capture evidence. Read article
- TCP Out-of-Order vs Retransmission in PCAP: How to Tell Reordering from Packet Loss How to distinguish TCP out-of-order packets, retransmissions, duplicate ACKs, SACK blocks, delayed packets, packet loss, and capture artifacts in PCAP analysis. Read article
- TCP Retransmission and Duplicate ACK Analysis in PCAP Learn how to analyse TCP retransmissions, duplicate ACKs, fast retransmit, SACK, packet loss, and reordering in a PCAP without assigning blame beyond the evidence. Read article
- TCP RST and Connection Reset PCAP Analysis: Who Closed the Connection and Why How to analyze TCP RST, connection reset by peer, reset after SYN, reset during TLS, firewall resets, application closes, and packet capture evidence. Read article
- TCP SYN Retransmission and No SYN-ACK PCAP Analysis: Firewall, Routing, Server Down, or Asymmetric Path? Analyze TCP SYN retransmissions and missing SYN-ACK packets in a PCAP with capture-point limits, forward and return-path checks, firewall, route, NAT, listener, and asymmetric-path hypotheses, then create a bounded handoff. Read article
- TCP Window Scaling and Throughput PCAP Analysis How to analyze TCP window scaling, receive window limits, zero window, window full events, slow throughput, bandwidth delay product, and packet capture evidence. Read article
- TCP Zero Window PCAP Analysis: Finding Receiver Bottlenecks and Application Stalls How to read TCP Zero Window, Window Update, retransmission, and stalled application behavior in packet captures without blaming the wrong side. Read article
- TLS Certificate and Handshake Failure PCAP Analysis: Expired Certs, Alerts, SNI, and Connection Resets How to analyze TLS handshake failures in packet captures, including expired certificates, unknown CA, SNI mismatch, TLS alerts, ClientHello, ServerHello, and TCP resets. Read article
- TLS Handshake Failure PCAP Analysis: ClientHello, ServerHello, Alerts, Resets, and Evidence Diagnose a TLS handshake failure in a PCAP by locating the ClientHello, ServerHello, certificate, alert, reset, and capture-point evidence. Read article
- TLS SNI Mismatch PCAP Analysis: Wrong Certificate, Wrong Host, Proxy Routing, and Handshake Failure Use packet evidence to investigate a TLS SNI mismatch, wrong certificate, hostname error, reverse-proxy route, alert, or reset without overclaiming what a PCAP proves. Read article
- WebSocket Upgrade Failure PCAP Analysis How to troubleshoot WebSocket upgrade failures with packet captures, including HTTP 101, Upgrade headers, Connection headers, proxy stripping, TLS, resets, and idle timeouts. Read article