Blogs
PCAP Surgery blogs
PCAP Surgery articles for debugging failures, reading evidence, and choosing the next step.
Isolate the flow that matters, preview controlled changes, and export a minimal repro or regression fixture without overwriting the source capture.
A local capture-transformation workbench for the step after Wireshark analysis and before vendor escalation or lab replay. It is not a live sniffer, a full protocol analyzer, or a complete payload-sanitization system.
This index is organized by real problems. Start with the symptom, check the evidence, then choose the next action.
Common starting points include:

PCAP editor
packet analyzer
anonymize PCAP
Latest articles
- A Truthful Packet-Capture Preparation Workflow How to turn a noisy capture into a focused support or QA artifact without confusing header repair with complete sanitization. Read article
- Best PCAP Editing Tools: Choose by Artifact, Not Feature Count An honest comparison of Wireshark, editcap, tcprewrite, TraceWrangler, Scapy, and PCAP Surgery for preparing support and regression artifacts. Read article
- Corrupt PCAP Triage: Preserve Evidence Before You Rewrite How to distinguish a damaged capture container from bad packet checksums, and where PCAP Surgery's repair scope stops. Read article
- PCAP Editing FAQ for Support and QA Engineers Straight answers about PCAP Surgery scope, checksums, privacy, formats, licensing, and tool choice. Read article
- PCAP File Analyzer vs Editor: Analyze First, Prepare the Artifact Second Understand what a PCAP file analyzer should prove, where Wireshark belongs, and when a focused PCAP editor is the safer tool for minimal support or regression artifacts. Read article
- PCAP Privacy Review: What Header Masking Does Not Remove A practical privacy checklist for packet captures and an explicit account of PCAP Surgery's current partial coverage. Read article
- PCAP Surgery vs editcap for Packet Artifact Preparation Compare a visual review workflow with mature CLI capture processing without overstating either tool. Read article
- PCAP Surgery vs TraceWrangler for Redaction and Handoff TraceWrangler is the deeper sanitization tool; PCAP Surgery is the reviewable artifact-preparation workflow. Read article
- PCAP Surgery vs Wireshark, editcap, and TraceWrangler An honest capability and workflow comparison for analysis, CLI processing, sanitization, and focused PCAP artifact preparation. Read article
- TraceWrangler Alternative? A Capture-Workflow Migration Test Test PCAP Surgery against a real TraceWrangler workflow with an acceptance corpus, exposure review, transformation preview, and output verification. Read article
- Visual editcap Alternative: Decide, Preview, and Verify a PCAP Handoff Choose between editcap automation and PCAP Surgery's visual review path, then verify packet selection, timing, transformations, and output integrity. Read article
- Asymmetric Routing and One-Sided PCAP Analysis How to analyze asymmetric routing and one-sided packet captures, missing replies, NAT/firewall paths, half conversations, capture point mistakes, and misleading retransmission evidence. Read article
- IPv6 DAD and Neighbor Solicitation PCAP Analysis How to analyze IPv6 Duplicate Address Detection, Neighbor Solicitation, Neighbor Advertisement, SLAAC failures, missing NA responses, duplicate IPv6 addresses, and no IPv6 connectivity in packet captures. Read article
- TCP CWR Flag and ECN PCAP Analysis: Diagnose CE, ECE, and Congestion Without Packet Loss Diagnose TCP CWR, ECE, and CE flags in Wireshark PCAPs. Covers ECN congestion without loss, ECN negotiation failure, and middlebox compatibility. Read article
- TCP Nagle and Delayed ACK PCAP Analysis How to analyze TCP Nagle algorithm and delayed ACK interactions in packet captures, small packet latency, request/response stalls, interactive protocol delays, and TCP_NODELAY evidence. Read article
- TCP SACK and DSACK in Wireshark: Diagnose Packet Loss, sack_perm Option, and Retransmission in PCAPs Diagnose TCP SACK, DSACK, and sack_perm options in Wireshark PCAPs. Covers selective acknowledgments, packet loss recovery, reordering, duplicate ACKs, and spurious retransmissions. Read article
- VLAN Tag Missing in PCAP Analysis: 802.1Q Tags, Native VLAN, Trunk Ports, Driver Stripping, and Wrong How to analyze missing VLAN tags in packet captures, 802.1Q tagging, native VLAN behavior, trunk port mistakes, driver tag stripping, capture filters, and VLAN mismatch failures. Read article
- ARP Duplicate IP Address Conflict PCAP Analysis How to diagnose duplicate IP address conflicts, ARP storms, gratuitous ARP, wrong MAC mappings, gateway confusion, and intermittent LAN failures in packet captures. Read article
- DHCP Failure PCAP Analysis: Discover, Offer, Request, ACK, NAK, and No IP Address Problems How to troubleshoot DHCP failure, no IP address, DHCP Discover without Offer, DHCP NAK, relay problems, VLAN issues, and packet capture evidence. Read article
- DNS Retransmission and Timeout PCAP Analysis: Finding Slow Resolvers, Lost Queries, and Broken Responses How to diagnose DNS timeout, retransmission, no response, SERVFAIL, UDP loss, TCP fallback, resolver latency, and application delay with packet captures. Read article
- DNS Timeout, NXDOMAIN, and SERVFAIL in PCAP: How to Tell Slow DNS from a Slow Server How to diagnose DNS timeouts, NXDOMAIN, SERVFAIL, repeated queries, and slow application startup using packet capture evidence. Read article
- HTTP 502 and 504 Gateway Timeout PCAP Analysis: Proxy, Load Balancer, Upstream, or Network? How to diagnose HTTP 502 Bad Gateway and 504 Gateway Timeout with packet captures, including proxy-to-upstream TCP, TLS, request timing, backend resets, and stalled responses. Read article
- HTTP Slow Request and TTFB in PCAP: Proving Whether the Delay Is DNS, TCP, TLS, or Server Time How to diagnose slow HTTP requests in packet captures by separating DNS delay, TCP handshake, TLS handshake, request upload, server processing, and time to first byte. Read article
- HTTP/2 GOAWAY and RST_STREAM PCAP Analysis: Debugging Reset Streams, Proxy Limits, and gRPC Failures How to diagnose HTTP/2 GOAWAY, RST_STREAM, gRPC unavailable errors, proxy stream limits, TLS ALPN negotiation, connection reuse, and packet capture evidence. Read article
- ICMP Destination Unreachable and Packet Too Big PCAP Analysis: What the Network Is Telling You How to analyze ICMP Destination Unreachable, Port Unreachable, Host Unreachable, Fragmentation Needed, Packet Too Big, policy filtering, and path MTU evidence in PCAP files. Read article
- MTU Black Hole and Fragmentation PCAP Analysis: Finding PMTUD Failures, MSS Problems, and Stalled TCP How to diagnose MTU black holes, path MTU discovery failure, TCP MSS mismatch, fragmentation, ICMP blocked messages, VPN tunnels, and stalled connections in packet captures. Read article
- NTP Clock Drift Packet Capture Analysis: Time Sync Failures, Offset, Delay, Jitter, and Firewall Issues How to analyze NTP time synchronization failures in packet captures, including offset, delay, jitter, missing responses, wrong servers, firewall blocks, and clock drift symptoms. Read article
- Packet Loss PCAP Analysis: Retransmissions, Duplicate ACKs, and Where Packets Disappeared How to use packet captures to diagnose packet loss, TCP retransmissions, duplicate ACKs, capture-point bias, and whether loss happened on the network or host. Read article
- PCAP Checksum Errors Are Not Always Bad Packets: Understanding Offload Evidence Why TCP, UDP, and IP checksum errors in packet captures can be caused by checksum offload, and how to avoid rewriting good evidence. Read article
- PCAP Timestamp Problems: When to Inspect, Normalize, or Rewrite Capture Time How to reason about bad PCAP timestamps, clock drift, capture ordering, and controlled timestamp rewrites without losing evidence. Read article
- PCAPNG vs PCAP: Why Interface Metadata and Timestamp Resolution Matter A practical explanation of PCAPNG versus PCAP for engineers who need capture metadata, timestamp resolution, and reproducible packet evidence. Read article
- QUIC and HTTP/3 Packet Capture Troubleshooting: What You Can Still Learn from UDP How to troubleshoot QUIC and HTTP/3 with packet captures by inspecting UDP flows, handshake timing, connection IDs, loss, fallback, and encrypted traffic boundaries. Read article
- SNI vs ALPN: TLS Handshake Analysis and HTTP/2 Negotiation in Wireshark PCAPs Analyze SNI vs ALPN in TLS handshakes. Diagnose HTTP/2 negotiation failure, h2 vs http/1.1 fallback, ClientHello extensions, ServerHello ALPN responses, and proxy termination issues in Wireshark PCAPs. Read article
- Split a Large PCAP and Extract One Conversation Without Losing Troubleshooting Context How to split large PCAP files, extract one TCP or UDP conversation, and preserve enough context for protocol troubleshooting. Read article
- TCP CLOSE_WAIT and FIN_WAIT PCAP Analysis: Finding Connection Leaks, Half-Closes, and Shutdown Bugs How to analyze TCP CLOSE_WAIT, FIN_WAIT, TIME_WAIT, half-close behavior, connection leaks, missing close calls, FIN packets, RST packets, and shutdown timing in packet captures. Read article
- TCP Keepalive and Idle Timeout PCAP Analysis: Firewalls, NAT, Load Balancers, and Long-Lived Connections How to analyze TCP keepalive packets, idle timeout, NAT session expiry, firewall connection drops, load balancer resets, long-lived API connections, and packet capture evidence. Read article
- TCP MSS Clamping and VPN PCAP Analysis: Finding Oversized Segments, MTU Mismatch, and Slow Tunnels How to analyze TCP MSS clamping problems in VPNs and tunnels, including SYN MSS values, MTU mismatch, oversized segments, retransmissions, fragmentation, and packet capture evidence. Read article
- TCP Out-of-Order vs Retransmission in PCAP: How to Tell Reordering from Packet Loss How to distinguish TCP out-of-order packets, retransmissions, duplicate ACKs, SACK blocks, delayed packets, packet loss, and capture artifacts in PCAP analysis. Read article
- TCP Retransmissions and Duplicate ACKs in PCAP: How to Read the Pattern Before Blaming the Server How to interpret TCP retransmissions, duplicate ACKs, fast retransmits, and out-of-order packets in packet captures without jumping to the wrong owner. Read article
- TCP RST and Connection Reset PCAP Analysis: Who Closed the Connection and Why How to analyze TCP RST, connection reset by peer, reset after SYN, reset during TLS, firewall resets, application closes, and packet capture evidence. Read article
- TCP SYN Retransmission and No SYN-ACK PCAP Analysis: Firewall, Routing, Server Down, or Asymmetric Path? How to analyze TCP SYN retransmissions, missing SYN-ACK, SYN_SENT, server unreachable, firewall drops, routing problems, asymmetric paths, and connection timeout in PCAP files. Read article
- TCP Window Scaling and Throughput PCAP Analysis How to analyze TCP window scaling, receive window limits, zero window, window full events, slow throughput, bandwidth delay product, and packet capture evidence. Read article
- TCP Zero Window PCAP Analysis: Finding Receiver Bottlenecks and Application Stalls How to read TCP Zero Window, Window Update, retransmission, and stalled application behavior in packet captures without blaming the wrong side. Read article
- TLS Certificate and Handshake Failure PCAP Analysis: Expired Certs, Alerts, SNI, and Connection Resets How to analyze TLS handshake failures in packet captures, including expired certificates, unknown CA, SNI mismatch, TLS alerts, ClientHello, ServerHello, and TCP resets. Read article
- TLS Handshake Failure in PCAP: ClientHello, ServerHello, Certificate, Alert, and Reset Evidence How to diagnose TLS handshake failures in packet captures by reading ClientHello, ServerHello, certificate, alert, and TCP reset evidence. Read article
- TLS SNI Mismatch PCAP Analysis: Wrong Certificate, Wrong Host, Proxy Routing, and Handshake Failure How to diagnose TLS SNI mismatch, wrong certificate, hostname mismatch, reverse proxy routing errors, ClientHello SNI, certificate validation failures, and packet evidence. Read article
- WebSocket Upgrade Failure PCAP Analysis How to troubleshoot WebSocket upgrade failures with packet captures, including HTTP 101, Upgrade headers, Connection headers, proxy stripping, TLS, resets, and idle timeouts. Read article