When to use this page
PCAP Surgery is built for focused desktop work rather than a cloud account workflow. Use this page when you need the latest installer, want to confirm platform support, or need a stable link before activating a license.
Download the current desktop build of PCAP Surgery. This page is the official download entry for users who want to install, evaluate, or update the application.
PCAP Surgery is built for focused desktop work rather than a cloud account workflow. Use this page when you need the latest installer, want to confirm platform support, or need a stable link before activating a license.
Check that your operating system matches the available build. If SmartScreen, Gatekeeper, antivirus software, or an endpoint policy blocks the app, verify that the installer came from this page and review the release notes before retrying.
A license is not required just to read this page. If the product requires activation after install, use the license page for email, license key, offline use, and machine transfer details.

PCAP Surgery improves capture editing with a resizable packet-details workspace and consistent Investigate, Surgery, and Export controls.
Use the NSIS setup executable for the Windows desktop build.
c2103084f2e5d730412ae1da1e9d4f7b430e9ccdbafdc10063d5e67a46c0b968 DownloadUse the DEB package on Debian/Ubuntu, RPM on Fedora/RHEL, or AppImage when you want a portable build.
ded0ba993919970ce54d7cda25097b5bae91f37338f57cc59dc628f4e1ddcccc Download9b99a725ca16f154c63c15795afbe279bfb6d193b8e4f1091cde374063559692 Downloadee71a5ea7632f143065769ed65fe0582928bd9fab6be27fdb9ffd9d0ecf43421 DownloadPCAP repair and editing
Isolate the flow that matters, preview controlled changes, and export a minimal repro or regression fixture without overwriting the source capture.
A local capture-transformation workbench for the step after Wireshark analysis and before vendor escalation or lab replay. It is not a live sniffer, a full protocol analyzer, or a complete payload-sanitization system.
Open classic PCAP and basic single-interface Ethernet PCAPNG, then index packet metadata without uploading capture content.
Filter by protocol, endpoint, direction, packet number, time range, and text while preserving a dense packet table.
Inspect Ethernet, IP, TCP, UDP, DNS, ICMP, ARP, payload bytes, offsets, and copyable evidence for the selected packet.
Linux users can choose DEB, RPM, or AppImage. Windows users can install with the setup executable.
Use the SHA-256 value beside each artifact to verify downloaded packages before installation.
Paid desktop capabilities activate online in the app with Email + License Key after purchase.