PCAP Surgery editions and export license

Community (free)

The full local review and planning workflow:

  • Open and view PCAP files
  • Filter packet evidence and inspect decoded/raw detail
  • Build and preview transformation rules
  • Preview timing changes, export scope, warnings, and privacy exposure

Professional

Everything in Community, plus artifact materialization:

  • Everything in Community
  • Write an edited classic PCAP
  • Write a filtered subset classic PCAP
  • Write a scope-aware artifact-review PDF

The license is a one-time purchase, not a subscription. The capture remains local. Professional does not add complete payload sanitization, automatic post-export reparse, or broader protocol decoding; the same limitations shown in preflight still apply.

Direct answer

Use Community to open an authorized classic PCAP, inspect packet evidence, build transformation rules, and preview the proposed output, scope, warnings, timing, and privacy exposure. Use Professional when the approved result must be materialized as an edited PCAP, filtered subset PCAP, or scope-aware review PDF. The paid feature is PCAP export; it is not a promise of complete sanitization or universal protocol support.

Stage Community Professional
Open and inspect the capture Yes Yes
Filter evidence and inspect decoded/raw fields Yes Yes
Build transformation rules Yes Yes
Preview output scope, timing, warnings, and exposure Yes Yes
Write edited classic PCAP No Yes
Write filtered subset classic PCAP No Yes
Write scope-aware review PDF No Yes

Preview and materialization are different

A Community preview answers what the configured operation intends to change, what packets are in scope, and what warnings remain. Professional materialization writes a new artifact from that approved plan. Neither stage should overwrite the source capture.

Keep the original immutable, write outputs to a separate explicit path, and record the operation, scope, version, time handling, and known limitations. Reopen the output in an independent packet tool when the case requires it. The current product does not claim automatic post-export reparse, so the operator owns that acceptance step.

Use the capture-scope guide before creating a subset and the PCAP Surgery overview for the investigation-to-export sequence.

Privacy and sanitization boundary

Removing or rewriting selected fields is not equivalent to complete payload sanitization. Raw payload, application content, names, addresses, identifiers, timestamps, checksums, derived metadata, and relationships among packets may still expose information. Review preflight warnings and the written artifact itself before sharing.

A Professional license grants the ability to materialize approved outputs; it does not grant permission to modify, possess, or distribute a capture. Follow the source owner’s authorization, incident policy, evidence-handling requirements, retention, and deletion rules.

License and export QA

  • The original capture is preserved and identifiable.
  • The desired transformation and packet scope are written down.
  • Community preview has been reviewed before any materialization.
  • Timing changes and selected output range are intentional.
  • Privacy warnings and remaining payload exposure are documented.
  • The output path cannot overwrite the original.
  • Professional is used only when an artifact must be written.
  • The edited or subset PCAP is reopened in an appropriate independent tool.
  • The PDF is checked for scope, labels, sensitive fields, and readability.
  • Recipient, authorization, retention, and deletion are known before handoff.
  • Current checkout terms are confirmed at PCAP Surgery licensing.

Frequently asked questions

Is Community useful without export?

Yes. It contains local inspection, filtering, rule construction, and transformation preview. That is the decision and review phase of the workflow.

Does Professional sanitize every packet automatically?

No. It writes the configured artifact. The documented limitations, raw payload exposure, and preflight warnings still apply.

Can Professional write pcapng?

This page claims edited and subset classic PCAP plus the review PDF. Do not infer an additional format without current product evidence.

Should I delete the source after export?

Not automatically. Follow the authorized evidence and retention policy. Preserve an immutable source when reproducibility or incident handling requires it, and never overwrite it during surgery.

Record the application version, source checksum, transformation plan, output checksum, reviewer, and test date so a later handoff can distinguish the original evidence from every derived artifact.

<!-- multilingual-help-closeout:start -->

Direct answer and acceptance boundary

For “PCAP Surgery editions and export license”, the short answer is: Community is free for local inspection and transformation previews. Professional is a one-time license for writing edited, subset, and PDF artifacts. Treat that statement as a result to verify, not as a promise that every input, device, project, or environment behaves identically. A complete result records the starting state, the exact action, the visible output, and the condition that proves the task is finished in PCAP Surgery.

Evidence-first operating procedure

Work from a small, repeatable case before changing a full project. Record the application version, operating system, input or device identity, relevant settings, and the expected result. Perform one deliberate action, preserve the first unexpected transition, and compare it with a known-good run whenever one is available. Changing several controls at once may hide which condition fixed or created the problem.

Checkpoint 1: PCAP Surgery editions and export license

Treat “PCAP Surgery editions and export license” as a separate acceptance gate for “PCAP Surgery editions and export license”. Record its initial state before acting, then capture the first visible change and the final state. If the result differs from the page’s stated outcome, return to the last confirmed checkpoint instead of continuing with assumptions.

Checkpoint 2: Community is free for local inspection and transformation previews. Professional is a one-

Verify “Community is free for local inspection and transformation previews. Professional is a one-time license for writing edited, subset, and PDF artifacts.” with the smallest representative input. Keep unrelated settings unchanged, repeat the same action once, and note whether the result is stable after reopening or reconnecting. A screenshot alone is weaker than a record that includes the input, setting, action, output, and time.

Checkpoint 3: Community (free)

For “Community (free)”, distinguish a product decision from an operating-system, hardware, source-file, permission, or workflow boundary. Confirm which layer supplied the evidence before assigning a cause. This prevents a nearby symptom from being reported as a proven root cause.

Checkpoint 4: Professional

Use “Professional” to define a pass/fail statement that another operator can repeat. Include what should be present, what must be absent, and what recovery action is safe if the check fails. Keep the original project or capture unchanged until the repaired copy has passed the same check.

Checkpoint 5: Direct answer

When “Direct answer” is ambiguous, compare one known-good case with one failing case under matching conditions. Mark the first meaningful difference rather than listing every later symptom. That first boundary usually produces a clearer support request and a safer next experiment.

Checkpoint 6: Preview and materialization are different

Close “Preview and materialization are different” only after the saved, exported, or reopened result still matches the observed state. Temporary UI feedback is useful, but durable evidence is stronger. Record any limitation that remains so the next reader does not interpret an incomplete path as a successful one.

Checkpoint 7: Privacy and sanitization boundary

Treat “Privacy and sanitization boundary” as a separate acceptance gate for “PCAP Surgery editions and export license”. Record its initial state before acting, then capture the first visible change and the final state. If the result differs from the page’s stated outcome, return to the last confirmed checkpoint instead of continuing with assumptions.

Checkpoint 8: License and export QA

Verify “License and export QA” with the smallest representative input. Keep unrelated settings unchanged, repeat the same action once, and note whether the result is stable after reopening or reconnecting. A screenshot alone is weaker than a record that includes the input, setting, action, output, and time.

Checkpoint 9: Frequently asked questions

For “Frequently asked questions”, distinguish a product decision from an operating-system, hardware, source-file, permission, or workflow boundary. Confirm which layer supplied the evidence before assigning a cause. This prevents a nearby symptom from being reported as a proven root cause.

Checkpoint 10: Is Community useful without export?

Use “Is Community useful without export?” to define a pass/fail statement that another operator can repeat. Include what should be present, what must be absent, and what recovery action is safe if the check fails. Keep the original project or capture unchanged until the repaired copy has passed the same check.

Acceptance matrix

Checkpoint Evidence to retain Pass condition
PCAP Surgery editions and export license Initial state, one action, and resulting state A second operator can reproduce the stated outcome
Community is free for local inspection and transformation previews. Professional is a one-time license for writing edite Initial state, one action, and resulting state A second operator can reproduce the stated outcome
Community (free) Initial state, one action, and resulting state A second operator can reproduce the stated outcome
Professional Initial state, one action, and resulting state A second operator can reproduce the stated outcome
Direct answer Initial state, one action, and resulting state A second operator can reproduce the stated outcome
Preview and materialization are different Initial state, one action, and resulting state A second operator can reproduce the stated outcome

Failure isolation, recovery, and handoff

If a check fails, stop at the first failed boundary. Preserve the source, project, session, or capture; duplicate it before destructive editing; and change one variable per experiment. Repeating a broad workflow after several simultaneous changes may produce a different result without explaining why.

Separate absence of evidence from evidence of absence. A blank view may mean the wrong input, scope, filter, permission, device, time range, or project state rather than “nothing happened.” Verify the acquisition or import path before interpreting a decoder, editor, report, or export.

Before handoff, reopen the durable artifact and inspect its beginning, the decision point, and its end. Record version, platform, relevant configuration, expected behavior, observed behavior, and the smallest reproduction. Remove or redact sensitive material and confirm the recipient is authorized to receive it.

Questions and answers

What is the fastest reliable way to start?

Use the smallest representative case, write down the expected result, and change one variable. Confirm the basic path before adding filters, effects, edits, automation, or a larger source. This creates a baseline that can be compared after every later decision.

What evidence should be saved?

Keep the input identity, application version, platform, relevant settings, exact action, first unexpected transition, and final output. If the workflow creates a project, session, report, or export, close and reopen it before treating it as durable evidence.

When should the procedure be repeated?

Repeat it after an application, operating-system, driver, firmware, model, source, or workflow change that can alter the result. Preserve the earlier accepted case so the comparison uses the same acceptance boundary rather than memory.

When is the task ready for handoff?

It is ready when another authorized person can identify the input, repeat the action, see the same result, understand any remaining limitation, and open the saved artifact without relying on undocumented local state.

Related guides

Continue with the same-language pages below. They cover adjacent stages without changing the canonical owner of this topic:

<!-- multilingual-help-closeout:end -->