Last updated:

Sample Captures

Load a capture and start analyzing!

PacketSnitch is compatible with both pcap and pcapng style captures. Download any of the samples below and drag the file onto the PacketSnitch window to begin analysis.

Note: Some of these captures are for internal testing purposes, and their protocols have varying compatibility coverage inside PacketSnitch. Some may even crash PacketSnitch or produce unexpected results! You have been warned.

Protocol Samples

File MD5 Description
HTTP with gzip compression 6cfbd9db24ca68725001049e9966419f Raw HTTP flow with gzip-compressed response bodies
HTTP with embedded images 0177a63e51292716b8a2b0afbcc9375b HTTP responses containing JPEG images to carve
FTP traffic with credentials 456fc04c32d5d3c4647ff113fddc38f8 FTP login and file transfer — clear-text creds exposed
FTP brute-force attempt 4061f02e2957cf71f8961fbce89ef36e Dictionary attack against an FTP server
BGP packets b0d4507a4a8e3a4700db67c8ff06b88f BGP update and keepalive messages from a router
DHCP discover/offer/ack 350a4a71b742023fcfed000c5f664fd6 DHCP exchange — see PacketSnitch’s DHCP decoder in action
SIP call setup (pcapng) 3ba94a8671d4784bc3352cf0d14904b3 VoIP SIP/SDP exchange — rtp, sdp, and sip keys all fire
SSH v2 session c101f3c6a8c79303742a1284433462a0 Encrypted SSH session — see protocol-aware dissection
SMB file transfer cd6061fcdf3ac536dafec38658c73ad9 SMB read/write — PacketSnitch extracts filenames and offsets
SMTP with attachments c06e944f3cc2c3f305bb37e23cfd6908 SMTP session — decoded MIME parts and extracted binaries
IMAP login and mailbox fetch f72b6bc0dfc3ef7ac5f1bf59f5edbe3a IMAP plain-text login and message fetch
LDAP bind and search 1210ce289623fdd9dd2ff8150662e890 LDAP bind request/response — Active Directory enumeration
MQTT connect/publish/subscribe c7791405c29a17497d4b29f47ed49ef1 MQTT IoT protocol exchange
SCTP chunked data 44a09ed7583c769a02ab7e6221c5c7d1 SCTP multi-stream — PacketSnitch’s SCTP decoder
PPP LCP & IPCP a7deafac29133719a1f2ec06e22af3b5 PPP link control and IP control protocol
PPPoE discovery & session 227cdf9cfaa307dfea39d1010d2dc6a5 PPP over Ethernet — see the PPPoE PADI/PADO flow
IGMP join/leave bb5501c21908d1a54c9157a02744bc30 IGMP group membership — multicast routing analysis
LLDP chassis & port IDs 8d14875117ce3d6036814835965c242e LLDP — neighbor discovery, chassis ID, port description
ATM (DSL modem) 676f2b36fbd3a7e42bcadc4ad3cd0e83 ATM AAL5 frames from a DSL modem — legacy carrier analysis
DSL PPPoA ATM 676f2b36fbd3a7e42bcadc4ad3cd0e83 Same ATM capture, PacketSnitch handles both PPPoA and AAL5
BitTorrent peer exchange 142d80fe1acfe7e88bffe4797a1414d2 BitTorrent handshakes and piece requests
Port scan detection 06b5133060b01f1e89629d81e8a08347 SYN scan against a single host — PacketSnitch flags it
Exploit/payload delivery 953deec4527c812b458096857e6741cb Shellcode and exploit traces — threat intel hits
USB keystroke injection 0a6c81d840a705166886181e9f9190f8 USB keystroke data captured from a rubber ducky payload
WEP-encrypted WiFi aa5cd8c71d785e77b59de75920b9d415 WEP traffic with a known key — PacketSnitch decrypts and decodes
WiFi Coherer/Induction 69fee8d6662c1265b6b9668a04070006 Historical wireless experiment capture
SMBv2/RPC over SMB cd6061fcdf3ac536dafec38658c73ad9 Large SMB transfer — PacketSnitch carves the transferred files
IPv4/IPv6 misc captures 53e22d7c0f66e135b64733cc731b265f Mixed IPv4/IPv6 traffic, various protocols
Large mixed capture 01107032d121dbcae06ea8b88515933b 25 MB mixed enterprise capture — stress-test the chunker UI
Small mixed capture c3fbe593362473fad774a9ce71fbc001 411 KB mixed capture with assorted protocols

If you want to test anything else, a great resource is the Wireshark Sample Captures Page.

Have fun!

See also