By extracting the time from an NTP packet the time skew can be determined between the frame timestamp in the pcap and the NTP server. This can be important to know in a forensic investigation when determining a timeline. Kudos to Steffen for the idea.