| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| checksums.txt | 2026-09-24 | 316 Bytes | |
| netcap-nodpi-v0.9.13-darwin-arm64.tar.gz | 2026-09-24 | 32.4 MB | |
| netcap-nodpi-v0.9.13-windows-amd64.tar.gz | 2026-09-24 | 34.2 MB | |
| netcap-v0.9.13-darwin-arm64.tar.gz | 2026-09-24 | 32.5 MB | |
| README.md | 2026-09-24 | 3.8 kB | |
| v0.9.13 source code.tar.gz | 2026-09-24 | 311.3 MB | |
| v0.9.13 source code.zip | 2026-09-24 | 313.1 MB | |
| Totals: 7 Items | 723.5 MB | 8 | |
๐ฆ Available Builds
| Build | OS | Architecture | DPI Support | Description |
|---|---|---|---|---|
netcap-v0.9.13-darwin-arm64 |
macOS | ARM64 | โ Yes | Full DPI support with nDPI |
netcap-v0.9.13-linux-amd64-libc |
Linux | AMD64 | โ Yes | glibc-based with DPI |
netcap-v0.9.13-linux-amd64-musl |
Linux | AMD64 | โ Yes | musl-based with DPI (Alpine) |
netcap-nodpi-v0.9.13-darwin-arm64 |
macOS | ARM64 | โ No | Static build, no DPI |
netcap-nodpi-v0.9.13-linux-amd64-libc |
Linux | AMD64 | โ No | glibc-based, no DPI |
netcap-nodpi-v0.9.13-linux-amd64-musl |
Linux | AMD64 | โ No | musl-based, no DPI |
netcap-nodpi-v0.9.13-windows-amd64 |
Windows | AMD64 | โ No | Windows build |
๐ Choosing the Right Build
- With DPI (
netcap-*): Choose if you need Deep Packet Inspection features (protocol classification, application detection) - Without DPI (
netcap-nodpi-*): Choose for basic packet capture and analysis, smaller binary size - libc vs musl: Use
libcfor standard Linux distros (Ubuntu, Debian, CentOS). Usemuslfor Alpine Linux or minimal containers
Installing on macOS via homebrew
Builds distributed via homebrew are built with DPI support. You need to install the libprotoident and ndpi libraries via homebrew.
$ brew install libprotoident ndpi
$ brew tap dreadl0ck/formulas
$ brew install netcap
Afterwards try running 'net' in your terminal.
๐ Documentation
โ ๏ธ Notes
- On macOS/Linux, you may need to grant necessary permissions:
sudo chmod +x net - Live capture requires root/administrator privileges
- Verify checksums with
checksums.txtbefore use
Changelog
- f98841eb Claim midstream conversations again: detection was run on zero bytes
- 9126800f Correct the record on f98841eb, and document how decoder selection can fail
- 75534c13 Decode selection existed twice, and the two copies had drifted
- d41c9cd1 Fix the DNP3-SA framing in the IEC 62351 reader, and stop guessing at objects
- c768814b Fix three CodeQL alerts: two quadratic regexes and an unrestricted GITHUB_TOKEN
- 82c5a848 Fix two misspellings in the QUIC confidence comment
- 5c304742 Give IEC 62351 records their own time and direction, on all four paths
- 4f7a52c7 Give records their own timestamp and the direction they travelled in
- e0c77f65 Measure the timestamp and direction defects across every reader
- 11f74352 Measure which decoder claims which protocol, for all 29
- 86c56002 Pick the decoder that required the most evidence, not the one with the low port
- 6638eff7 Rank a guessed QUIC header below a structural one, and restore protobuf over UDP
- 145f5bb8 Repair GitHub links broken by the relayout, and three that predate it
- ffcdecb5 Report every stream decoder in util -decoders, and drop the dead Modbus layer
- cbca6115 Rewrite the DNP3 decoder: it was reporting frames and objects nobody sent
- 4ad2019f Stop four decoders claiming ICS traffic they cannot parse
- a671d8f1 Stop parseDNP3SAObject restating the name table it is handed
- a299deee Timestamp each FTP, IMAP and IRC message from the packet that carried it
- 08115d7d Timestamp each HTTP request and response, not each connection
- 7e47da36 Validate the whole TACACS+ and SSH signatures, and test the confusable cases
- c767d38c netcap-ui 0.9.5
- 9e91ddc6 v0.9.13 release
Full Changelog: https://github.com/dreadl0ck/netcap/compare/v0.9.12...v0.9.13