CapLoader is a Windows tool designed to handle large amounts of captured network traffic in the tcpdump/libpcap format (PCAP). CapLoader displays the contents of opened PCAP files as a list of TCP and UDP flows. Users can select the flows of interest and quickly filter out those packets from the loaded PCAP files. Sending the selected flows/packets to a packet analyzer tool like Wireshark or NetworkMiner is then just a mouse click away.
CapLoader is the ideal tool to use when handling big data PCAP files in sizes up to many gigabytes (GB). The contents of individual flows can be exported to tools like Wireshark and NetworkMiner in just a matter of seconds after having loaded one or multiple large PCAP files.
» Watch the CapLoader Demo Video «
» Buy CapLoader «
CapLoader with 2 GB of PCAP data loaded from Defcon 11
The typical process of working with CapLoader is:



CapLoader includes the ability to identify protocols without relying on port numbers (a feature often referred to as “traffic classification”). This feature can be enabled by checking the “Identify protocols” check-box in the GUI. Loading PCAP files with the “identify protocols” feature enabled will cause the application layer protocols of the extracted flows to be identified and displayed in the flow list. Being able to identify the application layer protocol is important in order to detect what services that run on non-standard ports as well as to detect if common ports are being used to transport other protocols than what might be expected.
The dynamic protocol identification feature allows for detection of over 100 protocols and sub-protocols. The identified protocols include Skype, IRC, FTP and SSH, MS-RPC, Poison Ivy RAT as well as several P2P and CardSharing protocols.
CapLoader showing port independent identification of protocols
| CapLoader Trial | CapLoader (professional edition) | |
|---|---|---|
| License Validity Period | 30 Days | 10 Years |
| Max PCAP Data Size | 500 GB | No limit |
| PcapNG Support |
|
|
|
Flow Transcript View
(a.k.a Follow TCP/UDP Stream) |
|
|
|
Port Independent Protocol Identification (PIPI) |
|
|
| OS Fingerprinting |
|
|
| Geo-IP Localization (*) |
|
|
| Select Flows from Log file |
|
|
| Price | Free | From € 900 EUR |
|
Download Free Trial
(no registration required) |
Buy CapLoader |
CapLoader requires Microsoft .NET Framework 4.0 to be installed.