Npcap

1mos agoupdate 2 0 0

Npcap is a packet capture (and sending) library for Windows by the Nmap Project. It implements the open Pcap API using a custom Windows kernel driver alongside our Window...

Location:
United States
Collection time:
2025-09-29

Npcap is a packet capture and injection library for Windows by the Nmap Project. It is a complete update to the unmaintained WinPcap project with improved speed, reliability, and security.Npcap offers:Loopback Packet Capture and Injection: Npcap is able to sniff loopback packets (transmissions between services on the same machine) by using the Windows Filtering Platform (WFP). After installation, Npcap supplies an interface named NPF_Loopback, with the description “Adapter for loopback capture”. Wireshark’s users can choose this adapter to capture all loopback traffic the same way as other non-loopback adapters. Packet injection works as well with the pcap_inject() function.Support for all Windows Releases and architectures: Npcap works on Windows 7 and later by making use of the new NDIS 6 Light-Weight Filter (LWF) API. Also, the driver is signed with our EV certificate and countersigned by Microsoft so that it works even with the stricter driver signing requirements imposed by Windows 10. Starting with version 1.50 Npcap supports the new Windows on ARM architecture.Libpcap API: Npcap uses the excellent Libpcap library, enabling Windows applications to use a portable packet capturing API that is also supported on Linux and MacOS. Npcap includes the latest Libpcap release along with all the improvements.Extra Security: Npcap can (optionally) be restricted so that only Administrators can sniff packets. It also has the Windows ASLR and DEP security features enabled and signed driver, DLLs, and executables to prevent tampering.WinPcap compatibility: For applications that don’t yet make use of Npcap’s advanced features, Npcap installs in “WinPcap Compatible Mode” by default. Which replaces any old WinPcap software installs with its own drivers.Raw (monitor mode) 802.11 wireless capture: Npcap can be configured to read raw 802.11 traffic, including radiotap header details, and this functionality is directly supported by Wireshark.

data statistics

Relevant Navigation