Page 1 of 1

TraceWrangler - network capture file toolkit

Posted: Sat Dec 19, 2015 4:15 am
by I am Baas
TraceWrangler is a network capture file toolkit running on Windows (or on Linux, using WINE) that supports PCAP as well as the new PCAPng file format

Features

•utility to read, write and modifiy PCAPng files
•Sanitization/Anonymization/Scrubbing of packet captures created by Wireshark/TCPDump/etc.
•Editing packets in batch, especially by removing certain protocol layers like MPLS, GRE or GTP-u, or to convert Linux cooked captures to Pseudo-Ethernet
•Merging capture files, especially PCAPng files with more than one interface and using filters to keep only certain frames
•Gathering and aggregating packet details about a large number of capture files, like IP, TCP and UDP conversations
•Displaying the PCAPng specific block structure of a file
•extracting conversations from multiple files to new capture files, based on manual filters, capture file indicator frames, or Snort alerts
https://www.tracewrangler.com/

Image

Settings in \AppData\Roaming\TraceWrangler