PCAP Editor

pcap

Browser-based PCAP editor with Wireshark dissection and a Python (Scapy / Pycrate) editor.

Load a PCAP, edit any field in the dissection tree, hex view, or generated Python (Scapy / Pycrate via Pyodide), then export. 100+ protocols supported. Runs entirely in the browser.

A client-side editor for packet captures. Dissects packets with Wireshark's WASM engine, lets you edit fields in a Wireshark-style tree, raw hex, or human-readable Python code generated with Scapy and Pycrate via Pyodide, then re-encodes and exports a modified PCAP. Covers 100+ protocols across networking, telecom, industrial, automotive, IoT, and enterprise stacks.

What it does

  • Dissects packets with Wireshark-style structure for direct field editing.
  • Hex editor for raw byte manipulation.
  • Python editor: emits Scapy / Pycrate code layer-by-layer for human-readable editing and regeneration (Pyodide WASM runtime).
  • Filters packets with Wireshark display-filter syntax.
  • Generates malformed or edge-case variants for parser and detection testing.
  • Supports iterative test / replay cycles, export modified PCAPs for replay.

Best for

  • Researchers building protocol fuzzing scenarios.
  • Detection engineers validating signature coverage.
  • Trainers crafting reproducible packet examples.

Protocols: Ethernet, IP, IPv6, TCP, UDP, SCTP, ICMP, ARP, DNS, DHCP, BGP, OSPF, MPLS, GRE, VXLAN, L2TP, IPSec, MQTT, CoAP, ZigBee, 6LoWPAN, LoRaWAN, Modbus, DNP3, IEC 104, MMS (IEC 61850), UDS, DoIP, SOME/IP, M3UA, M2UA, MTP3, ISUP, SCCP, TCAP, MAP, CAMEL, Diameter, GTP, GTPv2, PFCP, S1AP, NGAP, NAS-5G, NAS-LTE, SMS, SIP, RTP, RTSP, HTTP, HTTP/2, TLS, SSH, Kerberos, LDAP, RADIUS

Inputs: PCAP, PCAPNG, Wireshark display filters

Outputs: Modified PCAP, Generated Scapy / Pycrate Python code