PCAPdroid
com.emanuelef.remote_capture
Zapstore _@zapstore.dev Republished from GitHub / F-Droid by the Zapstore main account.
PCAPdroid is a privacy-friendly open source app which can track, analyze and block the connections made by the other apps on the device. It can also export a PCAP dump of the traffic, inspect HTTP requests, decrypt TLS traffic and much more. PCAPdroid simulates a VPN in order to capture the network traffic without root. It does not use a remote VPN server, instead data is processed locally on the device. Main features: - Log and analyze the connections made by user and system apps - Get a summary of how much data each app sent and received - Low battery usage for continuous, all-day capture - Extract hosts and IP addresses from DNS, TLS and HTTP - Record the traffic to PCAP files with additional app metadata - Send traffic via PCAP-over-IP for real-time analysis (e.g. on Wireshark) - Decrypt the HTTPS/TLS traffic, extract the URLs and save the SSLKEYLOGFILE - Inspect the HTTP requests/replies and export them to HAR - Identify the country and ASN of the remote server via offline DB lookups - On rooted devices, capture the traffic while other VPN apps are running Paid features: - Firewall: create rules to block individual apps, domains and IP addresses - Malware detection: detect malicious connections by using third-party blacklists - PcapNG format: makes it easier to export and analyze decrypted traffic If you plan to use PCAPdroid to perform packet analysis, check out [the specific section](https://www.google.com/url?q=https%3A%2F%2Femanuele-f.github.io%2FPCAPdroid%2Fquick_start%2314-packet-analysis&sa=D&sntz=1&usg=AOvVaw1IjDnDKpBGs-bgW8QYho9B) of the manual. Join the international PCAPdroid community [on Telegram](https://www.google.com/url?q=https%3A%2F%2Ft.me%2FPCAPdroid&sa=D&sntz=1&usg=AOvVaw1Dw0NGQLBMQEykPKv4D5ia) or [on Matrix](https://www.google.com/url?q=https%3A%2F%2Fmatrix.to%2F%23%2F%2523pcapdroid%3Amatrix.org&sa=D&sntz=1&usg=AOvVaw13G9ty-yeGOKgbaZT53Vpw).
First release: Sep 3, 2025, 6 total releases.
Most recent release: Sep 20, 2026.
Appears in 5 app stacks.
0 sats / 0 zaps received in the past year.
Sats Received
Underlying data available via MCP: app_zaps, app_releases.
Zap Count
Underlying data available via MCP: app_zaps, app_releases.
Releases
- Sep 20, 2026 2.0.2- Fix leaked connections listener causing IllegalStateException - Fix out-of-memory crash on large pcap files load with full payload enabled - Harden import settings to prevent crashes and protect from social engineering - Minor fixes and improvements
- Sep 9, 2026 2.0.1- Update maltrail malware blacklist URL - Bump mitm addon to 2.4, fixes decryption with root - Fix null mitm certificate after export on some devices (#887) - Fix firewall not working with always-on VPN when root capture is enabled - Fix other inconsistencies when running via always-on VPN / from Intent - Fix possible crash in ConnectionsFragment
- Feb 22, 2026 1.9.1- Fix minor crashes - Switch to facebook zstd and build from the source
- Feb 12, 2026 1.9.0- New HTTP requests view - Export HTTP data in the HAR format - Add Portuguese (BR) translation - Support the zstd compression - Fix HTTP/2 handling (possible mismatch of requests and replies) - Fix WebSocket data loading from PCAP file - Fix buffer overruns and leaks when decrypting PCAP files - New language selector on Android 12 and below - Select and export individual connections - Pretty-print JSON in HTTP data
More…
- Support using domain names in port mapping - Add toggle to show system apps - Export data in background threads to avoid UI hangs - Fix ushark crash on x86_64 when decrypting PCAP files (F-Droid only) - - Support 16 KB page size devices - Make PCAP/CSV file name prefix configurable - Fix possible invalid Pcapng block length with root - New API options: full_payload, keylog filename, decryption rules (credits: c4rl2s0n)
- - Support 16 KB page size devices - Make PCAP/CSV file name prefix configurable - Fix possible invalid Pcapng block length with root - New API options: full_payload, keylog filename, decryption rules (credits: c4rl2s0n)