Captured signal. Preserved evidence.

See what your game is saying.

Your machine is already exchanging thousands of packets a second while you play. fragcap makes them readable: which process, which endpoint, how many bytes, right now. It reads traffic and never writes it — no injection, no modification, no automation, nothing hidden.

One worked invocation

Capture, filtered by process

$ fragcap --process game.exe --filter "udp.port == 27015" --out session.pcapng interface Ethernet 2 attributed game.exe (pid 8412) filter udp.port == 27015 writing session.pcapng
OUT 10.0.0.99:51820 → 172.16.10.12:27015 game.exe 1 314 B Captured
IN 172.16.10.12:27015 → 10.0.0.99:51820 game.exe 208 B Captured
IN 172.16.10.12:27015 → 10.0.0.99:51820 game.exe 1 460 B Inspect
OUT 10.0.0.99:51821 → unknown unattributed 0 B Failed
Before you start

Prerequisites and limitations

Stated up front, where they are still useful. Supported behaviour, inferred behaviour and unknown behaviour are distinguished throughout the documentation.

Prerequisite

Packet capture requires an Npcap-compatible capture driver.

Limitation

Encrypted payloads remain opaque unless a supported decoder can derive the required session context.

Unknowns

Traffic that cannot be attributed to a process is labelled unattributed, never guessed.

Session filter

Narrow the capture

Only interfaces the driver exposes are listed.
Attribution is per-process, not per-port.
Path is not writable. Capture will not start.