Captured signal. Preserved evidence.
See what your game is saying.
Your machine is already exchanging thousands of packets a second while you play. fragcap makes them readable: which process, which endpoint, how many bytes, right now. It reads traffic and never writes it — no injection, no modification, no automation, nothing hidden.
One worked invocation
Capture, filtered by process
$ fragcap --process game.exe --filter "udp.port == 27015" --out session.pcapng
interface Ethernet 2
attributed game.exe (pid 8412)
filter udp.port == 27015
writing session.pcapng
OUT
10.0.0.99:51820 → 172.16.10.12:27015
game.exe
1 314 B
Captured
IN
172.16.10.12:27015 → 10.0.0.99:51820
game.exe
208 B
Captured
IN
172.16.10.12:27015 → 10.0.0.99:51820
game.exe
1 460 B
Inspect
OUT
10.0.0.99:51821 → unknown
unattributed
0 B
Failed
Before you start
Prerequisites and limitations
Stated up front, where they are still useful. Supported behaviour, inferred behaviour and unknown behaviour are distinguished throughout the documentation.
Prerequisite
Packet capture requires an Npcap-compatible capture driver.
Limitation
Encrypted payloads remain opaque unless a supported decoder can derive the required session context.
Unknowns
Traffic that cannot be attributed to a process is labelled unattributed, never guessed.
Session filter
Narrow the capture
Only interfaces the driver exposes are listed.
Attribution is per-process, not per-port.
Path is not writable. Capture will not start.