D4

PCAP capture file signature

Magic number at the start of the file

D4 C3 B2 A1

A classic tcpdump/libpcap capture starts with a magic number that also encodes byte order: D4 C3 B2 A1 little-endian or A1 B2 C3 D4 big-endian. The newer pcapng format instead begins 0A 0D 0D 0A.

Hex signature
D4 C3 B2 A1
Offset
0 (start of file)
Length
4 bytes

What this magic number means

A magic number is a short, fixed run of bytes at a known position that tells a program what a file really is, no matter what the filename says. If a file starts with the bytes D4 C3 B2 A1, it is a PCAP capture file.

What each byte of D4 C3 B2 A1 means

Here is the signature byte by byte, the way a hex editor shows it: the position in the file, the value in hex and in decimal, and the character that value stands for in ASCII. Bytes with no printable character show a dot.

Byte offsetHexDecimalASCII
0D4212.
1C3195.
2B2178.
3A1161.

Signature variants

PCAP capture appears with more than one byte pattern. These all identify the same family:

Hex signatureOffsetNote
D4 C3 B2 A10little-endian, microsecond timestamps
A1 B2 C3 D40big-endian, microsecond timestamps
0A 0D 0D 0A0pcapng (next-generation) block

Formats that use the D4 C3 B2 A1 signature

These file types in our database carry this signature:

How to check a file's signature

You can read the bytes of any file yourself. They are shown in hex, the same way this page lists them.

Linux & macOS

  • xxd -l 16 example.pcap
  • hexdump -C -n 16 example.pcap
  • file example.pcap

Windows (PowerShell)

  • Format-Hex -Path example.pcap -Count 16

Python

  • open("example.pcap","rb").read(4).hex()

In your browser

Frequently asked questions

What is the PCAP capture file signature?

PCAP capture files start with the hex bytes D4 C3 B2 A1. This magic number identifies the format regardless of the file's name or extension.

How do I check a file's magic number?

Open the file in a hex editor, or run a command such as xxd -l 16 example.pcap on Linux or macOS, or Format-Hex -Path example.pcap -Count 16 in Windows PowerShell, and read the first bytes.

Can a file fake the PCAP capture signature?

Renaming a file does not change its bytes, so the extension can lie but the signature usually cannot. A genuine PCAP capture file has these exact bytes; a file with the wrong bytes is not really PCAP capture, whatever its name says.

Related signatures

Sources

Reuse this signature

This entry is part of the WhatFileType file signature reference, published under a CC BY 4.0 licence with the full provenance for every entry, a copy-paste embed and a JSON export. Credit WhatFileType and the data is yours to republish.