Open-source project
emanuele-f/PCAPdroid avatar
emanuele-f/PCAPdroid

PCAPdroid: no-root packet capture on Android, and what it will not do

No-root network monitor, firewall and PCAP dumper for Android

4,847 stars553 forksJavaGPL-3.0

At a glance

What is it?
PCAPdroid captures Android app traffic through a local VPN interface, dumps it to PCAP and can decrypt TLS. It is the closest thing to Wireshark on a phone, with platform limits worth knowing before you install it.
Who is it for?
Adopt PCAPdroid if you need to see what an Android app is talking to and you cannot or will not root the device; the local VPN capture, PCAP export and PCAP-over-IP streaming cover most troubleshooting work. Skip it if you need a Windows or iOS capture client, or if you expect the firewall, malware detection and PCAPng export without paying, since the README lists those as paid features.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 4 days ago.
What is it written in?
Mainly Java, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem PCAPdroid solves on an unrooted phone

Android gives a normal app no way to see packets belonging to other apps. On a Linux desktop you reach for tcpdump or Wireshark; on a stock phone there is no shell and no raw socket permission. PCAPdroid works around this by presenting itself as a VPN. The README is explicit that no remote server is involved: "it does not use a remote VPN server, instead data is processed locally on the device." Android routes app traffic through the VPN interface, PCAPdroid reads it there, and the packets never leave the handset unless you deliberately export them.

The audience is narrow but real. Mobile developers who need to confirm which endpoint a build actually hits. Security reviewers checking what a third-party app phones home with. Support engineers who cannot reproduce a customer complaint on a desktop. The README also points at a second use: "if you plan to use PCAPdroid to perform packet analysis, check out the specific section of the manual." That sentence is a useful signal. The project expects two kinds of users, people who want a connection list and people who want a capture file, and the documentation splits accordingly.

How the local VPN capture and PCAP export actually work

Three components do the work, and the README names all three. nDPI provides deep packet inspection and the connection metadata, so the app can label a flow as TLS, HTTP or DNS and extract hostnames from those protocols. zdtun is described as a "minimal TCP/IP stack for the non-root capture", which is what lets the app terminate and forward traffic it intercepts through the VPN interface. mitmproxy runs as a local proxy for TLS decryption.

That last point is the interesting design decision. Decryption is not done by PCAPdroid itself; it delegates to mitmproxy, which means the app has to install or coordinate a certificate authority so the proxy can present certificates the target app will accept. The README lists the payoff: "decrypt the HTTPS/TLS traffic, extract the URLs and save the SSLKEYLOGFILE." The SSLKEYLOGFILE matters more than the inline decryption for many workflows, because you can capture encrypted traffic on the phone and hand the key log to Wireshark on a desktop later.

Output paths are equally concrete. Traffic can be recorded to PCAP files "with additional app metadata", or streamed live: "send traffic via PCAP-over-IP for real-time analysis (e.g. on Wireshark)." PCAP-over-IP is the one to reach for when you are debugging a live session, because the file never has to be copied off the device. HTTP requests and replies can be inspected in the app and exported to HAR.

One architectural note the README states plainly: on rooted devices PCAPdroid "can capture the traffic while other VPN apps are running." On an unrooted device it cannot, because Android permits only one active VPN. That is a platform constraint, not a bug.

Installing PCAPdroid and running a first capture

The README offers two distribution channels, F-Droid and Google Play, plus a Beta repository at pcapdroid.org/fdroid/repo/ for pre-release features. There is no desktop installer. The related searches include "pcapdroid for windows" and "pcapdroid for ios", and the README answers both implicitly: the app is an Android package, and the Windows side of the workflow is Wireshark receiving a stream or opening an exported file.

If you build from source instead of installing a release, the README gives this sequence. Submodules must be populated first or the native components will be missing.

bash
git clone https://github.com/emanuele-f/PCAPdroid
cd PCAPdroid
git submodule update --init

After that you open the project in Android Studio, install the SDK and the NDK, and build. The README flags one common failure: if you get "No valid CMake executable was found", install the CMake version the project uses, which the README says is currently 3.22.1 and points to app/build.gradle for the authoritative value.

For a first capture on a device, the flow described in the README is: start the capture, which brings up the VPN interface, watch the connection list populate with per-app entries, and use the summary view to see how much data each app sent and received. To move the capture to a desktop for analysis, either record to a PCAP file and copy it off, or enable PCAP-over-IP and point Wireshark at the stream. The README does not document a rollback or undo path for a capture session; you stop the capture and the VPN interface goes away.

If you are integrating rather than using the app, the README describes two routes. On rooted devices the pcapd daemon under app/src/main/jni/pcapd can be embedded directly in your APK. On any device, PCAPdroid "exposes an API to control the packet capture and send the captured packets via UDP to your app", and that route requires PCAPdroid to be installed alongside yours.

Where PCAPdroid stops being the right tool

The single biggest limitation is the one Android imposes: one VPN at a time. If the device already runs a corporate VPN or a consumer privacy VPN, PCAPdroid cannot capture alongside it unless the device is rooted. The README states the rooted case as the exception, which confirms the unrooted case is blocked. Anyone whose test device is managed by an MDM with an always-on VPN should stop here.

TLS decryption has a similar shape. It depends on mitmproxy and on the target app trusting the proxy certificate. Apps that pin certificates will not cooperate, and the README does not claim otherwise. The SSLKEYLOGFILE export is the more reliable path for those cases, but it only helps if you can decrypt offline with the key log, which rules out inspecting a flow in real time on the phone.

There is also a feature boundary that surprises people. The README separates three capabilities into a paid tier: the firewall for blocking apps, domains and IP addresses; malware detection via third-party blacklists; and PCAPng export, which the README says "makes it easier to export and analyze decrypted traffic." Plain PCAP capture is free, PCAPng is not. If your downstream tooling expects PCAPng, budget for it or plan a conversion step.

Finally, the project is Android only. There is no iOS build and no Windows client. The related searches for both are answered by the platform, not by a port.

PCAPdroid compared with tcpdump and Wireshark on a rooted device

The obvious alternative on Android is rooting the phone and running tcpdump or tcpdump-based tooling from a shell. That gives you a real packet socket, no VPN interface, and no conflict with other VPN apps. It also gives you a device that fails SafetyNet-style checks, may void a warranty, and cannot be handed to a non-technical colleague. PCAPdroid trades kernel-level capture for an installable app: you lose the ability to capture while another VPN runs, and you gain a device that still behaves like a normal phone.

Against Wireshark on a laptop, the split is complementary rather than competitive. Wireshark has the dissection depth and the display filters; PCAPdroid has the vantage point inside the phone. The README leans into this by supporting PCAP-over-IP for live analysis in Wireshark and by exporting SSLKEYLOGFILE for offline decryption. If your problem is on a desktop, PCAPdroid adds nothing. If your problem is an app that only misbehaves on a handset, Wireshark cannot see the traffic at all without a capture point, and PCAPdroid is that capture point.

For teams that need capture inside their own product, the API route is the third option: rather than shipping a general-purpose sniffer, embed the pcapd daemon on rooted devices or drive PCAPdroid over its documented API and receive packets by UDP. That is a smaller surface than forking a full capture app.

Licence, maintenance and the cost of staying current

PCAPdroid is GPL-3.0. That matters if you plan to redistribute a modified APK or reuse the pcapd daemon inside your own application: the copyleft terms travel with the code, and the README's integration section points at the daemon as something you can embed. If you are only installing the published build for internal troubleshooting, the licence is not something you interact with day to day. This is a description of the licence file, not legal advice; read COPYING in the repository before you ship anything derived from it.

The repository is not archived, and the last push was on 2026-09-20, which is three days before the date used for this review. Releases v2.0.0, v2.0.1 and v2.0.2 landed on 2026-08-20, 2026-09-09 and 2026-09-20 respectively, so the 2.0 line is being patched on a short cadence. That is a good sign for bug fixes, and it also means a pinned older build will drift from the current one quickly.

Upgrade cost is mostly on the integration side. If you embed the pcapd daemon or drive the app API, a 2.x bump can change the interface you depend on, and the README does not promise API stability. If you build from source, remember the submodule step and the CMake 3.22.1 requirement from app/build.gradle; a stale local NDK or CMake is the most likely reason a fresh checkout will not compile. The project also accepts translations through Weblate, so non-English UI text may lag the English source between releases.

Editorial conclusion

Adopt PCAPdroid if you need to see what an Android app is talking to and you cannot or will not root the device; the local VPN capture, PCAP export and PCAP-over-IP streaming cover most troubleshooting work. Skip it if you need a Windows or iOS capture client, or if you expect the firewall, malware detection and PCAPng export without paying, since the README lists those as paid features. Verify first that your target device is not already running another always-on VPN, that you can install the F-Droid or Play build, and that you are willing to accept the GPL-3.0 obligations if you plan to redistribute the APK or reuse the pcapd daemon.

Frequently asked questions

What does PCAPdroid do?

It tracks, analyzes and can block the connections made by other apps on an Android device, and it can export the traffic as a PCAP dump. It also inspects HTTP requests, decrypts TLS traffic and streams packets over PCAP-over-IP for live analysis.

Is PCAPdroid safe to use?

The README describes it as privacy-friendly and states that it does not use a remote VPN server, with data processed locally on the device. It is open source under GPL-3.0, so the capture path can be audited.

How to view PCAP files on Android?

PCAPdroid itself can record traffic to PCAP files with additional app metadata, and the README points to PCAP-over-IP for real-time analysis in Wireshark. For deeper dissection, move the file or the stream to a desktop tool.

Is there a Wireshark for Android?

PCAPdroid is the closest fit described in the README: it captures on-device and can send traffic via PCAP-over-IP to Wireshark, or save an SSLKEYLOGFILE so decryption happens later on a desktop. It is a capture point, not a full Wireshark port.

How to use PCAPdroid?

Install it from F-Droid or Google Play, start a capture so the local VPN interface comes up, then read the connection list and per-app data summary. For deeper work, record to a PCAP file, stream via PCAP-over-IP to Wireshark, or enable TLS decryption through the mitmproxy-based proxy.

Official sources

  1. emanuele-f/PCAPdroid on GitHub
  2. License: GPL-3.0
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/emanuele-f-pcapdroid.svg)](https://hysenlabs.com/projects/emanuele-f-pcapdroid)