# Npcap: the Windows capture layer that Nmap and other tools sit on top of

> A packet capture and injection library for Windows from the Nmap Project, distributed as an installer with a free tier for five systems and a paid OEM edition for redistribution.

**nmap/npcap** — Nmap Project's Windows packet capture and transmission library

- Repository: https://github.com/nmap/npcap
- Website: https://npcap.com
- Stars: 3,608 · Forks: 592
- Language: C
- License: NOASSERTION
- Published: 2026-10-07 · Updated: 2026-10-07 · Language: en
- Canonical page: https://hysenlabs.com/projects/nmap-npcap

## A replacement for WinPcap, not a scanner in its own right

Npcap is a packet capture and injection library for Windows, built by the Nmap Project, and the README calls it a complete update to WinPcap, the project it replaces. The comparison to WinPcap is the whole pitch: WinPcap is described as unmaintained, and the three words the README uses for what changed are speed, reliability and security.

It is worth being precise about what this thing is not. Npcap has no target list, no scan profiles, no service detection and no report writer. It never decides what to look at on the network. It exposes raw packets to software that already knows what it wants, and its repository carries exactly two topics, packet-capture and windows, which is an accurate summary of the scope.

The README also reveals the intended audience in an indirect way. When it asks for a bug report it asks for your user software version, and the two examples it gives are Nmap and Wireshark. Those are the tools most people meet Npcap through, usually without noticing it: you install Nmap on Windows and it points you at npcap.com for the driver, you open Wireshark and it is already there or it asks. From that angle Npcap is infrastructure, and its release notes are the ones to read when a capture tool suddenly stops seeing traffic.

## Five systems free, and a separate product for redistribution

The licensing arrangement is the part that catches people out, and it is stated in the README in plain language. End users can download, install and use Npcap from the project's own site for free on up to five systems, commercial usage included. That is a per machine allowance attached to the download, not a per user or per organisation allowance, so five workstations in an office are covered and a sixth is not.

Software providers who want to ship Npcap functionality inside their own product are pointed at npcap.com so their users can download it themselves. That is a deliberately narrow permission, and it is why the project funds itself with Npcap OEM, a version the README describes as including enterprise features such as the silent installer and commercial support, along with special license rights.

So the practical question is not whether Npcap is open source. The repository reports no standard licence identifier, and the README links a bespoke Npcap License file rather than MIT or GPL. What it offers is a permissive-looking end user licence with a system cap, and a paid path for vendors. Anyone shipping a capture feature inside a product needs to read the LICENSE file and talk to sales@nmap.com rather than assume the GitHub repository implies a conventional open source grant.

## A kernel driver, a wpcap shim and a set of example tools

The repository layout explains how the pieces fit together without needing the developer guide. `packetWin7/` holds the driver sources, `wpcap/` holds the user level compatibility layer that keeps the familiar WinPcap API working, `Common/` is shared code, and `installer/` is the packaging. The directory name is a useful detail for anyone still on older Windows, since it ties the driver work to the Windows 7 era and up.

Alongside that sit the parts of the repository you are most likely to read first. `Examples/` holds fourteen sample projects, and the names describe the API surface directly: `pcap_filter/` for BPF filters, `pktdump_ex/` for saving to a file, `sendcap/` for transmission, `iflist/` for enumerating adapters, `tcptop/` for a live socket table, and `UserLevelBridge/` for reading packets from a process that is not allowed to touch the driver directly. `Examples-pcap/` sits apart for capture-only variants, and `Examples/MakeAll.sln` is the solution file that ties them together.

The build side is Windows native rather than cross platform: `build_sdk.bat`, `build_include.bat`, `build_lib.bat`, `build_test.bat` and `create_docs.bat` each do one step, with `appveyor.yml` holding the CI definition. Documentation is generated rather than written by hand, with `Npcap_Guide.html`, `docs/` and the `create_docs` scripts in the tree. There is no Linux story at all in this repository, which is the single biggest reason it exists alongside native capture stacks on other systems.

## Recent releases fix crashes and installer behaviour, not features

Three releases are published, and reading them tells you what kind of project this is. Npcap 1.89, published on 2026-09-12, fixed a crash seen on some systems during an upgrade, caused by NDIS calling `NPF_ReturnEx` after the driver had unloaded. It also renamed the adapter binding ComponentID from `INSECURE_NPCAP` to `nmap_npcap`, reflecting a company name change, and updated the bundled libpcap to 1.10.7.

Npcap 1.88 from 2026-05-06 is heavier. It fixed processes hanging when closing a capture handle after the driver had rejected a BPF filter, and fixed the outermost VLAN tag being stripped from packets carrying more than one tag. The VLAN bug is the kind of thing that silently corrupts analysis of tagged traffic rather than crashing anything. The release also expanded the documented installer exit codes, so an already running installer and unsupported Windows versions such as Vista and Server 2008 now report distinct outcomes, and an aborted install over a newer existing copy returns 0. It moved the installer to NSIS 3.12 to close a privilege escalation path and signed plugin DLLs that had gone unsigned.

Npcap 1.87 from 2026-02-04 fixed assorted blue screen crashes in `NPF_DoTap()`. Two crash fixes and one privilege escalation fix across three releases is the shape of a low level driver library that has to keep pace with Windows internals. It also means upgrade notes are worth reading before you upgrade, particularly if your capture tool passes unusual BPF filters or works on stacked VLANs.

## There is no install command, because Npcap installs as a Windows package

The README gives no command line and no package manager route. Installation is a signed installer fetched from npcap.com, together with a Software Development Kit, the source and debug symbols, and the README links all four to the same download page. The guide on the site carries the details the README skips: a section on installation, a section on reporting bugs, a developer guide for writing software against Npcap, and a page on internals.

That split is worth understanding before you evaluate the project. Anyone choosing between capture stacks wants to know about driver signing policy, silent deployment into an existing image, and coexistence with a VPN client, and none of that appears on the README page. It lives on npcap.com, and you would be reading it either way.

For anyone rebuilding from source, the repository gives you the sequence rather than a single entry point: `build_include.bat` prepares headers, `build_lib.bat` builds the libraries, `build_sdk.bat` assembles the SDK, `build_test.bat` runs the tests under `test/`, and `create_docs.bat` regenerates the HTML guide. Changelog history is split too, with `CHANGELOG.md` for the driver and `SDK_CHANGELOG.md` for the kit, and the current version lives in `version.h`.

## Bug reports that start with a DiagReport

The README asks reporters for a DiagReport output, the version of the user software such as Nmap or Wireshark, reproduction steps, and anything else that helps. The DiagReport request is a strong signal about how this project expects to be debugged: a kernel driver failure is not something you can describe adequately in prose, so the first artefact is a generated diagnostic file.

The repository also documents where the conversation happens. Technical issues and discussion go to `dev@nmap.org`, licensing and commercial questions to `sales@nmap.com`, and everything else to the GitHub issue tracker. The issue tracker is where the release notes point when they cite a fix, using the issues.npcap.org addresses, so the tracker is a usable record of what has actually broken and in which version it was addressed.

One contradiction is worth naming rather than resolving. The README describes Npcap as being by the Nmap Project and points at nmap.org and nmap.com, while the repository reports no standard open source licence identifier and ships a custom Npcap License, and the release notes show a company rename from Insecure.Org, LLC to Nmap Software, LLC still landing in 1.89. All three are true at once: this is an Nmap Project component, under an Nmap Software company, on a bespoke licence. If licence clarity matters to your procurement process, the LICENSE file and the OEM terms are the two documents to read, not the GitHub metadata.

## Conclusion

Npcap is a good fit when you run Windows tooling that captures or injects packets, and a poor fit for anything that only needs to talk HTTP. The free installer covers personal and commercial use on up to five systems, and the OEM edition exists because redistributing the driver inside another product is a different question from running it yourself. Before committing, read the release notes for your Windows build, since three of the last four releases fixed crashes and installer behaviour rather than adding features, then check the Npcap Guide installation section for the exit codes and the DiagReport output you will need if something goes wrong.

## FAQ

### What is Npcap used for?

It is the Windows packet capture and injection library that tools such as Nmap and Wireshark rely on to see traffic. Npcap itself does no scanning or analysis. It loads a driver, hands packets to whatever program asked for them, and can inject packets on request.

### Is Npcap safe to use?

The project presents it as the maintained replacement for WinPcap, with improvements to speed, reliability and security, and it ships as a signed installer. Recent releases tightened the installer itself: 1.88 moved to NSIS 3.12 to address a privilege escalation and signed previously unsigned plugin DLLs.

### Do I need Npcap?

You need it if you run Windows software that captures or injects packets, and the README names Nmap and Wireshark as the usual examples. If your Windows work stays inside a browser or an ordinary application, nothing in the project's own documentation suggests you have any use for the driver.

## Sources

- [Issues](https://github.com/nmap/npcap/issues)
- [nmap/npcap on GitHub](https://github.com/nmap/npcap)
- [Project website](https://npcap.com)
- [README](https://github.com/nmap/npcap/blob/master/README.md)
- [Releases](https://github.com/nmap/npcap/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/nmap-npcap
