Library / SDK
seladb/PcapPlusPlus avatar
seladb/PcapPlusPlus

PcapPlusPlus: a C++ wrapper for libpcap, DPDK and AF_XDP packet capture

PcapPlusPlus is a multiplatform C++ library for capturing, parsing and crafting of network packets. It is designed to be efficient, powerful and easy to use. It provides C++ wrappers for the most popular packet processing engines such as libpcap, Npcap, WinPcap, DPDK, AF_XDP and PF_RING.

3,145 stars760 forksC++Unlicense

At a glance

What is it?
PcapPlusPlus puts one C++ API in front of libpcap, Npcap, DPDK, AF_XDP, WinDivert and PF_RING, and adds protocol parsing, crafting and TCP reassembly on top. It suits C++ engineers who need packet work inside an existing binary, not a standalone sniffer.
Who is it for?
Adopt PcapPlusPlus if you are writing C++ that must capture, parse or forge packets and you want one API across libpcap, Npcap, DPDK and AF_XDP. Do not adopt it if you only need to read a pcap file once (tcpdump and Wireshark already do that), if you are not writing C++ (the project publishes no Python binding), or if you want a daemon you configure rather than a library you link.
Can I use it commercially?
Yes. Unlicense is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly C++, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem PcapPlusPlus solves: one C++ API across six capture engines

Packet capture in C++ usually starts with a choice you cannot easily undo. libpcap gives you a portable capture handle and a filter language, but leaves you to hand-roll Ethernet, IP, TCP and application-layer parsing. DPDK gives you line-rate processing on dedicated queues, but its own API, its own memory model and its own build. Moving from one to the other means rewriting the capture path.

PcapPlusPlus sits above both. The README describes it as a multiplatform C++ library for capturing, parsing and crafting of network packets that provides C++ wrappers for libpcap, WinPcap, Npcap, DPDK, eBPF AF_XDP, WinDivert and PF_RING. The capture engine becomes a construction detail rather than the shape of your program.

The second half of the problem is parsing. A raw frame is bytes with offsets; PcapPlusPlus gives you layers. The repository splits into Common++, Packet++ and Pcap++, and the protocol list spans data link, network, transport, session, presentation and application layers. The intended reader is a C++ engineer embedding packet handling into a larger program: a test harness, a traffic generator, a forensic tool, a protocol implementation under test.

How the layer model and packet crafting actually fit together

The mechanism visible in the repository is a three-library split. Common++ holds shared utilities. Packet++ holds protocol parsing and packet generation. Pcap++ holds the capture wrappers and file readers and writers. Your code links against the pieces it needs.

On the read path, a capture device or a pcap file yields raw packet bytes, and Packet++ walks them as a stack of layers: data link, then network, then transport, then whatever the payload turns out to be. The README lists PCAP and PCAPNG as the two file formats supported for reading and writing.

On the write path, the same layer classes are used to build a packet rather than to interpret one. You construct the outer layer, then the inner ones, and the library serialises the result. This is why the Examples/ directory is the most useful part of the repository for a newcomer: it contains complete programs rather than snippets. ArpSpoofing, DnsSpoofing, HttpAnalyzer, SSLAnalyzer, TLSFingerprinting, TcpReassembly, IPFragUtil, IPDefragUtil, PcapPrinter, PcapSplitter and PcapSearch each exercise a different part of the API.

Two features are worth separating from the rest. TCP reassembly is described in the README as handling TCP retransmission, out-of-order TCP packets and missing TCP data, which is the part most home-grown parsers get wrong. IP fragmentation and defragmentation are the counterpart at the network layer. Both are the kind of code you would otherwise write badly and then debug for a week.

Installing PcapPlusPlus and running a first capture on Ubuntu

The README offers three package managers and a source build. On macOS, Homebrew:

bash
brew install pcapplusplus

On Windows, Vcpkg from a developer prompt:

text
.\vcpkg install pcapplusplus

On macOS or Linux, the same tool without the backslash:

text
vcpkg install pcapplusplus

Conan is the third option, and the README gives this exact command:

text
conan install "pcapplusplus/[>0]@" -u

If you prefer to build from source, the README's instruction is to clone the repository and then follow the platform-specific steps on the Build From Source page of the project site:

bash
git clone https://github.com/seladb/PcapPlusPlus.git

For a first real use, go to Examples/ rather than writing code from scratch. Examples/CMakeLists.txt builds the set, and the Tutorials/ directory under Examples/ is the project's own guided path. A reasonable first target is PcapPrinter, which reads a capture file and prints the decoded layers; PcapSearch, which filters packets by a pattern; and TcpReassembly, which demonstrates the reassembly API on a capture file. The repository does not document a single canonical run command for these in the README, so read the CMake target names and the per-example sources. Expect to need the development headers for whichever capture engine your platform uses, since libpcap, Npcap and the rest are separate dependencies rather than vendored code.

Where PcapPlusPlus is the wrong tool

The most common mismatch is treating it as a replacement for tcpdump or Wireshark. It is a library. There is no CLI in the README, no configuration file format, no daemon. If your task is to read one pcap file and look at it, the existing tools finish the job before you have written a CMakeLists.txt.

The second mismatch is language. PcapPlusPlus is C++. The README documents no Python binding, so the related search for a Python interface does not correspond to anything in the project. If your pipeline is Python, you are looking at ctypes or a subprocess, and both erase the reason to use this library.

The third is the capture backend. DPDK, AF_XDP, WinDivert and PF_RING are listed as separate engines with separate requirements. DPDK in particular needs hugepages, bound NICs and a build configured for it. PcapPlusPlus wraps those engines; it does not remove their prerequisites. A container without the right capabilities will not capture, and the library will not change that.

Finally, the licence. The repository ships an Unlicense file, which is a public-domain dedication rather than a permissive licence with conditions. That is unusual and worth reading directly rather than assuming it behaves like MIT.

PcapPlusPlus versus libpcap and versus Scapy

Against libpcap, the difference is the layer model. libpcap gives you a capture handle, a BPF filter and a buffer of bytes. PcapPlusPlus gives you the same capture handle underneath, plus typed objects for each protocol and a crafting API that libpcap does not have at all. If you only need to capture and count, libpcap alone is less code and fewer dependencies. If you need to inspect or build packets, the parsing layer is the reason to add PcapPlusPlus.

Against Scapy, the difference is the runtime and the performance envelope. Scapy is Python and interactive; you can build a packet in a REPL and send it in seconds. PcapPlusPlus is compiled C++ with a build step and no REPL. Scapy is faster to prototype with, and PcapPlusPlus is the one you can put in a latency-sensitive path or ship as part of a native binary. Scapy also has a much larger set of contributed protocol layers; PcapPlusPlus's protocol coverage is fixed by what is in Packet++.

A third comparison the README implies rather than states: against writing your own DPDK application. PcapPlusPlus gives you a DPDK wrapper with the same layer API as the libpcap path, so the same parsing code works on both. The cost is that you accept the library's abstractions on the fast path. The repository includes Examples/DpdkExample-FilterTraffic and Examples/PcapPlusPlus-benchmark if you want to see how the project itself structures that comparison.

Maintenance, releases and what the Unlicense means for your build

The repository is not archived, and the last push was on 2026-09-21. Releases are infrequent and dated: v26.07 in July 2026, v25.05 in May 2025, v24.09 in September 2024. That cadence matters for planning. You are not tracking a fast-moving dependency, but you are also not getting monthly fixes. Pin a version and plan to move deliberately.

Upgrade cost is dominated by the capture backends, not by PcapPlusPlus itself. A change in DPDK or in the kernel's AF_XDP interface can force a rebuild and occasionally an API adjustment, because the wrappers track those engines. The libpcap path is the stable one. If your code is written against Packet++ layer classes, upgrades are usually a recompile; if it reaches into the DPDK wrapper, read the release notes before jumping.

On licensing, the repository contains a single LICENSE file and the project is listed as Unlicense. That is a public-domain dedication, so there are effectively no attribution or copyleft obligations attached to the code as published. Two caveats are worth checking yourself rather than taking on faith: the 3rdParty/ directory may contain code under different terms, and the Unlicense does not automatically cover patents the way some permissive licences do. Read LICENSE and the third-party notices before shipping in a jurisdiction where that distinction matters. This is a description of what the repository states, not legal advice.

Editorial conclusion

Adopt PcapPlusPlus if you are writing C++ that must capture, parse or forge packets and you want one API across libpcap, Npcap, DPDK and AF_XDP. Do not adopt it if you only need to read a pcap file once (tcpdump and Wireshark already do that), if you are not writing C++ (the project publishes no Python binding), or if you want a daemon you configure rather than a library you link. Before committing, build one of the Examples/ targets on your own platform and confirm that the packet capture engine you intend to use is actually available there, since the README lists DPDK, AF_XDP, WinDivert and PF_RING as separate backends rather than one binary that switches between them.

Frequently asked questions

What is PcapPlusPlus used for?

It is a C++ library for capturing, parsing and crafting network packets, and for reading and writing PCAP and PCAPNG files. The README also lists TCP reassembly and IP fragmentation and defragmentation as features, so it is used where a program needs to understand packet contents rather than just move them.

How can I read a pcap file with PcapPlusPlus?

The README states that reading and writing packets from and to files is supported in both PCAP and PCAPNG formats, and the Examples/ directory contains complete programs that do this, including PcapPrinter, PcapSearch and PcapSplitter. The README does not give a single run command for them, so build the examples through Examples/CMakeLists.txt and read the per-example sources.

Which file format does PcapPlusPlus support, PCAP or PCAPNG?

Both. The README lists reading and writing packets from and to files in both PCAP and PCAPNG formats as a feature. The repository does not state a preference between them.

Official sources

  1. License: Unlicense
  2. Project website
  3. README
  4. Releases
  5. seladb/PcapPlusPlus on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/seladb-pcapplusplus.svg)](https://hysenlabs.com/projects/seladb-pcapplusplus)