Operating system: Windows
Publisher: Tomasz Mon
Release: USBPcap 1.5.4.0
License: Open source (GPLv2/BSD 2-Clause)
Antivirus check: VirusTotal report
USBPcap is an open-source Windows software package that makes it possible to capture and analyze USB data. It is a practical tool for USB communication research, development, and debugging.
Features
-Protocol-level USB capture
USBPcap records the USB traffic between Windows and connected devices, including control, bulk and interrupt transfers. Wireshark decodes it at the protocol level, including classes such as Mass Storage and HID.
USBPcap allows the user to capture and analyze USB traffic in a native Windows environment.
-Real-time capture and analysis
USBPcap supports live capture: when USBPcapCMD is installed as a Wireshark extcap interface, the USB root hubs appear in the Wireshark interface list, allowing you to monitor and debug USB communication as it occurs.
-Built for Windows
USBPcap is a filter driver for Windows 7, 8, 10 and later, both 32-bit and 64-bit. On Linux, USB traffic is captured with the usbmon kernel module instead.
-Flexible capture filters
USBPcap attaches one filter instance to each root hub, so you capture only the hub your device is plugged into, and you can limit the capture to selected devices and set the snapshot length and buffer size.
-Capture of device enumeration
USBPcap can capture from newly connected devices, so the descriptors sent while a device is enumerated are recorded, which helps when debugging drivers and firmware.
-Command-line capture
USBPcapCMD lists the root hubs and connected devices, and writes captures to files or pipes them into Wireshark, so captures can be started from scripts.
-Standard pcap output
Captures are saved in the pcap format with a dedicated USBPcap link-layer header, so they can be opened in Wireshark and other tools that read pcap files.
-Free and open source
USBPcap is free and open source: the driver is licensed under GPLv2 and USBPcapCMD under the BSD 2-Clause license. The installer is digitally signed, and USBPcap is also offered by the Wireshark installer.