1<!DOCTYPE html> 2<html lang="en"> 3<head> 4<title>Npcap vs WinPcap</title> 5<meta name="description" content="How does Npcap compare to WinPcap?"> 6<meta name="keywords" content="Npcap,packet capture,winpcap,comparison,advantages,compatibility"> 7<link rel="stylesheet" href="/shared/css/tab.css" type="text/css"> 8<meta name="viewport" content="width=device-width,initial-scale=1"> 9<meta name="theme-color" content="#2A0D45"> 10<link rel="preload" as="image" href="/images/sitelogo.png" imagesizes="168px" imagesrcset="/images/sitelogo.png, /images/sitelogo-2x.png 2x"> 11<link rel="preload" as="image" href="/shared/images/nst-icons.svg"> 12<link rel="stylesheet" href="/shared/css/nst.css?v=2">
13<script async src="/shared/js/nst.js?v=2"></script>
13 14<link rel="stylesheet" href="/shared/css/nst-foot.css?v=2" media="print" onload="this.media='all'"> 15<link rel="stylesheet" href="/site.css"> 16<!--Google Analytics Code--> 17<link rel="preload" href="https://www.google-analytics.com/analytics.js" as="script">
18<script>
vendor: 328 bytes, lines 18-23
18 19(function(i,s,o,g,r,a,m){i['GoogleAnalyticsObject']=r;i[r]=i[r]||function(){ 20(i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o), 21m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m) 22})(window,document,'script','//www.google-analytics.com/analytics.js','ga'); 23ga('create', '
23UA-11009417-1
vendor: 36 bytes, lines 23-24
23', 'auto'); 24ga('send', 'pageview');
25</script>
25 26<!--END Google Analytics Code--> 27<META NAME="ROBOTS" CONTENT="NOARCHIVE"> 28<link rel="shortcut icon" href="/shared/images/tiny-eyeicon.png" type="image/png"> 29</head> 30<body><div id="nst-wrapper"> 31 32<div id="menu"> 33 <div class="blur"> 34 <header id="nst-head"> 35 36 <a id="menu-open" href="#menu" aria-label="Open menu"> 37 <img width="44" height="44" alt="" aria-hidden="true" 38 src="/shared/images/nst-icons.svg#menu"> 39 </a> 40 <a id="menu-close" href="#" aria-label="Close menu"> 41 <img width="44" height="44" alt="" aria-hidden="true" 42 src="/shared/images/nst-icons.svg#close"> 43 </a> 44 45 <a id="nst-logo" href="/" aria-label="Home page"> 46 <img alt="Home page logo" srcset="/images/sitelogo.png, /images/sitelogo-2x.png 2x" src="/images/sitelogo.png" onerror="this.onerror=null;this.srcset=this.src" height=90 width=168></a> 47 48 <nav id="nst-gnav"> 49 <a class="nlink" href="https://nmap.org/">Nmap.org</a> 50 <a class="nlink" href="https://npcap.com/">Npcap.com</a> 51 <a class="nlink" href="https://seclists.org/">Seclists.org</a> 52 <a class="nlink" href="https://sectools.org">Sectools.org</a> 53 <a class="nlink" href="https://insecure.org/">Insecure.org</a> 54 </nav> 55 56 <form class="nst-search" id="nst-head-search" action="/search/"> 57 <input class="nst-search-q" name="q" type="search" placeholder="Site Search"> 58 <button class="nst-search-button" title="Search"> 59 <img style="width:100%;aspect-ratio:1/1;" alt="" aria-hidden="true" 60 src="/shared/images/nst-icons.svg#search"> 61 </button> 62 </form> 63 64 </header> 65 </div> 66</div> 67 68<main id="nst-content"> 69 70<nav id="nst-sitenav"> 71<a class="nlink" href="/guide/">Docs</a> 72<a class="nlink" href="/#download">Download</a> 73<a class="nlink" href="/oem/">Licensing</a> 74<a class="nlink" href="/windows-10.html">Windows 11</a> 75<a class="nlink" href="/vs-winpcap.html">WinPcap</a> 76</nav> 77 78 79 80 81 82 83 84 85<h1 class="purpleheader">Npcap or WinPcap?</h1> 86 87<p>WinPcap has been the de facto standard library for packet capture and 88link-layer packet injection for over a decade. Many open source and commercial 89network tools use WinPcap for network access and filtering, but it has been 90unmaintained since 2013 and is <a href="https://www.winpcap.org/news.htm">no longer supported</a>.</p> 91 92<p>Npcap is the exciting and feature-packed update to the venerable WinPcap 93packet capture library. Building on the successful WinPcap legacy, Npcap brings
94increased speed, security, and Windows 10 support. All of WinPcap's packet 95capture and injection features are included, with a few great additions like 96<a href="guide/npcap-devguide.html#npcap-feature-dot11"> 97raw 802.11 frame capture</a>. Still wondering if Npcap is right for you? Check 98out this comparison of features: 99</p> 100 101<table class="feature-table"> 102 <colgroup> 103 <col class="feature" span="1"><col><col> 104 </colgroup> 105 <thead> 106 <tr> 107 <th>Feature</th> <th>Npcap</th> <th>WinPcap</th> 108 </tr> 109 </thead> 110 <tbody> 111 <tr class="feature-group"> 112 <td class="feature">Info</td> <td>Npcap</td> <td>WinPcap</td> 113 </tr> 114 <tr> 115 <td class="feature">Actively maintained and supported</td> 116 <td class="yes">Yes</td> 117 <td class="no"><span class="note">No<span class="note-text"><a href="https://www.winpcap.org/news.htm">WinPcap development was terminated</a></span></span></td> 118 </tr> 119 <tr> 120 <td class="feature">Last release date</td> 121 <td>Sep 12, 2026</td> 122 <td>March 8, 2013</td> 123 </tr> 124 <tr> 125 <td class="feature"><a href="http://www.tcpdump.org/">libpcap</a> version</td> 126 <td>1.10.7 (2026)</td> 127 <td>1.0.0 (2008)</td> 128 </tr> 129 <tr> 130 <td class="feature">License</td> 131 <td><a href="https://npcap.com/license">Free for personal use</a></td> 132 <td><a href="https://www.winpcap.org/misc/copyright.htm">BSD-style</a></td> 133 </tr> 134 <tr> 135 <td class="feature">Supported commercial/<wbr>redistributable version</td> 136 <td class="yes">Yes: <a href="/oem/">Npcap OEM</a></td> 137 <td class="no"><span class="note">No<span class="note-text">WinPcap Professional product terminated</span></span></td> 138 </tr> 139 140 <tr class="feature-group"> 141 <td class="feature">Security</td> <td>Npcap</td> <td>WinPcap</td> 142 </tr> 143 <tr> 144 <td class="feature">EV SHA-256 code signing</td> 145 <td class="yes">Yes</td> 146 <td class="no">No</td> 147 </tr> 148 <tr> 149 <td class="feature">Limit access to administrators (optional)</td> 150 <td class="yes">Yes</td> 151 <td class="no">No</td> 152 </tr> 153 154<tr style="visibility: collapse"><!-- fix odd/even colors --><td></td><td></td><td></td></tr> 155 <tr class="feature-group"> 156 <td class="feature">Basic features</td> <td>Npcap</td> <td>WinPcap</td> 157 </tr> 158 <tr> 159 <td class="feature">Packet capture with the cross-platform libpcap API</td> 160 <td class="yes"><span class="note">Yes<span class="note-text">Check out <a href="/whats-new">the latest API features</a></span></span></td> 161 <td class="yes">Yes</td> 162 </tr> 163 <tr> 164 <td class="feature">Link-layer packet injection</td> 165 <td class="yes">Yes</td> 166 <td class="yes">Yes</td> 167 </tr> 168 <tr> 169 <td class="feature">Source code available</td> 170 <td class="yes"><span class="note">Yes<span class="note-text"><a href="https://github.com/nmap/npcap">Npcap source on Github</a></span></span></td> 171 <td class="yes"><span class="note">Yes<span class="note-text"><a href="https://www.winpcap.org/devel.htm">WinPcap source on winpcap.org</a></span></span></td> 172 </tr> 173 174 <tr class="feature-group"> 175 <td class="feature">Advanced features</td> <td>Npcap</td> <td>WinPcap</td> 176 </tr> 177 <tr> 178 <td class="feature">Capture raw 802.11 frames</td> 179 <td class="yes"><span class="note">Yes<span class="note-text">with <a href="https://secwiki.org/w/Npcap/WiFi_adapters">many widely-available adapters</a></span></span></td> 180 <td class="yes"><span class="note">Yes<span class="note-text">with specialized <a href="https://support.riverbed.com/content/support/software/steelcentral-npm/airpcap.html">AirPcap hardware</a></span></span></td> 181 </tr> 182 <tr> 183 <td class="feature">Capture Loopback traffic</td> 184 <td class="yes">Yes</td> 185 <td class="no">No</td> 186 </tr> 187 <tr> 188 <td class="feature">Inject Loopback traffic</td> 189 <td class="yes">Yes</td> 190 <td class="no">No</td> 191 </tr> 192 </tbody> 193</table> 194 195<p>Ready to give Npcap a try? Just <a href="https://npcap.com/#download">download the 196 latest installer</a>. Npcap works great with Wireshark, Nmap, and more of your 197favorite tools already. For software that's written with WinPcap in mind, simply 198select "WinPcap API-compatible mode" at installation. 199</p> 200 201<p>Want to develop software for Npcap? Check out the 202<a href="/guide/npcap-devguide.html">Npcap Developer's 203 Guide</a> and the <a href="https://npcap.com/#download">
203Npcap SDK</a>. For software that 204already uses WinPcap, you can test Npcap in WinPcap API-compatible mode. You can 205<a href="/guide/npcap-devguide.html#npcap-feature-native">easily support both WinPcap and Npcap</a> or simply use the SDK to 206use Npcap with all of its new features. If you want to distribute Npcap with 207your application, ask us about getting a <a href="oem/">Npcap OEM</a> 208license and support contract. 209</p> 210 211</main><!-- content --> 212 213<footer id="nst-foot"> 214 <form class="nst-search" id="nst-foot-search" action="/search/"> 215 <input class="nst-search-q" name="q" type="search" placeholder="Site Search"> 216 <button class="nst-search-button" title="Search"> 217 <img style="width:100%;aspect-ratio:1/1;" alt="" aria-hidden="true" 218 src="/shared/images/nst-icons.svg#search"> 219 </button> 220 </form> 221<div class="flexlists"> 222<div class="fl-unit"> 223<h2><a class="nlink" href="https://nmap.org/">Nmap Security Scanner</a></h2> 224<ul> 225<li><a class="nlink" href="https://nmap.org/book/man.html">Ref Guide</a> 226<li><a class="nlink" href="https://nmap.org/book/install.html">Install Guide</a> 227<li><a class="nlink" href="https://nmap.org/docs.html">Docs</a> 228<li><a class="nlink" href="https://nmap.org/download.html">Download</a> 229<li><a class="nlink" href="https://nmap.org/oem/">Nmap OEM</a> 230</ul> 231</div> 232<div class="fl-unit"> 233<h2><a class="nlink" href="https://npcap.com/">Npcap packet capture</a></h2> 234<ul> 235<li><a class="nlink" href="https://npcap.com/guide/">User's Guide</a> 236<li><a class="nlink" href="https://npcap.com/guide/npcap-devguide.html#npcap-api">API docs</a> 237<li><a class="nlink" href="https://npcap.com/#download">Download</a> 238<li><a class="nlink" href="https://npcap.com/oem/">Npcap OEM</a> 239</ul> 240</div> 241<div class="fl-unit"> 242<h2><a class="nlink" href="https://seclists.org/">Security Lists</a></h2> 243<ul> 244<li><a class="nlink" href="https://seclists.org/nmap-announce/">Nmap Announce</a> 245<li><a class="nlink" href="https://seclists.org/nmap-dev/">Nmap Dev</a> 246<li><a class="nlink" href="https://seclists.org/fulldisclosure/">Full Disclosure</a> 247<li><a class="nlink" href="https://seclists.org/oss-sec/">Open Source Security</a> 248<li><a class="nlink" href="https://seclists.org/dataloss/">BreachExchange</a> 249</ul> 250</div> 251<div class="fl-unit"> 252<h2><a class="nlink" href="https://sectools.org">Security Tools</a></h2> 253<ul> 254<li><a class="nlink" href="https://sectools.org/tag/vuln-scanners/">Vuln scanners</a> 255<li><a class="nlink" href="https://sectools.org/tag/pass-audit/">Password audit</a> 256<li><a class="nlink" href="https://sectools.org/tag/web-scanners/">Web scanners</a> 257<li><a class="nlink" href="https://sectools.org/tag/wireless/">Wireless</a> 258<li><a class="nlink" href="https://sectools.org/tag/sploits/">Exploitation</a> 259</ul> 260</div> 261<div class="fl-unit"> 262<h2><a class="nlink" href="https://insecure.org/">About</a></h2> 263<ul> 264<li><a class="nlink" href="https://insecure.org/fyodor/">About/Contact</a> 265<li><a class="nlink" href="https://insecure.org/privacy.html">Privacy</a> 266<li><a class="nlink" href="https://insecure.org/advertising.html">Advertising</a> 267<li><a class="nlink" href="https://nmap.org/npsl/">Nmap Public Source License</a> 268</ul> 269</div> 270<div class="fl-unit social-links"> 271<a class="nlink" href="https://twitter.com/nmap" title="Visit us on Twitter"> 272 <img width="32" height="32" src="/shared/images/nst-icons.svg#twitter" alt="" aria-hidden="true"> 273 </a> 274<a class="nlink" href="https://facebook.com/nmap" title="Visit us on Facebook"> 275 <img width="32" height="32" src="/shared/images/nst-icons.svg#facebook" alt="" aria-hidden="true"> 276 </a> 277<a class="nlink" href="https://github.com/nmap/" title="Visit us on Github"> 278 <img width="32" height="32" src="/shared/images/nst-icons.svg#github" alt="" aria-hidden="true"> 279 </a> 280<a class="nlink" href="https://reddit.com/r/nmap/" title="Discuss Nmap on Reddit"> 281 <img width="32" height="32" src="/shared/images/nst-icons.svg#reddit" alt="" aria-hidden="true"> 282 </a> 283</div> 284</div> 285</footer> 286 287</div><!-- wrapper --> 288</body> 289</html> 290
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.