NetworkMiner
NetworkMiner is a network forensic analysis tool (NFAT) that parses PCAP files and can also perform live sniffing of network traffic.
Rather than organising data by packets, it presents information by individual hosts — extracting files, images, sessions, credentials, and other artifacts — which makes it a favourite of incident response teams.
Available in a free edition and a Professional edition with extended protocol support and reporting.

More from NETRESEC
PolarProxy
Transparent TLS-decrypting proxy that intercepts encrypted malware traffic and saves it as decrypted PCAP.
FlowCarp
Behaviour-based protocol identification that detects application-layer protocols regardless of port numbers.
CapLoader
Handle large PCAP datasets fast — view traffic as TCP/UDP flows, filter, and export to other tools.
PacketCache
Free Windows service that continuously buffers captured packets in memory for retrospective analysis.
RawCap
Tiny command-line sniffer for Windows that needs no drivers and can capture localhost traffic.
TrimPCAP
Open-source tool that shrinks PCAP files by over 90% to enable longer traffic retention.
findject
Open-source script that detects injected TCP packets and Man-on-the-Side attacks in HTTP sessions.
SplitCap
Command-line tool that splits large PCAP files by IP, session, or host for faster filtering.