PacketCache
PacketCache is a free Windows service that continuously monitors a computer's network interfaces and stores captured packets in memory.
When an incident is detected, the buffered traffic can be dumped to PCAP — giving responders packet history from before they started capturing.

More from NETRESEC
NetworkMiner
Network forensic analysis tool that parses PCAP files and reconstructs hosts, files, sessions, and credentials.
PolarProxy
Transparent TLS-decrypting proxy that intercepts encrypted malware traffic and saves it as decrypted PCAP.
FlowCarp
Behaviour-based protocol identification that detects application-layer protocols regardless of port numbers.
CapLoader
Handle large PCAP datasets fast — view traffic as TCP/UDP flows, filter, and export to other tools.
RawCap
Tiny command-line sniffer for Windows that needs no drivers and can capture localhost traffic.
TrimPCAP
Open-source tool that shrinks PCAP files by over 90% to enable longer traffic retention.
findject
Open-source script that detects injected TCP packets and Man-on-the-Side attacks in HTTP sessions.
SplitCap
Command-line tool that splits large PCAP files by IP, session, or host for faster filtering.