RawCap
RawCap is a free, lightweight command-line packet sniffer for Windows that requires no special drivers or installation.
It can uniquely capture localhost (127.0.0.1) traffic, making it handy for capturing on machines where installing WinPcap isn't possible.

More from NETRESEC
NetworkMiner
Network forensic analysis tool that parses PCAP files and reconstructs hosts, files, sessions, and credentials.
PolarProxy
Transparent TLS-decrypting proxy that intercepts encrypted malware traffic and saves it as decrypted PCAP.
FlowCarp
Behaviour-based protocol identification that detects application-layer protocols regardless of port numbers.
CapLoader
Handle large PCAP datasets fast — view traffic as TCP/UDP flows, filter, and export to other tools.
PacketCache
Free Windows service that continuously buffers captured packets in memory for retrospective analysis.
TrimPCAP
Open-source tool that shrinks PCAP files by over 90% to enable longer traffic retention.
findject
Open-source script that detects injected TCP packets and Man-on-the-Side attacks in HTTP sessions.
SplitCap
Command-line tool that splits large PCAP files by IP, session, or host for faster filtering.