TrimPCAP
TrimPCAP is an open-source tool that reduces the size of PCAP files by over 90%.
By trimming each flow after a configurable threshold, it lets organisations retain network capture data for much longer without exhausting storage.

More from NETRESEC
NetworkMiner
Network forensic analysis tool that parses PCAP files and reconstructs hosts, files, sessions, and credentials.
PolarProxy
Transparent TLS-decrypting proxy that intercepts encrypted malware traffic and saves it as decrypted PCAP.
FlowCarp
Behaviour-based protocol identification that detects application-layer protocols regardless of port numbers.
CapLoader
Handle large PCAP datasets fast — view traffic as TCP/UDP flows, filter, and export to other tools.
PacketCache
Free Windows service that continuously buffers captured packets in memory for retrospective analysis.
RawCap
Tiny command-line sniffer for Windows that needs no drivers and can capture localhost traffic.
findject
Open-source script that detects injected TCP packets and Man-on-the-Side attacks in HTTP sessions.
SplitCap
Command-line tool that splits large PCAP files by IP, session, or host for faster filtering.