# emanuele-f/PCAPdroid

No-root network monitor, firewall and PCAP dumper for Android

Repository: https://github.com/emanuele-f/PCAPdroid
Canonical: https://ross.abutalabs.com/products/pcapdroid
Homepage: https://emanuele-f.github.io/PCAPdroid
Language: Java
License: GPL-3.0
License Family: copyleft
Topics: pcap, capture-traffic, android, no-root, traffic-monitor, pcap-files, sniffer, network-analysis, sniffing, decryption, firewall, wireshark
Last push: 2026-08-26T20:37:14+00:00

## Health v2 (maintenance only)
Score: 99/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 98, longevity 100
- inputs: {"age_days": 2431, "days_push": 7, "days_rel": 13, "gap_med": 28.0, "n_releases_24m": 15}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4602, forks 533 (observed 2026-08-28T04:08:54.853360+00:00)

## What it is
PCAPdroid is a privacy-friendly open source Android app that monitors, analyzes, and blocks network connections made by other apps without requiring root. It simulates a VPN to capture traffic locally, supporting PCAP export, HTTP inspection, and TLS decryption.

## Use cases
- monitor which apps make network connections on my android phone
- capture traffic to a pcap file without root
- decrypt https traffic on android for analysis
- stream android traffic to wireshark in real time
- block specific apps or domains from accessing the network
- detect malware connections on my device
- inspect http requests from android apps

## When to choose
- you need to inspect or dump android network traffic without rooting the device
- you want to export traffic as pcap for analysis in wireshark
- you need per-app connection logging and firewall rules on android
- you want to decrypt TLS traffic on-device for debugging or security research

## When to avoid
- you need packet capture on desktop or server platforms
- you need a full network intrusion detection system for an entire network
- you require high-throughput production traffic analysis rather than on-device inspection

## Facets
- artifact type: application
- maturity: active
- function: monitoring, security, networking, privacy
- domain: security, networking, privacy, android-tools
- platform: -
- tags: pcap, packet-capture, traffic-analysis, no-root, vpn, tls-decryption, wireshark, firewall, sniffer, android

## Member repositories
- emanuele-f/PCAPdroid (main) score 99

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:54.853360+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:19:46.437360+00:00, confidence not recorded.
  - readme: https://github.com/emanuele-f/PCAPdroid (fetched 2026-08-28T04:08:54.853360+00:00, sha 823ce6c646a6)
  - homepage: https://emanuele-f.github.io/PCAPdroid (fetched 2026-08-29T09:04:46.826615+00:00, sha 3c094f3dc952)
- Data as of 2026-08-30T08:39:29.467469+00:00.
