PCAPdroid - network monitor APP
PCAPdroid simulates a VPN in order to capture the network traffic without root. It does not use a remote VPN server, instead data is processed locally on the device.
Main features:
- Log and analyze the connections made by user and system apps
- Get a summary of how much data each app sent and received
- Low battery usage for continuous, all-day capture
- Extract hosts and IP addresses from DNS, TLS and HTTP
- Record the traffic to PCAP files with additional app metadata
- Send traffic via PCAP-over-IP for real-time analysis (e.g. on Wireshark)
- Decrypt the HTTPS/TLS traffic, extract the URLs and save the SSLKEYLOGFILE
- Inspect the HTTP requests/replies and export them to HAR
- Identify the country and ASN of the remote server via offline DB lookups
- On rooted devices, capture the traffic while other VPN apps are running
Paid features:
- Firewall: create rules to block individual apps, domains and IP addresses
- Malware detection: detect malicious connections by using third-party blacklists
- PcapNG format: makes it easier to export and analyze decrypted traffic
If you plan to use PCAPdroid to perform packet analysis, check out the specific section of the manual.
Join the international PCAPdroid community on Telegram or on Matrix.
michat 
