Skip to main content

PCAPNG to HAR Converter

Python-based tool for converting PCAPNG files to HAR files.

License: GPLv3 and MIT

PyPI - Version GitHub Release

Website | Support

Overview

This project is a Python-based tool for converting PCAPNG files to HAR files. It supports HTTP/1.1, HTTP/2 and WebSocket protocols, but not HTTP/3.

Requirements

This converter requires a PCAPNG file as input. If you have a PCAP file, you can convert it to PCAPNG using editcap:

editcap <traffic.pcap> <traffic.pcapng>

Make sure the following tools are installed on your system:

  • Python 3.11+
  • tshark (part of the Wireshark suite; requires version >= 4.0)

Known issues

  • For tshark < 4.2, HTTP/2 streams that are compressed and chunked are not decompressed during reassembly step by tshark. To properly handle such data, we advise you to use tshark >= 4.2.

Installation

pip install pcapng-utils

Usage

Shell

Run pcapng_to_har [-h] in your shell (with your Python virtual environment activated)

Python

from pcapng_utils.pcapng_to_har import pcapng_to_har
help(pcapng_to_har)

Features

TLS Decryption

If the captured traffic contains TLS traffic and a SSLKEYLOGFILE has been generated during the capture, use the following command to inject the TLS client randoms read from the <keylog_file> into the PCAPNG file:

editcap --inject-secrets tls,<keylog_file> <traffic.pcap> <traffic.pcapng>

Once the secrets have been injected into the PCAPNG file, you can use pcapng_to_har to convert the PCAPNG file to a HAR file. The output HAR will contain the decrypted TLS traffic.

pcapng_to_har -i <traffic.pcapng> -o <traffic.har>

Stacktrace Identification (PiRogue only)

If the traffic has been captured on a PiRogue with the command pirogue-intercept[single|gated], the stacktrace of all operations (read, write) on sockets have been logged in a file socket_trace.json. The converter will use this file to add the stacktrace information to each request and response. The attributes request._stacktrace and response._stacktrace will, respectively, contain the stacktrace of the socket operations that have been performed for the request and the response.

pcapng_to_har -i <traffic.pcapng> -o <traffic.har> -sf <socket_trace.json>

In case there was a systematic time shift between socket operations timestamps vs. network traffic timestamps, you may provide the --time-shift SECONDS flag to account for it. Indeed socket operations timestamps come from phone date, whereas network traffic timestamps come from Pirogue date, which may be desynchronized. Positive shift means network traffic timestamps (Pirogue) were earlier than socket operations timestamps (phone).

Note: this enrichment is automatically performed provided that socket_trace.json is present in the folder containing your input PCAPNG

Payload Decryption (PiRogue only)

If the traffic has been captured on a PiRogue with the command pirogue-intercept[single|gated], the encryption and decryption operations have been logged in a file aes_info.json. The converter will use this file to identifies the payloads that have been encrypted before been transmitted. The encrypted payload will be replaced by its cleartext in request.postData.text and response.content.text.

Additional information about the encryption and decryption operations will be added to the HAR in the attributes request._decryption and response._decryption.

pcapng_to_har -i <traffic.pcapng> -o <traffic.har> -cf <aes_info.json>

Note: this enrichment is automatically performed provided that aes_info.json is present in the folder containing your input PCAPNG

Development

  1. Install Python 3.11 or higher.
  2. Install tshark from the Wireshark suite.
  3. Clone this repository:
git clone https://github.com/PiRogueToolSuite/pcapng-utils
cd pcapng-utils
  1. Install the package in editable mode:
pip install -e .

Licensing

This work is licensed under multiple licences:

Metadata

Release files for pcapng-utils 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pcapng-utils 1.1.0
File Size Uploaded
pcapng_utils-1.1.0.tar.gz 50.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pcapng-utils 1.1.0
File Interpreter ABI Platform
pcapng_utils-1.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 106.3 kB

Release files / pcapng_utils-1.1.0.tar.gz

Download URL pcapng_utils-1.1.0.tar.gz
Size 50.1 kB
Tags Source
SHA-256 checksum
How to use checksums
8cd19e1100a68f862c9688793a928e8e2c2bd1788eae69275ed2e83288594682
BLAKE2b-256 checksum
How to use checksums
076224fa65f0f755c2f86bd438380f829ef7d774971bc19505e1a55ec3d5737f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Mar 27, 2026.

Transparency log

Release files / pcapng_utils-1.1.0-py3-none-any.whl

Download URL pcapng_utils-1.1.0-py3-none-any.whl
Size 56.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7848cb80d6a2efc2efe8736de21c58ff541b008504e6d181ec51de9d39a68b8f
BLAKE2b-256 checksum
How to use checksums
89a8833b8f6a9bae44fbdf620d0ad415705f212c92502879061f1386e7cdf8e2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Mar 27, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.1.0 This release

2 release files

1.0.10

2 release files

1.0.9

2 release files

1.0.8

2 release files

1.0.7

2 release files

1.0.6

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page