Documentation

Process-attributed Capture and explicit, target-scoped Deep Capture for Windows game traffic.

Published baseline: v0.10.3.

Deep Capture status

Deep Capture uses the native Rust proxy, with supported protocols, scoped routing, managed launch, recovery, final-package certification, stable API and guided calibration shipped in v0.10.0 on 2026-09-15. S150 supplied independent-review readiness, not an audit. v0.10.2 included S154 through S158 documentation, review-intake, deterministic package-certification and Windows observation corrections. v0.10.3 adds bounded QUIC observation headroom and corrected interactive CLI input. Concrete failures observed in an active release are tracked as defects against that release.

fragcap has two shipped modes for Windows game traffic. Capture passively records packets and correlates flows with the processes that produced them, including clients started indirectly through platform and publisher launchers. Deep Capture runs that same packet capture alongside explicit, target-scoped local proxy inspection for authorized sessions and compatible traffic.

Ordinary packet records do not preserve process ownership. fragcap correlates them with separate Windows socket and process-lifecycle observations and records the result without reaching inside the processes it names. Deep Capture adds application observations only when the selected target reaches the local proxy and accepts its trust path; unsupported and unobserved traffic remains explicit.

What you need first

Two prerequisites, before anything else:

  • Npcap in WinPcap API-compatible mode is required for live packets and is never bundled or redistributed. Published doctor --fix offers the official acquisition page after confirmation; optional source-build net support can fetch and launch the vendor's signed installer after confirmation.
  • Wireshark (or another pcapng-aware analyzer) is how you read a capture. fragcap writes extended pcapng; you capture with fragcap, then open the result in Wireshark to inspect it.

Where to start

The Glossary defines the vocabulary the rest of these pages assume, one term to a heading.

Native product contract maps thirteen required current topics, sections and examples to executable authorities while keeping published bytes, current source and external acceptance separate.

The security posture

Capture observes passively. Deep Capture is active by design, but runs only after explicit selection and remains scoped to the chosen target session, visible in output, reversible through cleanup, and auditable afterward. Neither mode injects code, hooks target functions, reads target memory, modifies target executables, changes the Winsock catalog, uses a packet interception driver, extracts target TLS keys, or bypasses certificate pinning. Deep Capture never falls back silently to system-wide proxy settings or silent certificate trust.