Command line
The checked fragcap command surface: commands, options, values, defaults, sinks, and output routing.
Current native path
Deep Capture uses the library-owned native proxy for the supported HTTP, streaming, generic TCP/UDP, and QUIC/HTTP/3 paths. Trust effects use native Windows APIs. Guided calibration and the stable library API share its authority boundaries. The Native product contract records the shipped boundary and its explicit non-claims.
Before capturing
Capture requires the npcap driver in WinPcap-compatible mode. Run
fragcap doctor first to inspect readiness without capturing anything.
Published baseline: v0.10.3.
This page describes the current source command tree, checked by the production parser without dispatch. The published v0.10.3 baseline includes the native API, guided calibration, command migrations below, S151's visible Doctor --timings, nested readiness timings and live elapsed diagnostics, and S161's interactive CLI input correction. Historical v0.10.0 retains the hidden completion-only timing option. Hidden test controls are excluded. clap's generated help and version controls remain available but are not repeated in every table.
In the tables, open means the parser accepts a value whose grammar is explained
in the Meaning column. none means clap declares no default; the application may
still apply the fallback described in Meaning. all means every build carries
the option, while net means a maintainer build with the optional network
feature carries it.
Running fragcap with no command lists registered targets and points at
--help.
Retired command migration
Older releases and their preserved changelog pages may refer to command forms that the current CLI no longer accepts. Use these replacements with the published v0.10.3 command surface:
| Retired form | Current form |
|---|---|
fragcap run ... | fragcap capture ... |
fragcap tap --process <image> ... | fragcap capture --process <image> ... |
Historical pages remain searchable as release records. This page is the source of truth for commands accepted by the current binary.
Global options
These options propagate to every command.
| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--json | open | false | all | Emit structured command results instead of human text where the command supports them. See Output routing. |
--quiet | open | false | all | Suppress progress while retaining terminal results, warnings, and errors. Required authorization output remains visible. |
--silent | open | false | all | Suppress optional progress, summaries, and warnings. Errors and required authorization output still surface. |
Capture
capture
Capture a stored target or a directly named running process. Exactly one target
input is required: positional SELECTOR, --target, --id, or --process.
A selector is an exact handle, a case-insensitive exact name, or a 1-based row
number from targets list.
fragcap capture 1 --out capture.fcapng
fragcap capture --target sample-target --duration 30s --out capture.fcapng
fragcap capture --process sample.exe --out capture.fcapng| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--catalog-db | open | none | all | Override FRAGCAP_CATALOG_DB, then %APPDATA%\fragcap\catalog.db, for target context. The managed path is not required. |
--direction | both, in, out | both | all | Record the requested flow direction. Non-default directional output filtering is not yet enforced. |
-d, --duration | open | none | all | Stop after a duration measured from arm, such as 30s, 5m, or 2h. |
--id | open | none | all | Select a stored target by durable numeric identifier. |
-i, --interface | open | none | all | Select a capture interface; repeat for more than one. |
--launch | open | false | all | Start an eligible prepared stored target through its declared managed launch, then capture. |
--local-db | open | none | all | Override FRAGCAP_LOCAL_DB, then %APPDATA%\fragcap\local.db, for stored-target resolution. The managed path is not required. |
--loopback | open | false | all | Include the loopback adapter. |
--max-bytes | open | none | all | Stop after a byte count using an integer plus b, kb, mb, or gb. |
--max-packets | open | none | all | Stop after this many captured packets. |
--mode | file, ring, stream | none | all | Select file, bounded ring, or streaming output. The fallback is a profile mode when present, otherwise file. |
--no-payload | open | false | all | Write metadata without packet payload bytes. |
-o, --out | open | none | all | Write a pcapng file; shorthand for a file sink. |
--path | open | none | all | Require a case-insensitive substring in the target image path. |
--path-regex | open | none | all | Require the target image path to match a regular expression. |
--process | open | none | all | Capture a running process by image name without a stored target. |
--ring | open | none | all | Set the bounded ring window as a duration or size. See Capture modes for mode and sink constraints. |
--roles | open | none | all | Capture a comma-separated role list. The fallback is profile roles, then all roles. |
--scope | all, target | target | all | Write only attributed target traffic or everything captured. Exclusions are counted. |
--sink | open | none | all | Add an output sink; repeat for multiple destinations. See Sink specifications. |
--target | open | none | all | Explicit form of the stored-target selector. A numeric value is a row number, not a platform app id. |
--wait | open | none | all | Set the target acquisition timeout. With no value, wait until start or interruption. |
--roles is enforced. --direction in and --direction out are recorded and reported, but v0.10.3 still writes both directions.
Sink specifications
The grammar is <destination>[,<key>=<value>]....
Accepted sink schemes: file, pcapng, jsonl, pipe, fifo, unix, tcp
Accepted sink modifiers: format, payload, rotate-size, rotate-duration, queue, timeout
| Form | Behavior |
|---|---|
file:PATH | File destination. Format follows format= or the extension (.jsonl means JSON Lines; anything else means pcapng). |
pcapng:PATH | Alias for file:PATH; format can still be overridden explicitly. |
jsonl:PATH | File destination defaulting to JSON Lines; format=pcapng overrides it. |
pipe:NAME | Windows named-pipe server. Requires format=pcapng or format=jsonl. |
fifo:PATH | Analyzer-provided FIFO or named-pipe path opened for pcapng writing. Used by extcap. |
unix:PATH | Unix-domain socket listener on supported non-Windows systems. Requires an explicit format. |
tcp://HOST:PORT | TCP listener. Requires an explicit format. |
format accepts pcapng or jsonl; payload accepts true or false.
rotate-size and rotate-duration apply only to file destinations and are
mutually exclusive. queue and timeout apply only to streaming destinations;
their runtime fallbacks are 1024 records and 5 seconds. Streaming destinations
cannot use rotation modifiers. Example:
fragcap capture 1 --sink "tcp://127.0.0.1:9000,format=jsonl,payload=false,queue=2048,timeout=10s"deep-capture
Run Capture with explicit, target-scoped local proxy inspection. Exactly one
stored-target input is required: positional SELECTOR, --target, or --id.
The current implementation requires a managed launch, one exact complete-plan
authorization, and compatible launch facts.
fragcap deep-capture sample-target --launch --har --key-log| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--bundle | open | none | all | Select the session bundle directory. The fallback is a new directory under FRAGCAP_SESSION_DIR, then %APPDATA%\fragcap\sessions. |
--authorize-stdin | open | false | all | Select prompt-free authorization. Read the emitted plan, return its exact plan-v1 identifier plus one LF on standard input in the same process, and keep the event stream open. Required with --json. |
--calibrate | reachability, tls | none | all | Run one explicit compatibility calibration phase. Requires --launch-case and --calibration-protocol. |
--calibration-protocol | routing, http1, https, http2, websocket, sse, grpc, generic-tcp, non-http-tls, socks5-tcp, socks5-udp, generic-udp, quic, http3 | none | all | Select the exact case to measure. Reachability requires routing; TLS requires one concrete protocol. |
--catalog-db | open | none | all | Override FRAGCAP_CATALOG_DB, then the managed per-user catalog store. |
-d, --duration | open | none | all | Stop after a duration measured from arm. |
--har | open | false | all | Write an HTTP-oriented projection when HTTP semantics are observable. |
--id | open | none | all | Select a stored target by durable identifier. |
-i, --interface | open | none | all | Select a capture interface; repeat for more than one. |
--key-log | open | false | all | Write a proxy-owned TLS key log at its final bundle path. |
--client-certificate | open | none | all | Present this explicit operator-owned certificate chain to an upstream requiring mutual TLS. Requires --client-private-key. |
--client-private-key | open | none | all | Use the private key matching --client-certificate. The key is never written to session output. |
--launch | open | false | all | Start the target under scoped proxy configuration. Required by the current implementation. |
--launch-case | steam-protocol-warm, steam-protocol-cold, direct-exe-warm, direct-exe-cold, publisher-launcher, publisher-launcher-warm, publisher-launcher-game-start-clean-warm, publisher-launcher-cold | none | all | Declare the case measured by --calibrate. Cold Steam, direct executable, and declared publisher-chain launches are supported. Unsupported or warm authority receives a pre-effect refusal. |
--local-db | open | none | all | Override FRAGCAP_LOCAL_DB, then the managed per-user local store. |
--max-bytes | open | none | all | Stop after a byte count. |
--max-packets | open | none | all | Stop after this many captured packets. |
--no-payload | open | false | all | Write packet metadata without payload bytes. |
--proxy-bypass | open | none | all | Add an explicit target bypass rule. Repeat or comma-separate DNS domain, IP, CIDR, or port-qualified authority rules. Bare and leading-dot domains both include descendants. Ambient proxy variables are never inherited. |
--proxy-family | ipv4, ipv6 | ipv4 | all | Bind the exact loopback family authorized by this session. No wildcard or automatic family fallback is used. |
--target | open | none | all | Explicit form of the stored-target selector. |
--restart-warm | open | false | all | Wait while the operator closes a warm application normally, then freshly prepare and authorize the cold launch. Conflicts with calibration. |
--wait | open | none | all | Set the target acquisition timeout. |
Deep Capture hides and rejects the former --trust-ca and --yes inputs for one release. The migration error points to the complete interactive plan or --authorize-stdin. Other commands retain their separately scoped --yes confirmations.
Authorization plan and prompt writes must succeed before input is read. Interactive approval requires a complete LF-terminated line, and effective deadlines are bound at exact millisecond precision. The prepared CA must remain within its displayed validity period. Stored target authority is checked immediately after approval, then the facade independently resolves and compares the exact profile, executable paths, platform root, dispatch, and managed launch before endpoint selection. Before constructing a new plan, a bounded read-only inspection refuses any pending prior-session recovery and directs the operator to fragcap doctor --fix; the new plan never authorizes effects against an older session.
Read Output formats and session bundles for artifact authority, sensitivity, omission, correlation, retention, and cleanup. See Deep Capture compatibility for certificate-pinning, QUIC, and launch limits.
calibrate
Guide one target through a bounded sequence of current Deep Capture reachability and protocol attempts. Stored targets retain precedence. On a clean stored miss, an exact installed Steam application identifier or Unicode-aware case-insensitive display name can produce one complete registration plan. The plan exposes and binds the complete candidate, conserved discovery account and warnings, and effective store before confirmation. Interactive registration defaults to no; structured registration requires the exact emitted target-registration-v1 identifier through --authorize-stdin. Discovery is repeated before the shared single-target registration operation runs. When an exact Steam target has no authored client, appinfo's executable is labeled a launch hint. Interactive setup can confirm a separate cold Steam launch and observe descendant socket owners; a unique complete observation proposes a client under a separate steam-client-setup-v1 plan. --client-executable EXE instead records an explicit operator declaration, including in structured workflows, without claiming observed ownership. No evidence, ambiguity, interruption, or decline changes no target row. The authoring plan revalidates discovery and the full stored row before conditional update. Setup exits after authoring; close the title and Steam normally before a new cold reachability attempt. A non-Steam stored target with two or more client-only launch entries instead requires one stable executable candidate and a separate stored-client-selection-v1 confirmation before its complete row can be narrowed to one authored client. Steam targets and ordered publisher chains never enter that rewrite path. Registration, topology setup, and every later Deep Capture attempt remain separate authorizations.
For a target with authoritative topology, the command freshly reads the process image inventory and retained compatibility facts before every proposed action. Repeatable --protocol values request measurements and do not constitute evidence. Missing route evidence selects reachability first. After each separately authorized session, eligible final-client observations may add concrete candidates, but only a fresh current positive fact permits the next useful case. One workflow runs reachability at most once and each concrete protocol at most once, for a maximum of fourteen durable attempt ordinals. A decline, invalid input, interruption, failure, partial result, warm transition, limitation, target change, or repeated case stops before later effects and checkpoints current coverage. A warm target starts no session unless --restart-warm explicitly selects the existing operator-owned close-and-retry workflow.
Fresh calibration creates a target-bound workflow before its first attempt. Resume it explicitly with --resume <WORKFLOW_ID> from the same effective local store. Resume revalidates the complete target snapshot and rebuilds current process, fact, proposal, recovery, bundle, plan, and confirmation authority. It never reuses a prior plan or response. A row left in flight first becomes an effect-free interruption pause. --pause-for can record login, EULA, update, anti-cheat, gameplay, shutdown, or interruption work without entering the session executor. A pause records operator intent, not proof or compatibility evidence. Generated commands carry the effective local-store path as one PowerShell-quoted argument. If target discovery, Steam executable metadata, or an eligible stored non-Steam client declaration is ambiguous, calibration.choice_required lists stable content-derived candidate identities. Repeat the command with one exact --candidate; list positions are never accepted. The selection still passes its separate complete plan and fresh post-confirmation checks.
A failed session prints the earliest known causal stage, observed target packet retention, proxy accept count when the native cleanup report supplies it, exact fact writes, and the workflow pause. Artifact creation is separate from successful acquisition. --resume preserves a failed attempt's history and does not rerun the same exact case; correct the cause and start a fresh workflow when another attempt is needed.
Advanced fresh workflows may assert --launch-case, select --routing-strategy, and select --proxy-family. The values become immutable workflow intent and appear in guidance. A launch assertion must equal the current inferred cold topology, and unimplemented routing strategies remain pre-effect refusals. Resume cannot change candidate or exact-case intent.
fragcap calibrate sample-target
fragcap calibrate sample-target --client-executable sample.exe
fragcap calibrate "Sample Target" --candidate candidate-v1:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef
fragcap calibrate --id 42 --protocol https
fragcap calibrate --id 42 --launch-case direct-exe-cold --routing-strategy child-environment --proxy-family ipv6
fragcap calibrate --resume 17 --local-db C:\Users\you\local.db
fragcap calibrate --resume 17 --pause-for login --local-db C:\Users\you\local.db| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--authorize-stdin | open | false | all | Read each exact emitted plan identifier from standard input. A discovered target first requires its target-registration-v1 identifier, an eligible absent Steam client requires its separate steam-client-setup-v1 identifier, an ambiguous stored non-Steam client requires its stored-client-selection-v1 identifier, and any later effectful attempt requires its current Deep Capture plan identifier. Conflicts with --restart-warm. |
--bundle | open | none | all | Select the first attempt bundle. Later attempts use deterministic sibling paths containing attempt, phase, and protocol. |
--candidate | open | none | all | Fresh workflow only. Select one exact current candidate from a prior ambiguity event. The value must be a candidate-v1:<digest> content-derived identity and must be consumed exactly once. |
--client-executable | open | none | all | Fresh Steam setup only. Supply one Windows .exe path to declare the final client explicitly when it is not already authored. This is an operator declaration, not observed socket or proxy evidence. |
--catalog-db | open | none | all | Override FRAGCAP_CATALOG_DB, then the managed per-user catalog store. |
-d, --duration | open | none | all | Bound the selected observation duration. |
--id | open | none | all | Select a stored target by durable identifier. |
-i, --interface | open | none | all | Select a capture interface; repeat for more than one. |
--local-db | open | none | all | Override FRAGCAP_LOCAL_DB, then the managed per-user local store. |
--launch-case | steam-protocol-warm, steam-protocol-cold, direct-exe-warm, direct-exe-cold, publisher-launcher, publisher-launcher-warm, publisher-launcher-game-start-clean-warm, publisher-launcher-cold | none | all | Fresh workflow only. Assert the exact current cold launch case. Omission uses the inferred case; a mismatch refuses and never rewrites topology. |
--max-bytes | open | none | all | Stop the selected attempt after this many captured bytes. |
--max-packets | open | none | all | Stop the selected attempt after this many captured packets. |
--no-payload | open | false | all | Write packet metadata without payload bytes during the selected attempt. |
--protocol | http1, https, http2, websocket, sse, grpc, generic-tcp, non-http-tls, socks5-tcp, socks5-udp, generic-udp, quic, http3 | none | all | Request concrete protocol measurements after reachability. Repeat for more than one candidate; each useful case retains a separate authorization plan. |
--pause-for | login, eula, update, anti-cheat, gameplay, shutdown, interrupted | none | all | With --resume, atomically record operator-owned work and exit without session effects. |
--proxy-family | ipv4, ipv6 | none | all | Fresh workflow only. Persist the exact loopback family and use it in every fresh proposal and attempt. Omission selects IPv4. |
--resume | open | none | all | Resume one positive target-bound workflow identifier from the effective local store. Conflicts with target selectors and --protocol. |
--restart-warm | open | false | all | Wait while the operator closes a warm application normally, take a fresh process snapshot, and measure the selected cold launch. Conflicts with --authorize-stdin. |
--routing-strategy | child-environment, command-arguments, target-configuration, http-proxy, socks, protocol-specific | none | all | Fresh workflow only. Persist the exact routing dimension. Omission selects child-environment. Only child-environment is currently implemented; other values refuse before effects. |
--target | open | none | all | Explicit target selector. Stored resolution runs first; a clean miss may exactly match an installed title name or Steam application identifier. |
--wait | open | none | all | Set the target acquisition timeout for an attempt or the bounded client observation. Client observation defaults to 60 seconds. |
calibrate registers at most one exactly selected, explicitly confirmed discovery candidate through the shared target operation. Its durable checkpoint stores target identity, candidate intent, coverage projection, bounded ordinal, lifecycle, and pause state only. It stores no authorization, secret, trust state, endpoint, effect obligation, or compatibility claim. A request, an observation, and a current exact compatibility fact remain separate. Ambiguous, invalid, and unavailable proposals report typed limitations before effects and do not invent authority.
Guided calibration implementation acceptance is checked by the versioned thirteen-criterion registry in integration/guided-calibration-acceptance-v1.json and the ordinary Linux and Windows CI suites. S147 did not run a real game or demonstrate live compatibility. Optional real-game validation belongs to the operator and may be performed only against an already published release.
replay
Accept a capture path and trailing arguments, then report that replay is not yet implemented.
fragcap replay capture.fcapng| Option | Values | Default | Availability | Meaning |
|---|
Targets
The local target store resolves from an explicit local-store option, then
FRAGCAP_LOCAL_DB, then %APPDATA%\fragcap\local.db. The final location is a
managed fallback, so a --db or --local-db option is never required merely to
use the ordinary per-user store.
targets
With no subcommand, discover and register newly installed titles, then print the numbered target listing.
fragcap targets| Option | Values | Default | Availability | Meaning |
|---|
targets add
Register a target. Positional NAME is optional when --steam supplies the
installed title name.
fragcap targets add "Sample Game" --exe sample.exe --socket-holder yes
fragcap targets add --steam 620| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--anchor | open | none | all | Give the target a stable platform:id identity; mutually exclusive with --steam. |
--db | open | none | all | Override FRAGCAP_LOCAL_DB, then the managed per-user local store. |
--exe | open | none | all | Record a launch executable name. |
--handle | open | none | all | Override the derived handle, subject to normal validity and uniqueness rules. |
--socket-holder | open | none | all | Record whether --exe holds sockets: yes, no, or unsure. Requires --exe. |
--steam | open | none | all | Register an installed Steam title by app id and anchor it as steam:<app_id>. |
targets list
Discover and register newly installed titles, then list row number, handle, readiness, and known technologies.
| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--db | open | none | all | Override FRAGCAP_LOCAL_DB, then the managed per-user local store. |
targets show
Show one target selected by positional SELECTOR or --id, including local
Deep Capture compatibility evidence.
fragcap targets show sample-target| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--db | open | none | all | Override FRAGCAP_LOCAL_DB, then the managed per-user local store. |
--id | open | none | all | Select by durable identifier instead of positional selector. |
targets discover
Read installed-game candidates from Steam and known roots without registering
the candidates. Detailed output reports whether each candidate is eligible for
automatic registration and why. --summary emits aggregate counts only and is
safe to retain as validation evidence without publishing local inventory.
| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--catalog-db | open | none | all | Override FRAGCAP_CATALOG_DB, then the managed per-user catalog store used to classify Steam titles. |
--local-db | open | none | all | Override FRAGCAP_LOCAL_DB, then the managed per-user store holding volume eligibility. |
--steam-root | open | none | all | Override automatic Steam installation discovery. |
--summary | open | false | all | Emit aggregate discovery and eligibility counts without local names, identities, paths, or warning text. |
targets reconcile
Preview conservative cleanup of historical tool-owned discovery residue. The
default is non-mutating. --yes rebuilds the preview and atomically removes only
exact rows whose complete stored value is unchanged; authored, anchored,
ambiguous, or incompletely inventoried rows remain.
fragcap targets reconcile
fragcap targets reconcile --yes| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--db | open | none | all | Override FRAGCAP_LOCAL_DB, then the managed per-user local store. |
--steam-root | open | none | all | Override automatic Steam installation discovery for the exact platform inventory. |
--yes | open | false | all | Confirm removal of the exact rows reported by the recomputed preview. |
targets scan
Treat positional DIR as one game location. With --catalog-db, attach
technology evidence. Discovered candidates are registered idempotently in the
resolved local store.
fragcap targets scan "C:\Games\Sample Game"| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--catalog-db | open | none | all | Select a catalog store whose signature table labels the directory. |
--db | open | none | all | Override FRAGCAP_LOCAL_DB, then the managed per-user local store used to register discoveries. |
targets remove
Remove one target selected by positional SELECTOR or --id.
| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--db | open | none | all | Override FRAGCAP_LOCAL_DB, then the managed per-user local store. |
--id | open | none | all | Select by durable identifier instead of positional selector. |
targets export
Write all registered targets, or positional SELECTOR or --id, as a JSON
array to standard output.
fragcap targets export| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--db | open | none | all | Override FRAGCAP_LOCAL_DB, then the managed per-user local store. |
--id | open | none | all | Export one target by durable identifier. |
targets import
Merge the target-entry JSON array at positional FILE by stable identifier.
fragcap targets import targets.json| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--db | open | none | all | Override FRAGCAP_LOCAL_DB, then the managed per-user local store, creating the selected store if absent. |
Environment
technologies
Detect engine, anti-cheat, and DRM signatures in an install directory.
fragcap technologies --path "C:\Games\Sample Game"| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--catalog-db | open | none | all | Override FRAGCAP_CATALOG_DB, then the managed per-user catalog store containing signatures. |
-p, --path | open | none | all | Required install directory to scan. |
steam
Group Steam-specific inspection commands.
| Option | Values | Default | Availability | Meaning |
|---|
steam list
List installed Steam titles. Register one with targets add --steam <app_id>.
fragcap steam listHuman output contains no tab separators. It uses an aligned APP ID, NAME, STATE, and TARGET table when every complete row fits the selected 40-through-80 display-column width, then switches the entire result to labeled vertical records when a long or localized value would not fit. Values are never truncated, and positioned, registered without a current listing position, and unregistered titles remain distinct. Use global --json for the unchanged JSON Lines machine interface.
| Option | Values | Default | Availability | Meaning |
|---|
doctor
Report environment readiness. The default is read-only; --fix offers only the
remediations already named by the report.
Native Deep Capture residue is shown under a stable native residue label with
plain-language ownership, readiness, and review guidance. Long session and
resource identities wrap without truncation, and terminals use an aligned or
compact layout from 40 through 80 display columns. With global --json, each
native residue check retains its existing machine name and adds a
native_resource object containing session_id, resource_id, kind,
state, health, ownership_authority, and recovery_eligible. Read-only
Doctor never performs cleanup; exact eligible records are reviewed and
confirmed through fragcap doctor --fix.
fragcap doctor| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--fix | open | false | all | Offer remediations interactively. Refused with --json or non-interactive standard output. |
--timings | open | false | all | Published since v0.10.1: show phase and nested readiness completion timings on interactive stderr progress. No JSON or final report changes. Historical v0.10.0 accepts this option but hides it and supplies only coarse completion timings. |
--yes | open | false | all | Pre-confirm offered actions with --fix; interactive standard output is still required. |
extcap
Serve Wireshark's extcap protocol. Query flags print declarations to standard output; capture streams pcapng to the analyzer-provided FIFO.
| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--capture | open | false | all | Start extcap capture. |
--catalog-db | open | none | all | Override FRAGCAP_CATALOG_DB, then the managed per-user catalog store. |
--direction | both, in, out | none | all | Configure the requested direction. |
--extcap-config | open | false | all | Print configurable extcap options and exit. |
--extcap-dlts | open | false | all | Print link types and exit. |
--extcap-interface | open | none | all | Select the extcap interface. |
--extcap-interfaces | open | false | all | Print available extcap interfaces and exit. |
--extcap-version | open | none | all | Accept the analyzer protocol version query; currently not acted on. |
--fifo | open | none | all | Analyzer FIFO or named-pipe path for capture bytes. |
--local-db | open | none | all | Override FRAGCAP_LOCAL_DB, then the managed per-user local store. |
--loopback | open | false | all | Include loopback. |
--roles | open | none | all | Configure comma-separated capture roles. |
--target | open | none | all | Select the stored target by the same selector grammar as Capture. |
extcap install
Register fragcap in Wireshark's extcap directory. With no scope flag, use the per-user directory.
fragcap extcap install --user| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--dir | open | none | all | Use an explicit extcap directory instead of a discovered scope. |
--system | open | false | all | Use the machine-wide Wireshark directory; write privilege is required. |
--user | open | false | all | Use %APPDATA%\Wireshark\extcap, the default scope. |
extcap uninstall
Remove the corresponding extcap registration. Scope flags have the same
precedence as extcap install.
| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--dir | open | none | all | Use an explicit extcap directory instead of a discovered scope. |
--system | open | false | all | Use the machine-wide Wireshark directory. |
--user | open | false | all | Use the per-user Wireshark directory, the default scope. |
Data
bundle
Group explicit lifecycle operations for completed Deep Capture bundles.
| Option | Values | Default | Availability | Meaning |
|---|
bundle cleanup
Delete only artifacts that the completed bundle manifest declares sensitive. The original journal records each intent and result so interrupted cleanup can resume without broad directory deletion.
fragcap bundle cleanup .\fragcap-session --yes| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--yes | open | false | all | Confirm targeted deletion of the manifest-declared sensitive artifacts. |
bundle export
Create a separate share copy containing ordinary artifacts and a complete sharing manifest. The source bundle is never modified.
fragcap bundle export .\fragcap-session --out .\fragcap-session-share| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--out | open | none | all | Required destination directory for the new share copy. |
fresh-start
Preview or irreversibly remove canonical fragcap user data. Preview is read-only and emits an inventory identifier. Execution requires both --confirm with that exact unchanged identifier and --yes. Current-user scope covers only %APPDATA%\fragcap and %LOCALAPPDATA%\fragcap. All-users scope requires an elevated Administrator session and a report path. It enumerates Windows profiles through the operating system profile authority rather than searching the filesystem. Deep Capture evidence in another profile remains for current-user recovery under that profile's Windows trust identity, so such an all-users result is partial until that recovery is complete.
fragcap fresh-start --scope current-user --preview
fragcap fresh-start --scope current-user --confirm <inventory-id> --yes --report .\fresh-start-report.json| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--confirm | open | none | all | Require the unchanged identifier emitted by the exact preview. |
--preview | open | false | all | List exact roots, categories, and inventory identity without mutation. |
--report | open | none | all | Write the bounded versioned cleanup result to a new local path outside cleanup roots. Required for all-users execution. |
--scope | all-users, current-user | current-user | all | Select one caller profile or the distinct elevated all-users inventory. |
--yes | open | false | all | Confirm irreversible execution after reviewing the inventory. |
Deep Capture session evidence is removed only after Doctor's exact recovery authority reaches safe terminal states. Custom paths, Npcap, Wireshark configuration, and independently managed extcap registrations are excluded. A redirection or recovery failure remains in the report and makes the result partial.
Catalog store options resolve from explicit --db, then
FRAGCAP_CATALOG_DB, then %APPDATA%\fragcap\catalog.db. The managed path is
the ordinary fallback, not a required argument.
catalog
Group commands for the shipped, disposable catalog store.
| Option | Values | Default | Availability | Meaning |
|---|
catalog import
Load positional SEED, a schema-conformant local JSON export, transactionally.
fragcap catalog import catalog.json| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--db | open | none | all | Override FRAGCAP_CATALOG_DB, then the managed per-user catalog store. |
catalog export
Write the catalog store as schema-conformant JSON to standard output.
| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--db | open | none | all | Override FRAGCAP_CATALOG_DB, then the managed per-user catalog store. |
catalog seed
Fill one repeatable --tier or every tier with an available source. --from
is the hermetic local source. --steam and --pcgamingwiki exist only in an
optional network-capable maintainer build.
fragcap catalog seed --tier signature
fragcap catalog seed --tier catalog --from catalog.json| Option | Values | Default | Availability | Meaning |
|---|---|---|---|---|
--db | open | none | all | Override FRAGCAP_CATALOG_DB, then the managed per-user catalog store. |
--from | open | none | all | Read one local source document; requires exactly one consumable --tier. |
--min-reviews | open | 500 | all | Set the title-tier review-count corpus threshold. |
--pcgamingwiki | open | false | net | Seed the engine tier from the live PCGamingWiki query API. |
--steam | open | false | net | Seed the title tier from the live Steam catalog. |
--tier | catalog, engine, launch, signature | none | all | Select a tier; repeat as needed. signature is always offline. |
schema
Group commands for the embedded master JSON schema.
| Option | Values | Default | Availability | Meaning |
|---|
schema validate
Validate positional FILE and report every structural violation in one pass.
fragcap schema validate targets.json| Option | Values | Default | Availability | Meaning |
|---|
schema print
Write the embedded master schema to standard output.
| Option | Values | Default | Availability | Meaning |
|---|
Output routing
--json changes presentation, not the ownership of streams. Structured command
results, such as target, Steam, doctor, catalog, and schema results, go to
standard output. Capture and Deep Capture lifecycle events go to standard error
so they cannot contaminate capture bytes. Packet bytes and packet JSON Lines go
only to the configured --out, --sink, or extcap FIFO destination. Warnings
and errors are diagnostics on standard error.
--quiet suppresses progress but retains authoritative terminal results, warnings, and errors. --silent suppresses optional progress, completion summaries, and warnings; errors and configured sinks remain active. Neither flag hides required complete authorization plans or turns consent into approval. A consumer must parse documented result and lifecycle streams separately; there is no combined JSON stream.