Command line

The checked fragcap command surface: commands, options, values, defaults, sinks, and output routing.

Current native path

Deep Capture uses the library-owned native proxy for the supported HTTP, streaming, generic TCP/UDP, and QUIC/HTTP/3 paths. Trust effects use native Windows APIs. Guided calibration and the stable library API share its authority boundaries. The Native product contract records the shipped boundary and its explicit non-claims.

Before capturing

Capture requires the npcap driver in WinPcap-compatible mode. Run fragcap doctor first to inspect readiness without capturing anything.

Published baseline: v0.10.3.

This page describes the current source command tree, checked by the production parser without dispatch. The published v0.10.3 baseline includes the native API, guided calibration, command migrations below, S151's visible Doctor --timings, nested readiness timings and live elapsed diagnostics, and S161's interactive CLI input correction. Historical v0.10.0 retains the hidden completion-only timing option. Hidden test controls are excluded. clap's generated help and version controls remain available but are not repeated in every table.

In the tables, open means the parser accepts a value whose grammar is explained in the Meaning column. none means clap declares no default; the application may still apply the fallback described in Meaning. all means every build carries the option, while net means a maintainer build with the optional network feature carries it.

Running fragcap with no command lists registered targets and points at --help.

Retired command migration

Older releases and their preserved changelog pages may refer to command forms that the current CLI no longer accepts. Use these replacements with the published v0.10.3 command surface:

Retired formCurrent form
fragcap run ...fragcap capture ...
fragcap tap --process <image> ...fragcap capture --process <image> ...

Historical pages remain searchable as release records. This page is the source of truth for commands accepted by the current binary.

Global options

These options propagate to every command.

OptionValuesDefaultAvailabilityMeaning
--jsonopenfalseallEmit structured command results instead of human text where the command supports them. See Output routing.
--quietopenfalseallSuppress progress while retaining terminal results, warnings, and errors. Required authorization output remains visible.
--silentopenfalseallSuppress optional progress, summaries, and warnings. Errors and required authorization output still surface.

Capture

capture

Capture a stored target or a directly named running process. Exactly one target input is required: positional SELECTOR, --target, --id, or --process. A selector is an exact handle, a case-insensitive exact name, or a 1-based row number from targets list.

fragcap capture 1 --out capture.fcapng
fragcap capture --target sample-target --duration 30s --out capture.fcapng
fragcap capture --process sample.exe --out capture.fcapng
OptionValuesDefaultAvailabilityMeaning
--catalog-dbopennoneallOverride FRAGCAP_CATALOG_DB, then %APPDATA%\fragcap\catalog.db, for target context. The managed path is not required.
--directionboth, in, outbothallRecord the requested flow direction. Non-default directional output filtering is not yet enforced.
-d, --durationopennoneallStop after a duration measured from arm, such as 30s, 5m, or 2h.
--idopennoneallSelect a stored target by durable numeric identifier.
-i, --interfaceopennoneallSelect a capture interface; repeat for more than one.
--launchopenfalseallStart an eligible prepared stored target through its declared managed launch, then capture.
--local-dbopennoneallOverride FRAGCAP_LOCAL_DB, then %APPDATA%\fragcap\local.db, for stored-target resolution. The managed path is not required.
--loopbackopenfalseallInclude the loopback adapter.
--max-bytesopennoneallStop after a byte count using an integer plus b, kb, mb, or gb.
--max-packetsopennoneallStop after this many captured packets.
--modefile, ring, streamnoneallSelect file, bounded ring, or streaming output. The fallback is a profile mode when present, otherwise file.
--no-payloadopenfalseallWrite metadata without packet payload bytes.
-o, --outopennoneallWrite a pcapng file; shorthand for a file sink.
--pathopennoneallRequire a case-insensitive substring in the target image path.
--path-regexopennoneallRequire the target image path to match a regular expression.
--processopennoneallCapture a running process by image name without a stored target.
--ringopennoneallSet the bounded ring window as a duration or size. See Capture modes for mode and sink constraints.
--rolesopennoneallCapture a comma-separated role list. The fallback is profile roles, then all roles.
--scopeall, targettargetallWrite only attributed target traffic or everything captured. Exclusions are counted.
--sinkopennoneallAdd an output sink; repeat for multiple destinations. See Sink specifications.
--targetopennoneallExplicit form of the stored-target selector. A numeric value is a row number, not a platform app id.
--waitopennoneallSet the target acquisition timeout. With no value, wait until start or interruption.

--roles is enforced. --direction in and --direction out are recorded and reported, but v0.10.3 still writes both directions.

Sink specifications

The grammar is <destination>[,<key>=<value>]....

Accepted sink schemes: file, pcapng, jsonl, pipe, fifo, unix, tcp

Accepted sink modifiers: format, payload, rotate-size, rotate-duration, queue, timeout

FormBehavior
file:PATHFile destination. Format follows format= or the extension (.jsonl means JSON Lines; anything else means pcapng).
pcapng:PATHAlias for file:PATH; format can still be overridden explicitly.
jsonl:PATHFile destination defaulting to JSON Lines; format=pcapng overrides it.
pipe:NAMEWindows named-pipe server. Requires format=pcapng or format=jsonl.
fifo:PATHAnalyzer-provided FIFO or named-pipe path opened for pcapng writing. Used by extcap.
unix:PATHUnix-domain socket listener on supported non-Windows systems. Requires an explicit format.
tcp://HOST:PORTTCP listener. Requires an explicit format.

format accepts pcapng or jsonl; payload accepts true or false. rotate-size and rotate-duration apply only to file destinations and are mutually exclusive. queue and timeout apply only to streaming destinations; their runtime fallbacks are 1024 records and 5 seconds. Streaming destinations cannot use rotation modifiers. Example:

fragcap capture 1 --sink "tcp://127.0.0.1:9000,format=jsonl,payload=false,queue=2048,timeout=10s"

deep-capture

Run Capture with explicit, target-scoped local proxy inspection. Exactly one stored-target input is required: positional SELECTOR, --target, or --id. The current implementation requires a managed launch, one exact complete-plan authorization, and compatible launch facts.

fragcap deep-capture sample-target --launch --har --key-log
OptionValuesDefaultAvailabilityMeaning
--bundleopennoneallSelect the session bundle directory. The fallback is a new directory under FRAGCAP_SESSION_DIR, then %APPDATA%\fragcap\sessions.
--authorize-stdinopenfalseallSelect prompt-free authorization. Read the emitted plan, return its exact plan-v1 identifier plus one LF on standard input in the same process, and keep the event stream open. Required with --json.
--calibratereachability, tlsnoneallRun one explicit compatibility calibration phase. Requires --launch-case and --calibration-protocol.
--calibration-protocolrouting, http1, https, http2, websocket, sse, grpc, generic-tcp, non-http-tls, socks5-tcp, socks5-udp, generic-udp, quic, http3noneallSelect the exact case to measure. Reachability requires routing; TLS requires one concrete protocol.
--catalog-dbopennoneallOverride FRAGCAP_CATALOG_DB, then the managed per-user catalog store.
-d, --durationopennoneallStop after a duration measured from arm.
--haropenfalseallWrite an HTTP-oriented projection when HTTP semantics are observable.
--idopennoneallSelect a stored target by durable identifier.
-i, --interfaceopennoneallSelect a capture interface; repeat for more than one.
--key-logopenfalseallWrite a proxy-owned TLS key log at its final bundle path.
--client-certificateopennoneallPresent this explicit operator-owned certificate chain to an upstream requiring mutual TLS. Requires --client-private-key.
--client-private-keyopennoneallUse the private key matching --client-certificate. The key is never written to session output.
--launchopenfalseallStart the target under scoped proxy configuration. Required by the current implementation.
--launch-casesteam-protocol-warm, steam-protocol-cold, direct-exe-warm, direct-exe-cold, publisher-launcher, publisher-launcher-warm, publisher-launcher-game-start-clean-warm, publisher-launcher-coldnoneallDeclare the case measured by --calibrate. Cold Steam, direct executable, and declared publisher-chain launches are supported. Unsupported or warm authority receives a pre-effect refusal.
--local-dbopennoneallOverride FRAGCAP_LOCAL_DB, then the managed per-user local store.
--max-bytesopennoneallStop after a byte count.
--max-packetsopennoneallStop after this many captured packets.
--no-payloadopenfalseallWrite packet metadata without payload bytes.
--proxy-bypassopennoneallAdd an explicit target bypass rule. Repeat or comma-separate DNS domain, IP, CIDR, or port-qualified authority rules. Bare and leading-dot domains both include descendants. Ambient proxy variables are never inherited.
--proxy-familyipv4, ipv6ipv4allBind the exact loopback family authorized by this session. No wildcard or automatic family fallback is used.
--targetopennoneallExplicit form of the stored-target selector.
--restart-warmopenfalseallWait while the operator closes a warm application normally, then freshly prepare and authorize the cold launch. Conflicts with calibration.
--waitopennoneallSet the target acquisition timeout.

Deep Capture hides and rejects the former --trust-ca and --yes inputs for one release. The migration error points to the complete interactive plan or --authorize-stdin. Other commands retain their separately scoped --yes confirmations.

Authorization plan and prompt writes must succeed before input is read. Interactive approval requires a complete LF-terminated line, and effective deadlines are bound at exact millisecond precision. The prepared CA must remain within its displayed validity period. Stored target authority is checked immediately after approval, then the facade independently resolves and compares the exact profile, executable paths, platform root, dispatch, and managed launch before endpoint selection. Before constructing a new plan, a bounded read-only inspection refuses any pending prior-session recovery and directs the operator to fragcap doctor --fix; the new plan never authorizes effects against an older session.

Read Output formats and session bundles for artifact authority, sensitivity, omission, correlation, retention, and cleanup. See Deep Capture compatibility for certificate-pinning, QUIC, and launch limits.

calibrate

Guide one target through a bounded sequence of current Deep Capture reachability and protocol attempts. Stored targets retain precedence. On a clean stored miss, an exact installed Steam application identifier or Unicode-aware case-insensitive display name can produce one complete registration plan. The plan exposes and binds the complete candidate, conserved discovery account and warnings, and effective store before confirmation. Interactive registration defaults to no; structured registration requires the exact emitted target-registration-v1 identifier through --authorize-stdin. Discovery is repeated before the shared single-target registration operation runs. When an exact Steam target has no authored client, appinfo's executable is labeled a launch hint. Interactive setup can confirm a separate cold Steam launch and observe descendant socket owners; a unique complete observation proposes a client under a separate steam-client-setup-v1 plan. --client-executable EXE instead records an explicit operator declaration, including in structured workflows, without claiming observed ownership. No evidence, ambiguity, interruption, or decline changes no target row. The authoring plan revalidates discovery and the full stored row before conditional update. Setup exits after authoring; close the title and Steam normally before a new cold reachability attempt. A non-Steam stored target with two or more client-only launch entries instead requires one stable executable candidate and a separate stored-client-selection-v1 confirmation before its complete row can be narrowed to one authored client. Steam targets and ordered publisher chains never enter that rewrite path. Registration, topology setup, and every later Deep Capture attempt remain separate authorizations.

For a target with authoritative topology, the command freshly reads the process image inventory and retained compatibility facts before every proposed action. Repeatable --protocol values request measurements and do not constitute evidence. Missing route evidence selects reachability first. After each separately authorized session, eligible final-client observations may add concrete candidates, but only a fresh current positive fact permits the next useful case. One workflow runs reachability at most once and each concrete protocol at most once, for a maximum of fourteen durable attempt ordinals. A decline, invalid input, interruption, failure, partial result, warm transition, limitation, target change, or repeated case stops before later effects and checkpoints current coverage. A warm target starts no session unless --restart-warm explicitly selects the existing operator-owned close-and-retry workflow.

Fresh calibration creates a target-bound workflow before its first attempt. Resume it explicitly with --resume <WORKFLOW_ID> from the same effective local store. Resume revalidates the complete target snapshot and rebuilds current process, fact, proposal, recovery, bundle, plan, and confirmation authority. It never reuses a prior plan or response. A row left in flight first becomes an effect-free interruption pause. --pause-for can record login, EULA, update, anti-cheat, gameplay, shutdown, or interruption work without entering the session executor. A pause records operator intent, not proof or compatibility evidence. Generated commands carry the effective local-store path as one PowerShell-quoted argument. If target discovery, Steam executable metadata, or an eligible stored non-Steam client declaration is ambiguous, calibration.choice_required lists stable content-derived candidate identities. Repeat the command with one exact --candidate; list positions are never accepted. The selection still passes its separate complete plan and fresh post-confirmation checks.

A failed session prints the earliest known causal stage, observed target packet retention, proxy accept count when the native cleanup report supplies it, exact fact writes, and the workflow pause. Artifact creation is separate from successful acquisition. --resume preserves a failed attempt's history and does not rerun the same exact case; correct the cause and start a fresh workflow when another attempt is needed.

Advanced fresh workflows may assert --launch-case, select --routing-strategy, and select --proxy-family. The values become immutable workflow intent and appear in guidance. A launch assertion must equal the current inferred cold topology, and unimplemented routing strategies remain pre-effect refusals. Resume cannot change candidate or exact-case intent.

fragcap calibrate sample-target
fragcap calibrate sample-target --client-executable sample.exe
fragcap calibrate "Sample Target" --candidate candidate-v1:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef
fragcap calibrate --id 42 --protocol https
fragcap calibrate --id 42 --launch-case direct-exe-cold --routing-strategy child-environment --proxy-family ipv6
fragcap calibrate --resume 17 --local-db C:\Users\you\local.db
fragcap calibrate --resume 17 --pause-for login --local-db C:\Users\you\local.db
OptionValuesDefaultAvailabilityMeaning
--authorize-stdinopenfalseallRead each exact emitted plan identifier from standard input. A discovered target first requires its target-registration-v1 identifier, an eligible absent Steam client requires its separate steam-client-setup-v1 identifier, an ambiguous stored non-Steam client requires its stored-client-selection-v1 identifier, and any later effectful attempt requires its current Deep Capture plan identifier. Conflicts with --restart-warm.
--bundleopennoneallSelect the first attempt bundle. Later attempts use deterministic sibling paths containing attempt, phase, and protocol.
--candidateopennoneallFresh workflow only. Select one exact current candidate from a prior ambiguity event. The value must be a candidate-v1:<digest> content-derived identity and must be consumed exactly once.
--client-executableopennoneallFresh Steam setup only. Supply one Windows .exe path to declare the final client explicitly when it is not already authored. This is an operator declaration, not observed socket or proxy evidence.
--catalog-dbopennoneallOverride FRAGCAP_CATALOG_DB, then the managed per-user catalog store.
-d, --durationopennoneallBound the selected observation duration.
--idopennoneallSelect a stored target by durable identifier.
-i, --interfaceopennoneallSelect a capture interface; repeat for more than one.
--local-dbopennoneallOverride FRAGCAP_LOCAL_DB, then the managed per-user local store.
--launch-casesteam-protocol-warm, steam-protocol-cold, direct-exe-warm, direct-exe-cold, publisher-launcher, publisher-launcher-warm, publisher-launcher-game-start-clean-warm, publisher-launcher-coldnoneallFresh workflow only. Assert the exact current cold launch case. Omission uses the inferred case; a mismatch refuses and never rewrites topology.
--max-bytesopennoneallStop the selected attempt after this many captured bytes.
--max-packetsopennoneallStop the selected attempt after this many captured packets.
--no-payloadopenfalseallWrite packet metadata without payload bytes during the selected attempt.
--protocolhttp1, https, http2, websocket, sse, grpc, generic-tcp, non-http-tls, socks5-tcp, socks5-udp, generic-udp, quic, http3noneallRequest concrete protocol measurements after reachability. Repeat for more than one candidate; each useful case retains a separate authorization plan.
--pause-forlogin, eula, update, anti-cheat, gameplay, shutdown, interruptednoneallWith --resume, atomically record operator-owned work and exit without session effects.
--proxy-familyipv4, ipv6noneallFresh workflow only. Persist the exact loopback family and use it in every fresh proposal and attempt. Omission selects IPv4.
--resumeopennoneallResume one positive target-bound workflow identifier from the effective local store. Conflicts with target selectors and --protocol.
--restart-warmopenfalseallWait while the operator closes a warm application normally, take a fresh process snapshot, and measure the selected cold launch. Conflicts with --authorize-stdin.
--routing-strategychild-environment, command-arguments, target-configuration, http-proxy, socks, protocol-specificnoneallFresh workflow only. Persist the exact routing dimension. Omission selects child-environment. Only child-environment is currently implemented; other values refuse before effects.
--targetopennoneallExplicit target selector. Stored resolution runs first; a clean miss may exactly match an installed title name or Steam application identifier.
--waitopennoneallSet the target acquisition timeout for an attempt or the bounded client observation. Client observation defaults to 60 seconds.

calibrate registers at most one exactly selected, explicitly confirmed discovery candidate through the shared target operation. Its durable checkpoint stores target identity, candidate intent, coverage projection, bounded ordinal, lifecycle, and pause state only. It stores no authorization, secret, trust state, endpoint, effect obligation, or compatibility claim. A request, an observation, and a current exact compatibility fact remain separate. Ambiguous, invalid, and unavailable proposals report typed limitations before effects and do not invent authority.

Guided calibration implementation acceptance is checked by the versioned thirteen-criterion registry in integration/guided-calibration-acceptance-v1.json and the ordinary Linux and Windows CI suites. S147 did not run a real game or demonstrate live compatibility. Optional real-game validation belongs to the operator and may be performed only against an already published release.

replay

Accept a capture path and trailing arguments, then report that replay is not yet implemented.

fragcap replay capture.fcapng
OptionValuesDefaultAvailabilityMeaning

Targets

The local target store resolves from an explicit local-store option, then FRAGCAP_LOCAL_DB, then %APPDATA%\fragcap\local.db. The final location is a managed fallback, so a --db or --local-db option is never required merely to use the ordinary per-user store.

targets

With no subcommand, discover and register newly installed titles, then print the numbered target listing.

fragcap targets
OptionValuesDefaultAvailabilityMeaning

targets add

Register a target. Positional NAME is optional when --steam supplies the installed title name.

fragcap targets add "Sample Game" --exe sample.exe --socket-holder yes
fragcap targets add --steam 620
OptionValuesDefaultAvailabilityMeaning
--anchoropennoneallGive the target a stable platform:id identity; mutually exclusive with --steam.
--dbopennoneallOverride FRAGCAP_LOCAL_DB, then the managed per-user local store.
--exeopennoneallRecord a launch executable name.
--handleopennoneallOverride the derived handle, subject to normal validity and uniqueness rules.
--socket-holderopennoneallRecord whether --exe holds sockets: yes, no, or unsure. Requires --exe.
--steamopennoneallRegister an installed Steam title by app id and anchor it as steam:<app_id>.

targets list

Discover and register newly installed titles, then list row number, handle, readiness, and known technologies.

OptionValuesDefaultAvailabilityMeaning
--dbopennoneallOverride FRAGCAP_LOCAL_DB, then the managed per-user local store.

targets show

Show one target selected by positional SELECTOR or --id, including local Deep Capture compatibility evidence.

fragcap targets show sample-target
OptionValuesDefaultAvailabilityMeaning
--dbopennoneallOverride FRAGCAP_LOCAL_DB, then the managed per-user local store.
--idopennoneallSelect by durable identifier instead of positional selector.

targets discover

Read installed-game candidates from Steam and known roots without registering the candidates. Detailed output reports whether each candidate is eligible for automatic registration and why. --summary emits aggregate counts only and is safe to retain as validation evidence without publishing local inventory.

OptionValuesDefaultAvailabilityMeaning
--catalog-dbopennoneallOverride FRAGCAP_CATALOG_DB, then the managed per-user catalog store used to classify Steam titles.
--local-dbopennoneallOverride FRAGCAP_LOCAL_DB, then the managed per-user store holding volume eligibility.
--steam-rootopennoneallOverride automatic Steam installation discovery.
--summaryopenfalseallEmit aggregate discovery and eligibility counts without local names, identities, paths, or warning text.

targets reconcile

Preview conservative cleanup of historical tool-owned discovery residue. The default is non-mutating. --yes rebuilds the preview and atomically removes only exact rows whose complete stored value is unchanged; authored, anchored, ambiguous, or incompletely inventoried rows remain.

fragcap targets reconcile
fragcap targets reconcile --yes
OptionValuesDefaultAvailabilityMeaning
--dbopennoneallOverride FRAGCAP_LOCAL_DB, then the managed per-user local store.
--steam-rootopennoneallOverride automatic Steam installation discovery for the exact platform inventory.
--yesopenfalseallConfirm removal of the exact rows reported by the recomputed preview.

targets scan

Treat positional DIR as one game location. With --catalog-db, attach technology evidence. Discovered candidates are registered idempotently in the resolved local store.

fragcap targets scan "C:\Games\Sample Game"
OptionValuesDefaultAvailabilityMeaning
--catalog-dbopennoneallSelect a catalog store whose signature table labels the directory.
--dbopennoneallOverride FRAGCAP_LOCAL_DB, then the managed per-user local store used to register discoveries.

targets remove

Remove one target selected by positional SELECTOR or --id.

OptionValuesDefaultAvailabilityMeaning
--dbopennoneallOverride FRAGCAP_LOCAL_DB, then the managed per-user local store.
--idopennoneallSelect by durable identifier instead of positional selector.

targets export

Write all registered targets, or positional SELECTOR or --id, as a JSON array to standard output.

fragcap targets export
OptionValuesDefaultAvailabilityMeaning
--dbopennoneallOverride FRAGCAP_LOCAL_DB, then the managed per-user local store.
--idopennoneallExport one target by durable identifier.

targets import

Merge the target-entry JSON array at positional FILE by stable identifier.

fragcap targets import targets.json
OptionValuesDefaultAvailabilityMeaning
--dbopennoneallOverride FRAGCAP_LOCAL_DB, then the managed per-user local store, creating the selected store if absent.

Environment

technologies

Detect engine, anti-cheat, and DRM signatures in an install directory.

fragcap technologies --path "C:\Games\Sample Game"
OptionValuesDefaultAvailabilityMeaning
--catalog-dbopennoneallOverride FRAGCAP_CATALOG_DB, then the managed per-user catalog store containing signatures.
-p, --pathopennoneallRequired install directory to scan.

steam

Group Steam-specific inspection commands.

OptionValuesDefaultAvailabilityMeaning

steam list

List installed Steam titles. Register one with targets add --steam <app_id>.

fragcap steam list

Human output contains no tab separators. It uses an aligned APP ID, NAME, STATE, and TARGET table when every complete row fits the selected 40-through-80 display-column width, then switches the entire result to labeled vertical records when a long or localized value would not fit. Values are never truncated, and positioned, registered without a current listing position, and unregistered titles remain distinct. Use global --json for the unchanged JSON Lines machine interface.

OptionValuesDefaultAvailabilityMeaning

doctor

Report environment readiness. The default is read-only; --fix offers only the remediations already named by the report.

Native Deep Capture residue is shown under a stable native residue label with plain-language ownership, readiness, and review guidance. Long session and resource identities wrap without truncation, and terminals use an aligned or compact layout from 40 through 80 display columns. With global --json, each native residue check retains its existing machine name and adds a native_resource object containing session_id, resource_id, kind, state, health, ownership_authority, and recovery_eligible. Read-only Doctor never performs cleanup; exact eligible records are reviewed and confirmed through fragcap doctor --fix.

fragcap doctor
OptionValuesDefaultAvailabilityMeaning
--fixopenfalseallOffer remediations interactively. Refused with --json or non-interactive standard output.
--timingsopenfalseallPublished since v0.10.1: show phase and nested readiness completion timings on interactive stderr progress. No JSON or final report changes. Historical v0.10.0 accepts this option but hides it and supplies only coarse completion timings.
--yesopenfalseallPre-confirm offered actions with --fix; interactive standard output is still required.

extcap

Serve Wireshark's extcap protocol. Query flags print declarations to standard output; capture streams pcapng to the analyzer-provided FIFO.

OptionValuesDefaultAvailabilityMeaning
--captureopenfalseallStart extcap capture.
--catalog-dbopennoneallOverride FRAGCAP_CATALOG_DB, then the managed per-user catalog store.
--directionboth, in, outnoneallConfigure the requested direction.
--extcap-configopenfalseallPrint configurable extcap options and exit.
--extcap-dltsopenfalseallPrint link types and exit.
--extcap-interfaceopennoneallSelect the extcap interface.
--extcap-interfacesopenfalseallPrint available extcap interfaces and exit.
--extcap-versionopennoneallAccept the analyzer protocol version query; currently not acted on.
--fifoopennoneallAnalyzer FIFO or named-pipe path for capture bytes.
--local-dbopennoneallOverride FRAGCAP_LOCAL_DB, then the managed per-user local store.
--loopbackopenfalseallInclude loopback.
--rolesopennoneallConfigure comma-separated capture roles.
--targetopennoneallSelect the stored target by the same selector grammar as Capture.

extcap install

Register fragcap in Wireshark's extcap directory. With no scope flag, use the per-user directory.

fragcap extcap install --user
OptionValuesDefaultAvailabilityMeaning
--diropennoneallUse an explicit extcap directory instead of a discovered scope.
--systemopenfalseallUse the machine-wide Wireshark directory; write privilege is required.
--useropenfalseallUse %APPDATA%\Wireshark\extcap, the default scope.

extcap uninstall

Remove the corresponding extcap registration. Scope flags have the same precedence as extcap install.

OptionValuesDefaultAvailabilityMeaning
--diropennoneallUse an explicit extcap directory instead of a discovered scope.
--systemopenfalseallUse the machine-wide Wireshark directory.
--useropenfalseallUse the per-user Wireshark directory, the default scope.

Data

bundle

Group explicit lifecycle operations for completed Deep Capture bundles.

OptionValuesDefaultAvailabilityMeaning

bundle cleanup

Delete only artifacts that the completed bundle manifest declares sensitive. The original journal records each intent and result so interrupted cleanup can resume without broad directory deletion.

fragcap bundle cleanup .\fragcap-session --yes
OptionValuesDefaultAvailabilityMeaning
--yesopenfalseallConfirm targeted deletion of the manifest-declared sensitive artifacts.

bundle export

Create a separate share copy containing ordinary artifacts and a complete sharing manifest. The source bundle is never modified.

fragcap bundle export .\fragcap-session --out .\fragcap-session-share
OptionValuesDefaultAvailabilityMeaning
--outopennoneallRequired destination directory for the new share copy.

fresh-start

Preview or irreversibly remove canonical fragcap user data. Preview is read-only and emits an inventory identifier. Execution requires both --confirm with that exact unchanged identifier and --yes. Current-user scope covers only %APPDATA%\fragcap and %LOCALAPPDATA%\fragcap. All-users scope requires an elevated Administrator session and a report path. It enumerates Windows profiles through the operating system profile authority rather than searching the filesystem. Deep Capture evidence in another profile remains for current-user recovery under that profile's Windows trust identity, so such an all-users result is partial until that recovery is complete.

fragcap fresh-start --scope current-user --preview
fragcap fresh-start --scope current-user --confirm <inventory-id> --yes --report .\fresh-start-report.json
OptionValuesDefaultAvailabilityMeaning
--confirmopennoneallRequire the unchanged identifier emitted by the exact preview.
--previewopenfalseallList exact roots, categories, and inventory identity without mutation.
--reportopennoneallWrite the bounded versioned cleanup result to a new local path outside cleanup roots. Required for all-users execution.
--scopeall-users, current-usercurrent-userallSelect one caller profile or the distinct elevated all-users inventory.
--yesopenfalseallConfirm irreversible execution after reviewing the inventory.

Deep Capture session evidence is removed only after Doctor's exact recovery authority reaches safe terminal states. Custom paths, Npcap, Wireshark configuration, and independently managed extcap registrations are excluded. A redirection or recovery failure remains in the report and makes the result partial.

Catalog store options resolve from explicit --db, then FRAGCAP_CATALOG_DB, then %APPDATA%\fragcap\catalog.db. The managed path is the ordinary fallback, not a required argument.

catalog

Group commands for the shipped, disposable catalog store.

OptionValuesDefaultAvailabilityMeaning

catalog import

Load positional SEED, a schema-conformant local JSON export, transactionally.

fragcap catalog import catalog.json
OptionValuesDefaultAvailabilityMeaning
--dbopennoneallOverride FRAGCAP_CATALOG_DB, then the managed per-user catalog store.

catalog export

Write the catalog store as schema-conformant JSON to standard output.

OptionValuesDefaultAvailabilityMeaning
--dbopennoneallOverride FRAGCAP_CATALOG_DB, then the managed per-user catalog store.

catalog seed

Fill one repeatable --tier or every tier with an available source. --from is the hermetic local source. --steam and --pcgamingwiki exist only in an optional network-capable maintainer build.

fragcap catalog seed --tier signature
fragcap catalog seed --tier catalog --from catalog.json
OptionValuesDefaultAvailabilityMeaning
--dbopennoneallOverride FRAGCAP_CATALOG_DB, then the managed per-user catalog store.
--fromopennoneallRead one local source document; requires exactly one consumable --tier.
--min-reviewsopen500allSet the title-tier review-count corpus threshold.
--pcgamingwikiopenfalsenetSeed the engine tier from the live PCGamingWiki query API.
--steamopenfalsenetSeed the title tier from the live Steam catalog.
--tiercatalog, engine, launch, signaturenoneallSelect a tier; repeat as needed. signature is always offline.

schema

Group commands for the embedded master JSON schema.

OptionValuesDefaultAvailabilityMeaning

schema validate

Validate positional FILE and report every structural violation in one pass.

fragcap schema validate targets.json
OptionValuesDefaultAvailabilityMeaning

schema print

Write the embedded master schema to standard output.

OptionValuesDefaultAvailabilityMeaning

Output routing

--json changes presentation, not the ownership of streams. Structured command results, such as target, Steam, doctor, catalog, and schema results, go to standard output. Capture and Deep Capture lifecycle events go to standard error so they cannot contaminate capture bytes. Packet bytes and packet JSON Lines go only to the configured --out, --sink, or extcap FIFO destination. Warnings and errors are diagnostics on standard error.

--quiet suppresses progress but retains authoritative terminal results, warnings, and errors. --silent suppresses optional progress, completion summaries, and warnings; errors and configured sinks remain active. Neither flag hides required complete authorization plans or turns consent into approval. A consumer must parse documented result and lifecycle streams separately; there is no combined JSON stream.