PCAPdroid
by Emanuele Faranda · GPL-3.0-or-later · open source
See every connection your apps make, without root. PCAPdroid captures traffic through a local VPN on the phone, lets you inspect and export it, and can decrypt HTTPS.
Needs:No root · Android 6.0+
2113 Apps is independent, not affiliated with or endorsed by Emanuele Faranda. Official sources: emanuele-f.github.io · source code on GitHub.
- Version
- 2.0.2
- Size
- 17.6 MB
- Requires
- Android 6.0+
- Updated
- 2026-09-22
Screenshots





Introduction
PCAPdroid tracks and analyses the connections the other apps on your phone make. It captures traffic without root by simulating a VPN: the data is processed on the phone itself and not sent to any remote server.
What it does for free
From the project’s README:
- A live list of connections per app, with the domains and addresses they reach.
- PCAP export of the captured traffic, or streaming it live to a computer (PCAP-over-IP), for example into Wireshark.
- HTTP inspection, with export to HAR files.
- HTTPS decryption, with URLs extracted and the TLS keys saved. The decryption itself is done by the separate PCAPdroid mitm add-on, which runs mitmproxy on the phone. The add-on version this release expects, 2.4, is the one we host.
Paid features
A firewall for blocking apps, domains and addresses, malware detection based on third-party blocklists, and PCAPng export are paid, in every build. For F-Droid and GitHub builds, the documentation explains how to use an unlock token bought through the Google Play app. The firewall doesn’t work in root capture mode.
Limits
- On Android 7 and later, most apps no longer trust user-installed certificates, and the documentation says a rooted device helps in most such cases. QUIC traffic can’t be decrypted yet.
- Running alongside another VPN app requires root, which lets PCAPdroid capture without the VPN slot. Otherwise, switch off any always-on VPN first.
About this file
This is F-Droid’s build of version 2.0.2, from September 2026, signed with F-Droid’s key. Google Play has the same app from the same developer, with in-app purchases; the two are signed differently and don’t update each other. The 17.6 MB file runs on ARM and x86, 32- and 64-bit, and declares 14 permissions.
What’s inside the APK
Trackers
No code matching the Exodus Privacy tracker signatures.
Native code
Runs on 64-bit and older 32-bit ARM phones.
Android versions
Built for Android 17 (target API 37).
Permissions
3 of them need your approval first.
CPU types in this build: arm64-v8a (64-bit ARM, almost every phone since 2017); armeabi-v7a (32-bit ARM, older and budget phones); x86 (32-bit Intel, emulators); x86_64 (64-bit Intel, emulators and Chromebooks).
Asks you first (3)
Android shows a prompt before the app can use these.
- Show notifications (Android 13+) · POST_NOTIFICATIONS
- Read shared storage (Android 12 and older) · READ_EXTERNAL_STORAGE
- Write shared storage (Android 10 and older) · WRITE_EXTERNAL_STORAGE
System-level (1)
Reserved for system apps. A normal install does not get these; they only take effect through root, ADB or Shizuku, if at all.
- INTERACT_ACROSS_USERS
Granted at install (9)
Low-risk permissions Android grants automatically, plus any we have not classified.
- ACCESS_LOCAL_NETWORK
- ACCESS_NETWORK_STATE
- ACCESS_WIFI_STATE
- FOREGROUND_SERVICE
- FOREGROUND_SERVICE_SPECIAL_USE
- INTERNET
- QUERY_ALL_PACKAGES
- RECEIVE_BOOT_COMPLETED
- WRITE_CLIPS
Defined by other apps (1)
Permissions that belong to another app or to this app itself.
- com.emanuelef.remote_capture.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
More Information
- Package name
- com.emanuelef.remote_capture
- Version
- 2.0.2 (build 95)
- File size
- 17.6 MB (17,560,048 bytes)
- Requires
- Android 6.0 or later
- Category
- Network & Privacy
- License
- GPL-3.0-or-later
- Developer
- Emanuele Faranda
- Source code
- github.com/emanuele-f/PCAPdroid
- Released
- Sep 22, 2026
- Signed by
- F-Droid, which built this APK from the published source code. Because the key is F-Droid’s, it won’t install over a copy from Google Play or GitHub (or the other way round) without uninstalling first.
- Signer SHA-256
- 9fdd93b62bcc95e86ff681a401f81653e37626e83369a3e192e060f2a3ca147d
- File SHA-256
- e03f79082278b3754b4954c7537e7c9f7681e5995a44e70aa1589eca10190066
- Checked
- , against the F-Droid index · how we check · verify it yourself
Common questions
Is this APK the official PCAPdroid release?
It is F-Droid’s build rather than the developer’s own: F-Droid compiled PCAPdroid 2.0.2 from the published source code and signed it with its own key. Its SHA-256 matches F-Droid’s signed index. Because the key is F-Droid’s, it won’t install over a copy from Google Play or GitHub without uninstalling first.
What Android version does PCAPdroid need?
Android 6.0 or later (API level 23). Version 2.0.2 is built for Android 17 (target API 37). Runs on 64-bit and older 32-bit ARM phones.
Can PCAPdroid access the internet?
Yes. The APK requests Android’s internet permission. In total it declares 14 permissions, and 3 of them need your approval first.
Does PCAPdroid contain trackers?
No known trackers: our scan of version 2.0.2 found no code matching the Exodus Privacy tracker signatures. The scan covers known tracker libraries; it doesn’t show what data the app itself sends.
Is PCAPdroid open source?
Yes. PCAPdroid is released under the GPL-3.0-or-later licence, and its source code is published at https://github.com/emanuele-f/PCAPdroid.
Recent releases
| Version | Released | Size | Requires |
|---|---|---|---|
| v2.0.2 · this download | Sep 22, 2026 | 17.6 MB | Android 6.0+ |
| v2.0.1 | Sep 12, 2026 | 17.5 MB | Android 6.0+ |
| v2.0.0 | Aug 23, 2026 | 17.5 MB | Android 6.0+ |
Versions currently kept in the F-Droid repository. We host and check only the newest one. Full changelog.