Did you know Little Snitch can also be a network sniffer and save to PCAP files? I didn’t!
I’ve been a Little Snitch user for years. Their latest version had a little hidden gem I stumbled across a few days ago: A network sniffer that saves to PCAP files. I guess it wasn’t really “hidden” but I saw nothing highlighting this feature under the new network monitor. Best of all, it will continue to capture the next time the process starts up.
Check it out:
1. Open your network monitor in your menu bar
2. Right click on any process, and click “Capture Traffic”
3. Choose where you want to save your PCAP file.
4. Capture traffic.
You’ll see a recording icon next to your process. Go ahead and do what you need to do. Then, when you’re done capturing, click Stop Capture
5. Open up your PCAP file in Wireshark.
Boom! Captured packets!