# Save traffic in pcap file or best way to log post data

**URL:** <https://discourse.mitmproxy.org/t/save-traffic-in-pcap-file-or-best-way-to-log-post-data/177>\
**Category:** help\
**Created:** [September 25, 2016, 10:43pm UTC](https://discourse.mitmproxy.org/t/save-traffic-in-pcap-file-or-best-way-to-log-post-data/177 "2016-09-25T22:43:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![phackt](https://avatars.discourse-cdn.com/v4/letter/p/bc79bd/32.png) [@phackt](https://discourse.mitmproxy.org/u/phackt)\
**Post date:** [September 25, 2016, 10:43pm UTC](https://discourse.mitmproxy.org/t/save-traffic-in-pcap-file-or-best-way-to-log-post-data/177/1 "2016-09-25T22:43:28Z")

</div>

Hello Everybody,

My question is, is there a way to store traffic in pcap format, and if not what is the best option to log post data?  
With option -w/-a all html traffic is logged, we can replay it with mitmdump but my aim is only at filtering sensitive logged data from post requests. Is the only alternative to write a script for that?

Thanks in advance,  
Phackt.

---

<div class="post-metadata">

**Author:** ![mhils](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/mhils/32/7_2.png) [@mhils](https://discourse.mitmproxy.org/u/mhils)\
**Post date:** [September 26, 2016, 2:35am UTC](https://discourse.mitmproxy.org/t/save-traffic-in-pcap-file-or-best-way-to-log-post-data/177/2 "2016-09-26T02:35:39Z")

</div>

> [@phackt](#):
>
> is there a way to store traffic in pcap forma

I would just use Wireshark next to mitmproxy for that. mitmproxy can log [TLS master secrets](http://docs.mitmproxy.org/en/stable/dev/sslkeylogfile.html) so that Wireshark can decrypt TLS packets.

> [@phackt](#):
>
> With option -w/-a all html traffic is logged, we can replay it with mitmdump but my aim is only at filtering sensitive logged data from post requests.

By filtering, you mean “only store/save/persist flows which are POST requests”? The first thing you can do is only save flows that match a certain pattern, e.g. by using mitmdump’s filter argument: `mitmdump -w dump.mitm '~m POST'` (or `mitmdump -r dump.mitm -w dump-filtered.mitm '~m POST'`. Depending on how small you want things to become, you can also delete the corresponding response or only the response body.

Does that make sense?

---

<div class="post-metadata">

**Author:** ![phackt](https://avatars.discourse-cdn.com/v4/letter/p/bc79bd/32.png) [@phackt](https://discourse.mitmproxy.org/u/phackt)\
**Post date:** [September 26, 2016, 7:20am UTC](https://discourse.mitmproxy.org/t/save-traffic-in-pcap-file-or-best-way-to-log-post-data/177/3 "2016-09-26T07:20:20Z")

</div>

Yeah thanks Maximilian, also i just read that objects are dumped thanks to tnetstrings. My purpose is just to save headers in order to minimize log files, i think ~m [post|get] ~h will do the trick for post and get requests/responses.

Phackt.

---

<div class="post-metadata">

**Author:** ![mhils](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/mhils/32/7_2.png) [@mhils](https://discourse.mitmproxy.org/u/mhils)\
**Post date:** [September 26, 2016, 8:01am UTC](https://discourse.mitmproxy.org/t/save-traffic-in-pcap-file-or-best-way-to-log-post-data/177/4 "2016-09-26T08:01:32Z")

</div>

> [@phackt](#):
>
> i think ~m [post|get] ~h will do the trick for post and get

You are misunderstanding filters here. We are always saving full flows, you can just filter which ones are saved based on a header value. This will not limit the dump file to headers only.

---

<div class="post-metadata">

**Author:** ![phackt](https://avatars.discourse-cdn.com/v4/letter/p/bc79bd/32.png) [@phackt](https://discourse.mitmproxy.org/u/phackt)\
**Post date:** [September 26, 2016, 8:19am UTC](https://discourse.mitmproxy.org/t/save-traffic-in-pcap-file-or-best-way-to-log-post-data/177/5 "2016-09-26T08:19:52Z")

</div>

Ok thanks Maximilian so i will look how to process dump files on my side to extract only headers information.

---

<div class="post-metadata">

**Author:** ![erik4711](https://avatars.discourse-cdn.com/v4/letter/e/c37758/32.png) [@erik4711](https://discourse.mitmproxy.org/u/erik4711)\
**Post date:** [June 26, 2019, 8:50am UTC](https://discourse.mitmproxy.org/t/save-traffic-in-pcap-file-or-best-way-to-log-post-data/177/6 "2019-06-26T08:50:10Z")

</div>

You can use PolarProxy (another free TLS proxy) if you wanna save the decrypted TLS traffic in a PCAP file.  
[https://www.netresec.com/?page=PolarProxy](https://www.netresec.com/?page=PolarProxy)
