
汉字 | English
[!IMPORTANT] Supports Linux and Android on x86_64 (kernel 4.18+) and aarch64 (kernel 5.5+). The kernel requirement applies per CPU architecture for both Linux and Android. Requires root privileges or specific Linux capabilities. Does not support Windows or macOS.
[!TIP] Supports Linux/Android on x86_64 and aarch64.
Download the ELF binary package from the releases page, extract it, and run:
sudo ecapture --help
[!TIP] Linux only.
# Pull the Docker image
docker pull gojue/ecapture:latest
# Run it
docker run --rm --privileged=true --net=host -v ${HOST_PATH}:${CONTAINER_PATH} gojue/ecapture ARGS
⚠️ Security note:
--privileged=truegrants full host access. For production use, prefer specific capabilities instead. See the Minimum Privileges Guide.
See Docker Hub for more information.
sudo ecapture tls
eCapture automatically detects the system's OpenSSL library and starts capturing plaintext traffic. When you make an HTTPS request, such as curl https://google.com, the captured request and response are displayed:
...
INF module started successfully. moduleName=EBPFProbeOPENSSL
??? UUID:233851_233851_curl_5_1_172.16.71.1:51837, Name:HTTP2Request, Type:2, Length:304
header field ":method" = "GET"
header field ":path" = "/"
header field ":authority" = "google.com"
...
📄 For complete output examples, see docs/example-outputs.md.
The eCapture tool includes 8 modules that can capture plaintext data from TLS/SSL libraries such as OpenSSL, GnuTLS, NSS/NSPR, BoringSSL, and GoTLS. It also supports auditing commands and queries from Bash, MySQL, and PostgreSQL applications.
You can use ecapture -h to view the full list of subcommands.
eCapture searches the default library paths from /etc/ld.so.conf to locate shared libraries and detect the OpenSSL library location. You can also set the library path explicitly with the --libssl flag.
If the target program is statically linked, you can set the program path directly as the value of the --libssl flag.
The OpenSSL module supports three capture modes:
pcap/pcapng mode stores captured plaintext data in pcap-NG format.keylog/key mode saves TLS handshake keys to a file.text mode captures plaintext data directly, either writing it to a file or printing it to the console.Supports TLS-encrypted HTTP 1.0/1.1/2.0 over TCP and HTTP/3 (QUIC) over UDP.
You can specify -m pcap or -m pcapng together with --pcapfile and -i. The default value of --pcapfile is ecapture_openssl.pcapng.
sudo ecapture tls -m pcap -i eth0 --pcapfile=ecapture.pcapng tcp port 443
This command saves captured plaintext packets as a pcapng file, which can be opened with Wireshark.
📄 For complete pcapng mode output, see docs/example-outputs.md.
You can specify -m keylog or -m key together with the --keylogfile option. The default output file is ecapture_masterkey.log.
The captured OpenSSL TLS master secret is saved to --keylogfile. You can also enable tcpdump capture and then open the file in Wireshark, setting the master secret path to view plaintext packets.
sudo ecapture tls -m keylog -keylogfile=openssl_keylog.log
You can also use tshark for real-time decryption and display:
tshark -o tls.keylog_file:ecapture_masterkey.log -Y http -T fields -e http.file_data -f "port 443" -i eth0
sudo ecapture tls -m text
This outputs all plaintext data packets.
Similar to the OpenSSL module.
gotls commandCapture TLS plaintext data.
Step 1:
sudo ecapture gotls --elfpath=/home/cfc4n/go_https_client --hex
Step 2:
/home/cfc4n/go_https_client
sudo ecapture gotls -h
Modules such as bash, mysqld, and postgres can also be used. You can view the full list with ecapture -h.
eCaptureQ is a cross-platform graphical client for eCapture that visualizes eBPF-based TLS capture capabilities. Built with Rust + Tauri + React, it provides a responsive, real-time interface for analyzing encrypted traffic without needing a CA certificate. It simplifies complex eBPF capture workflows and makes them easier to use.
It supports two modes: