Android packet capture without root
Netyvo Network Inspector helps you understand connections made by your own Android device. Capture TCP and UDP traffic locally through Android VpnService, inspect protocols and export captures without root access.
How does Network Inspector work?
You start inspection explicitly in the app. Netyvo uses Android's local VPN interface to inspect traffic on your device, including traffic from selected apps. This capture mode cannot run at the same time as another active VPN.
What can you inspect?
- TCP and UDP packets, IPv4 and IPv6, and protocol-layer details.
- DNS queries, TLS handshake metadata and unencrypted HTTP traffic.
- Network flows, traffic statistics, search and HEX/ASCII packet views.
- PCAP and PCAPNG exports, plus JSON, CSV and HTML reports.
How to capture Android packets and export a PCAPNG file
Example: you want to inspect which network services a selected app contacts. These steps reflect the actual Netyvo Network Inspector controls. The module is designed for Android phones; availability may depend on your installed app version.
- Open Network Inspector in Netyvo on your Android phone. Under “Capture from”, choose the entire device or selected apps. For selected apps, tap “Select applications”.
- Tap “Start capture” and approve Android's VPN consent prompt. Netyvo uses a local VpnService, so another active VPN — including the Netyvo DNS VPN — cannot run at the same time.
- Open your own test app or website and reproduce the network activity you want to examine. Return to Inspector and open the “Connections” or “Packets” tab.
- Use “Filter” to search by domain, address, port, “DNS”, “TCP”, “UDP” or “TLS”. Open a flow or packet to inspect available protocol details, HEX/ASCII bytes and metadata.
- Tap “Stop capture”. Under “Tools”, choose “Export PCAPNG” or “Export classic PCAP”, then select the destination. Stop the capture before exporting a complete saved session.
- For a shareable summary without raw packet bodies, choose “Export JSON / CSV / HTML report” under “Tools”. The reports omit packet payloads, authentication details, tokens and cookies; IP addresses are excluded by default.
Example: diagnose one app's network connections
Select only the app you want to examine and start capture. Open its screen that makes a network request, then look for new sessions under “Connections”. Filter by TCP, UDP or port and compare the packet counters. DNS names and TLS SNI may be visible when not encrypted; HTTPS content is not decrypted.
PCAPNG or a JSON report: which should you share?
PCAP and PCAPNG contain original packet bytes and are not redacted. Treat these files as sensitive and do not publish them openly. JSON/CSV/HTML reports include metadata and counters but omit raw payloads. Analyze only network traffic you are authorized to inspect.
Optional live monitoring
Start read-only live sharing explicitly on your phone to make a temporary connection summary available over your local network (LAN). The viewer requires a token and expires after 15 or 60 minutes. Raw packets are not shared. The experimental Cloudflare Quick Tunnel integration in the source belongs to the separate PacketScope app, not the built-in Netyvo module.
Important limitations
Encrypted HTTPS content is not decrypted. Use packet capture only for authorized analysis of traffic on your own device. Netyvo is not a location-changing VPN.
Do I need root access?
No. Capture runs through Android's local VpnService interface after you explicitly start the feature.
How to capture TCP/UDP packets on Android without root?
Netyvo Network Inspector uses the local Android VpnService, so root access is not required. You can inspect connections and export PCAP/PCAPNG files, but it does not automatically decrypt HTTPS content.