---
title: "Network Capture | 100Gbps Packet Capture for Trading | Pico"
description: "Market-leading network capture platform optimized for trading environments: up to 100Gbps with compression, encryption, deep buffering, and industry-leading price/performance."
source: https://www.pico.net/products/corvil-analytics/network-capture/
markdown_url: https://www.pico.net/products/corvil-analytics/network-capture.md
---

# Corvil Network Capture
Market-leading network capture platform optimized for trading environments: complete and reliable packet capture preventing loss even through sudden large and extended bursts of traffic at market open and close.

- Up to 100Gbps capture with industry-leading price/performance
- AES-256 hardware encryption at rest with 3x streaming compression
- Deep buffering: size for average rates, handle 10x burst peaks
- PTP clock synchronization for precision nanosecond timestamps

## What is Corvil Network Capture?

Corvil Network Capture is a fully distributed packet capture architecture that scales linearly as deployment grows. The platform offers storage from 3 TB to hundreds of TB per device, creating a distributed packet data system containing potentially petabytes of packets queryable from a single interface. It supports all leading network packet broker port tagging and timestamping capabilities with programmatic API for packet capture filtering and export.

## Capabilities and related products

### Compression & Encryption

3x streaming compression maximizes storage. AES-256 hardware encryption at rest for data security.

### Modular Upgrades

Flexible module-based system enables upgrade paths from Network Capture to Network Analytics and Trading Analytics.

### Trading Analytics

Full Corvil Analytics platform with 600+ decoders, Intelligence Hub, and real-time trading intelligence.

### Corvil APIs & SDK

Programmatic packet capture filtering and export API for forensic analysis and custom automation.

### Corvil Center

Centralized management: query petabytes of distributed packet data from a single search interface.

## Use cases for Network Capture

### Forensic Investigations

- Full packet capture for regulatory forensics and compliance audit trails
- Familiar query and filter syntax including tshark and BPF

### Issue Resolution

- Rapidly distinguish between network and server-originated issues
- Lower MTTR with per-packet metrics instead of 1-second averages

### Team Collaboration

- Faster collaboration and reduced finger-pointing across teams
- No configuration required, low cost of ownership for network operations

### Regulatory Compliance

- AES-256 encrypted packet store for secure long-term retention
- PTP-synchronized nanosecond timestamps for audit-grade evidence

## Frequently asked questions

Everything you need to know about Corvil Network Capture.

### What is Corvil Network Capture?

Corvil Network Capture is a distributed packet capture platform optimized for trading environments. It supports up to 100Gbps per appliance with storage from 3 TB to hundreds of TB per device, creating a system containing potentially petabytes of packets that can be queried from a single Corvil Center interface.

### How does Network Capture handle burst traffic?

Deep buffering allows you to size your monitoring infrastructure for average traffic rates rather than burst peaks, which can be 10x or more above average at market open and close. Combined with automatic 3x streaming compression, this maximizes disk capacity and historical access to packets while preventing capture loss during traffic spikes.

### How is captured data secured?

All data is automatically hardware-encrypted at rest using AES-256 encryption, ensuring a high level of data security for captured packet data. This is critical for financial trading environments where packet captures contain sensitive order and market data.

### How much storage does Network Capture support?

Storage ranges from 3 TB to hundreds of TB per device. With 3x streaming compression, effective capacity is tripled. The distributed architecture creates a system containing potentially petabytes of packets, all queryable from a single Corvil Center interface.

### Can Network Capture be upgraded to full analytics?

Yes. The modular system enables upgrade paths from Network Capture to Network Analytics and Trading Analytics without replacing hardware. Simply add analytics modules to transform packet capture appliances into full analytics platforms.

### What packet broker integrations are supported?

Network Capture supports port tagging and timestamping capabilities from all leading network packet broker vendors. It can capture multiple copies of packets from aggregation taps without deduplication, preserving the complete record for forensic analysis.

### How does PCAP export work?

Turbo export provides a responsive experience even when capturing at high speed. Users can one-click download PCAP files to desktop using familiar tshark and BPF filter syntax. The Corvil API also supports programmatic packet capture filtering and export for automated forensic workflows.

## Deploy enterprise packet capture

Talk to a Corvil specialist about deploying Network Capture in your trading infrastructure.