Documentation

Sessions

A capture you can hand to someone else next week.

1. Saving and opening

Save writes the capture to a .cms session file. Opening one restores the frames and the view configuration, so the person reading it sees what you saw.

  • Open from the toolbar, by dragging the file onto the window, or by passing the file on the command line.
  • The .cms extension can be associated with the application, so a double click opens it.
  • Sessions written by older versions of the product can still be opened; the reader supports both the current and the legacy format.

2. What is inside the file

The current format has a fixed 256-byte header, a block index, and records grouped in blocks of 4096 frames. Each record carries its own header with a CRC, which is what makes a partially written session still recoverable.

  • The header stores the session name, the format version, the frame count, the totals for reads and writes, and the view flags.
  • The block index lets a reader jump to a frame without replaying everything before it.

3. Password protection

If you protect a session with a password, the payload is encrypted with AES-256-GCM, using a key derived from your password with PBKDF2-SHA256.

  • Without a password, the file falls back to the legacy obfuscation, which only stops someone reading it in a hex editor.
  • The header records which mode was actually used, so a file is never mistaken for something stronger than it is.
  • A forgotten password cannot be recovered: there is no back door, by design.

Applies to version 14.0.0.26002 · All documentation

Next: redirect and export

Writing traffic to files while it is still arriving.