# tcpflow > Extract and reassemble TCP streams from PCAP files into individual files **Category:** [[categories/explore-network-interactions-monitoring|Explore Network Interactions > Monitoring]] | **Tier:** Rich (FOR610) **Docs:** [https://docs.remnux.org/discover-the-tools/explore+network+interactions/monitoring](https://docs.remnux.org/discover-the-tools/explore+network+interactions/monitoring) ## Usage ```bash tcpflow -r -o output/ ``` ## Recipes - [[recipes/pcap-file-carving|Extract Files from Network Capture]] ## Workflows - [[workflows/network-interception-workflow|Network Traffic Interception]] — Step 6: Traffic Analysis ## Related Tools - [[tools/burp-suite-community-edition|Burp Suite Community Edition]] — Investigate website interactions using this web proxy. - [[tools/cs-parse-traffic|cs-parse-traffic.py]] — Decrypt and parse Cobalt Strike beacon network traffic using - [[tools/mitmproxy|mitmproxy]] — Interactive HTTPS proxy for intercepting, inspecting, and mo - [[tools/network-miner-free-edition|Network Miner Free Edition]] — Examine network traffic and carve PCAP capture files. - [[tools/ngrep|ngrep]] — Search network traffic for patterns — like grep for packets #network #tcp #stream-extraction