How to creat or edit **.pcap file to test suricata?

Hello!

I am not familiar with the process of editing pcaps.
But I know of some tools that might help you:

  • Scapy allows one to create pcaps from scratch: https://scapy.net/
    (maybe it’s also possible to edit existing pcaps with that, but I’m unware)
  • There’s also this, for editing (I have never used it): Tshark | Edit Pcap

Hope that helps!