PCAP-over-IP is a method for transmitting captured network traffic through a TCP connection.
[1] The captured network traffic is transferred over TCP as a PCAP file in order to preserve relevant metadata about the packets, such as timestamps.
[2] However, the concept behind PCAP-over-IP was mentioned already in 2008 as part of a feature request for Wireshark.
E.g., ipmb_traced application available on Pigeon Point shelf managers can transmit the capture over the TCP connection without writing it to the filesystem."
Common use cases for PCAP-over-IP include: Software that can sniff network traffic, but doesn't support PCAP-over-IP, can read packets from a PCAP-over-IP provider with help of a netcat and tcpreplay combo.