Which protocol captures full packet data at the network level and is commonly analyzed in network forensics investigations?