Packet Captures is fundamental for any attack detection. As the saying goes , "If there is no pcap, it did not happen !" . So any intrusion detection paper would need pcaps !
Packet payloads are also used to verify an attack, even if discovered by other means. If you have the full packet capture, you can verify what the attack is, even if it's encoded or obfuscated to bypass defensive mechanisms.