Skip to main content

A premium interactive CLI network traffic analyzer with Gemini AI integration

Project description

โšก AuraSniff

AuraSniff Logo

A premium, interactive terminal-based network packet capture (PCAP) analyzer with built-in Gemini AI assistance.

PyPI version Python Support License: MIT GitHub stars


๐ŸŒŸ Introduction

AuraSniff is a lightweight, zero-dependency command-line interface (CLI) that brings advanced network forensics and artificial intelligence to your terminal. It parses .pcap and .pcapng files locally without relying on heavy external software or standard Wireshark installations, computes connection metrics, extracts cleartext login credentials, and features a chat shell where you can query your network captures in natural language using Gemini.


๐Ÿš€ Core Features

  • โšก Zero-Dependency Dissection: Streams and parses capture files locally using Scapy. You don't need Wireshark or tshark installed.
  • ๐Ÿ”‘ Credentials Harvester: Automatically intercepts and displays cleartext logins across HTTP-POST, FTP, SMTP, POP3, and IMAP payloads.
  • ๐Ÿšจ Security Anomaly Engine: Identifies network anomalies in real-time, including:
    • Port Scanning: Highlights hosts hitting multiple distinct ports in short intervals.
    • ARP Spoofing: Detects multiple MAC addresses claiming the same IP.
    • DNS Tunneling: Flagging abnormally long, high-entropy query names (indicative of C2/Exfiltration).
    • Cleartext passwords: Warns you about insecure login transmissions.
  • ๐Ÿ’ฌ Gemini AI Chat REPL: Launch an interactive shell to ask questions like "Who is scanning ports?" or "What did the device with IP 192.168.1.15 do?". Gemini translates your questions into local database search filters and answers in markdown.
  • ๐Ÿ” Deep Hex Inspection: Drill down into individual packets to view a structured tree of layers (Ethernet โžœ IP โžœ TCP โžœ Payload) alongside a color-coded side-by-side Hex & ASCII dump.

๐ŸŽจ Visual Preview

AuraSniff's terminal interface is built with Rich for a clean, cyber-neon theme:

The Dashboard (aurasniff analyze)

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ โ–ฒ AURA SNIFF PCAP ANALYZER โ–ฒ                                               โ”‚
โ”‚ Premium Command Line Traffic Inspector & AI Security Assistant             โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ Capture Summary โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”โ”Œโ”€โ”€โ”€โ”€ Protocol Distribution โ”€โ”€โ”€โ”€โ”
โ”‚ File Path:   home.pcapng                        โ”‚โ”‚ Protocol  Count  Ratio        โ”‚
โ”‚ Packets:     46                                 โ”‚โ”‚ TCP          42  91.3% โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ โ”‚
โ”‚ Data Size:   3.2 KB                             โ”‚โ”‚ UDP           4   8.7% โ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘ โ”‚
โ”‚ Duration:    23.0 s                             โ”‚โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ ๐Ÿ”‘ Extracted Credentials โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Pkt # โ”‚ Protocol  โ”‚ Source       โ”‚ Destination   โ”‚ Credentials Info         โ”‚
โ”‚   8   โ”‚ HTTP-POST โ”‚ 192.168.1.15 โ”‚ 93.184.216.34 โ”‚ User: admin / Pass: 123  โ”‚
โ”‚  13   โ”‚ FTP       โ”‚ 192.168.1.15 โ”‚ 192.168.1.5   โ”‚ User: admin / Pass: test โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Deep Packet Hexdissection (detail 8)

Packet #8
โ”œโ”€โ”€ Ether (dst=00:11:22:33:44:00, src=00:11:22:33:44:55, type=2048)
โ”œโ”€โ”€ IP (version=4, ihl=5, proto=6, src=192.168.1.15, dst=93.184.216.34)
โ”œโ”€โ”€ TCP (sport=49152, dport=80, flags=PA, window=8192)
โ””โ”€โ”€ Raw (load=b'POST /login HTTP/1.1\r\nHost: example.com...)

Raw Packet Hex/ASCII Dump:
0000  00 11 22 33 44 00 00 11  22 33 44 55 08 00 45 00  |.."3D..."3DU..E.|
0010  00 df 00 01 00 00 40 06  82 86 c0 a8 01 0f 5d b8  |......@.......].|
0020  d8 22 c0 00 00 50 00 00  00 00 00 00 00 00 50 18  |."...P........P.|
0030  20 00 f4 73 00 00 50 4f  53 54 20 2f 6c 6f 67 69  | ..s..POST /logi|
0040  n  20 48 54 54 50 2f 31  2e 31 0d 0a 48 6f 73 74  |n HTTP/1.1..Host|
0050  3a 20 65 78 61 6d 70 6c  65 2e 63 6f 6d 0d 0a 75  |: example.com..u|

โš™๏ธ Installation

Install the package globally via pip:

pip install aurasniff

๐Ÿ› ๏ธ Usage Guide

1. Interactive AI Chat Shell

Launch the prompt loop to inspect, query, and dissect the capture file:

aurasniff shell <path_to_file.pcap>
  • Type dns to show DNS lookup history.
  • Type http to see HTTP connections.
  • Type creds to print extracted credentials.
  • Type alerts to view detected threats.
  • Type detail <pkt_index> (e.g. detail 8) to run deep dissection and hex dumps.
  • Ask questions like: "Did any local laptop connect to standard DNS servers?" or "Which host triggered the port scanning alert?"

2. General Dashboard Scan

Generate a visual summary of the packet capture:

aurasniff analyze <path_to_file.pcap>

3. Quick AI Query

Run a single natural language question directly from your system command line:

aurasniff query <path_to_file.pcap> "explain the security alerts found"

4. Configure Gemini API Key

To enable the AI capabilities, save your Gemini API Key locally:

aurasniff config set-key <YOUR_GEMINI_API_KEY>

Note: If no API key is saved, the tool falls back to a local offline keyword routing parser.


๐Ÿ”’ Security & Privacy Disclosures

  1. Local Processing: AuraSniff performs all packet parsing, dissection, database storage, and filtering locally on your machine.
  2. Minified Context: When utilizing the Gemini AI features, AuraSniff does not upload your raw binary PCAP file. Instead, it generates a minified text-based summary of metadata (hostnames, domain lookups, connection metrics, and alert titles) and sends only this summary alongside your prompt to the Gemini API. Your actual packet payloads remain 100% private.
  3. The HTTPS Limitation: Like any passive packet sniffer, AuraSniff cannot decrypt TLS/HTTPS traffic (Port 443) without session keys. If you log in to a secure website like GitHub, the credentials will be encrypted before hitting the network interface. To test credential sniffing, capture traffic on unencrypted services (e.g., local development servers running HTTP, legacy router dashboards, or raw FTP).

๐Ÿ“„ License

This project is licensed under the MIT License - see the LICENSE file for details.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

aurasniff-0.1.2.tar.gz (23.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

aurasniff-0.1.2-py3-none-any.whl (21.7 kB view details)

Uploaded Python 3

File details

Details for the file aurasniff-0.1.2.tar.gz.

File metadata

  • Download URL: aurasniff-0.1.2.tar.gz
  • Upload date:
  • Size: 23.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for aurasniff-0.1.2.tar.gz
Algorithm Hash digest
SHA256 d9ff76656a4e31e5fd0ffa2a28a51a0895276317d7bf962ccf730727ba106a3b
MD5 a432d09540ac18a7fa22875395abfa84
BLAKE2b-256 52225fffd11f1869689a433a9714179f18218ed2314c818d8437785d11fbd9e3

See more details on using hashes here.

Provenance

The following attestation bundles were made for aurasniff-0.1.2.tar.gz:

Publisher: publish.yml on vatsalgargg/aurasniff

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file aurasniff-0.1.2-py3-none-any.whl.

File metadata

  • Download URL: aurasniff-0.1.2-py3-none-any.whl
  • Upload date:
  • Size: 21.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for aurasniff-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 a184ec6f1c22ad8f68ee708f0dad8f273cc0d5b57b4fe411adf7687f1b15878e
MD5 7925207a6e03531c5d4ce2b1769241cb
BLAKE2b-256 743180bd919856c6ea8ede26b3b4e24da8ba971db74035b7f4d58f225727eb1c

See more details on using hashes here.

Provenance

The following attestation bundles were made for aurasniff-0.1.2-py3-none-any.whl:

Publisher: publish.yml on vatsalgargg/aurasniff

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page