Skip to main content

IoT Inspector 3

Rufflibinspector_testcodecov

If the underlying dependencies is updated, please run the following first:

uv cache clean
uv lock
uv sync

User guide

Please review the User Guide for instructions how to run IoT Inspector.

Running on Windows

You have two options

  1. Click IoT Inspector.lnk
  2. Run start.bat on your terminal

It will spawn a new PowerShell admin shell to run IoT Inspector. For first time installation, you need to run start.bat twice, as uv requires a shell refresh.

For a detailed guide, see how to use IoT Inspector for Windows here.

Running on Mac

This assumes that you currently have brew installed. Once done, run the ./start.bash script to both install and run IoT Inspector.

Running on Linux

This assumes that you have either apt, yum of dnf package managers first, which should come by default with your Linux distribution.

Once done, run the ./start.bash script to both install and run IoT Inspector.

Developer Guide

If you are developing IoT Inspector, please read this section.

Database Schema

When presenting network stats, IoT Inspector reads from an internal SQLite database. To see how the packet collector and database is implemented, look at the IoT Inspector Core package.

You should always read from the database using the following approach:

import libinspector.global_state
db_conn, rwlock = libinspector.global_state.db_conn_and_lock
with rwlock:
    db_conn.execute("SELECT * FROM devices")

The schema is as follows:

CREATE TABLE devices (
    mac_address TEXT PRIMARY KEY,
    ip_address TEXT NOT NULL,
    is_inspected INTEGER DEFAULT 0,
    is_gateway INTEGER DEFAULT 0,
    updated_ts INTEGER DEFAULT 0,
    metadata_json TEXT DEFAULT '{}'
);

CREATE TABLE hostnames (
    ip_address TEXT PRIMARY KEY,
    hostname TEXT NOT NULL,
    updated_ts INTEGER DEFAULT 0,
    data_source TEXT NOT NULL,
    metadata_json TEXT DEFAULT '{}'
);

CREATE TABLE network_flows (
    timestamp INTEGER,
    src_ip_address TEXT,
    dest_ip_address TEXT,
    src_hostname TEXT,
    dest_hostname TEXT,
    src_mac_address TEXT,
    dest_mac_address TEXT,
    src_port TEXT,
    dest_port TEXT,
    protocol TEXT,
    byte_count INTEGER DEFAULT 0,
    packet_count INTEGER DEFAULT 0,
    metadata_json TEXT DEFAULT '{}',
    PRIMARY KEY (
            timestamp,
            src_mac_address, dest_mac_address,
            src_ip_address, dest_ip_address,
            src_port, dest_port,
            protocol
        )
);

IoT Inspector Helper Scripts

We also include two scripts to help with development and debugging.

Anonymize

After installing IoT Inspector, you can run the following command:

anonymize -i <input_pcap_file> -o <output_pcap_file>

Here is the help output

anonymize -h
usage: anonymize [-h] [-i INPUT_FILE] [-o OUTPUT]

Anonymize MACs and filter specific control packets (DHCP, SSDP, MDNS) from a PCAP file.

options:
  -h, --help            show this help message and exit
  -i INPUT_FILE, --input INPUT_FILE
                        The path to the input PCAP file.
  -o OUTPUT, --output OUTPUT
                        The path to save the anonymized PCAP file (default: sanitized_output.pcap).

The output PCAP file will have all

  • MAC addresses anonymized
  • all DHCP, SSDP, and MDNS packets removed.

This is useful for sharing PCAP files without revealing sensitive information.

PCAP Time Series

After installing IoT Inspector, you can run the following command:

time-series -i <PCAP_FILE/PCAP_DIRECTORY> -m <TARGET_MAC> --b <BIN_SIZE_IN_SECONDS>

Here is the help output

usage: time_series [-h] -i INPUT_FILE -m TARGET_MAC [--interval INTERVAL]

Analyze PCAP file to plot upload and download traffic over time for a specific MAC address.

options:
  -h, --help            show this help message and exit
  -i INPUT_FILE, --input INPUT_PATH
                        The path to the input PCAP file or directory with PCAP files.
  -m TARGET_MAC, --target-mac TARGET_MAC
                        The MAC address of the device to analyze (e.g., 'aa:bb:cc:dd:ee:ff').
  -b BIN_SIZE, --bin BIN_SIZE
                        The width of time bins in seconds for aggregating traffic data (default: 0.05 seconds).

The output will be a PNG file showing the upload and download traffic over time for the specified MAC address. This is useful for visualizing traffic patterns of a device in a PCAP file. An example is shown here.

To visualize the console output, if you pass a directory it would look something like this:

pcap_time_series -i C:/Users/andre/OneDrive/Desktop/packets/AndrewQuijano -m <MAC-ADDRESS>

INFO: Starting analysis for: C:/Users/andre/OneDrive/Desktop/packets/AndrewQuijano\Amazon Echo Show\Use a voice command to ask for time\Mar-20-2026_05-31-52PM_UTC_21.00s.pcap
INFO: Target MAC for analysis: <MAC-ADDRESS>
INFO: Time bin size: 0.05 seconds
Processing: C:/Users/andre/OneDrive/Desktop/packets/AndrewQuijano\Amazon Echo Show\Use a voice command to ask for time\Mar-20-2026_05-31-52PM_UTC_21.00s.pcap
INFO: Read 209 packets. Starting data processing...
INFO: Generating plot...
Processing: C:/Users/andre/OneDrive/Desktop/packets/AndrewQuijano\Amazon Echo Show\Use a voice command to ask for time\Mar-20-2026_05-33-30PM_UTC_22.00s.pcap
INFO: Successfully saved plot to 'C:/Users/andre/OneDrive/Desktop/packets/AndrewQuijano\Amazon Echo Show\Use a voice command to ask for time\Mar-20-2026_05-31-52PM_UTC_21.00s_bin_0.05s.png'
INFO: Starting analysis for: C:/Users/andre/OneDrive/Desktop/packets/AndrewQuijano\Amazon Echo Show\Use a voice command to ask for time\Mar-20-2026_05-33-30PM_UTC_22.00s.pcap
INFO: Target MAC for analysis: <MAC-ADDRESS>
INFO: Time bin size: 0.05 seconds
INFO: Read 222 packets. Starting data processing...
INFO: Generating plot...
INFO: Successfully saved plot to 'C:/Users/andre/OneDrive/Desktop/packets/AndrewQuijano\Amazon Echo Show\Use a voice command to ask for time\Mar-20-2026_05-33-30PM_UTC_22.00s_bin_0.05s.png'

Metadata

Release files for iot-inspector 3.0.21

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distribution (wheel)

Table of built distributions (wheels) for iot-inspector 3.0.21
File Interpreter ABI Platform
iot_inspector-3.0.21-py3-none-any.whl Python 3 none any Details

Release files / iot_inspector-3.0.21-py3-none-any.whl

Download URL iot_inspector-3.0.21-py3-none-any.whl
Size 301.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
2a687b524c4ebfbf959fdb515a7e96f46af186068f3dd0f5bc41a8e75c6045a1
BLAKE2b-256 checksum
How to use checksums
bcb9c165934acfecd8435d3bd0e570c6fc2aec910f35cbb1fa8ecd1efc02d731
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 16, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

3.0.21 This release

1 release file

3.0.20

1 release file

3.0.19

1 release file

3.0.18

1 release file

3.0.17

1 release file

3.0.16

1 release file

3.0.15

1 release file

3.0.14

1 release file

3.0.13

1 release file

3.0.12

1 release file

3.0.11

1 release file

3.0.10

1 release file

3.0.9

1 release file

3.0.8

1 release file

3.0.7

1 release file

3.0.6

1 release file

3.0.5

1 release file

3.0.4

1 release file

3.0.3

1 release file

3.0.2

1 release file

3.0.1

1 release file

3.0.0

1 release file

2.0.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page