Skip to main content

🐀 A clean, human-readable CLI packet analyzer for .pcap files

Project description

packrat 🐀

Packrat is an open source command-line packet analyzer that takes the pain out of reading raw .pcap files. Packrat gives you a clean, colorized summary of IP conversations, protocol breakdowns, and traffic detection.

After using tshark I just wanted something simpler. Something I could run and immediately understand what's happening in a capture without digging through documentation for flags.

If you are using this tool and have any suggestions, feel free to open an issue or reach out!

install

pip install packrat-cli

usage

# basic analysis
packrat capture.pcap

# filter by IP or protocol
packrat capture.pcap --filter 192.168.1.5
packrat capture.pcap --filter DNS

# export results
packrat capture.pcap --export json
packrat capture.pcap --export html
packrat capture.pcap --export txt

# skip DNS resolution (faster)
packrat capture.pcap --nd

# check version
packrat --version

Screenshot

packrat screenshot

features

  • Protocol breakdown — TCP, UDP, DNS, HTTP, HTTPS, SSH, FTP, SMTP, IMAP, ARP
  • Top IP addresses with hostname resolution and color coding
  • DNS query analysis with top domains
  • TLS/HTTPS handshake detection
  • Anomaly detection — port scans, ARP floods, DNS tunneling, FTP plaintext
  • Export to JSON, HTML, or TXT

changelog BELOWWWWWW

v1.1.0 (most recent)

  • Added threat detection engine with rules for SYN flood, ICMP flood, UDP flood, port scan, and ARP scan
  • Refactored codebase into layered architecture (core API, CLI, detection)

v1.0.2

  • Initial release

NOTE

Packrat reports HTTP at the packet level, not the transaction level. What this means is that since there is no TCP reassembly, A single HTTP request/response may span multiple packets. This can lead to a higher number of packets according to Wireshark or other Networking tools.

That being said, use Packrat for convenience not pin point accuracy. 

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

packrat_cli-1.1.1.tar.gz (9.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

packrat_cli-1.1.1-py3-none-any.whl (10.4 kB view details)

Uploaded Python 3

File details

Details for the file packrat_cli-1.1.1.tar.gz.

File metadata

  • Download URL: packrat_cli-1.1.1.tar.gz
  • Upload date:
  • Size: 9.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.1

File hashes

Hashes for packrat_cli-1.1.1.tar.gz
Algorithm Hash digest
SHA256 eb1743d02232f760e1ab197e81b7e8c338918389b9946d1fd0aaf95889ef3d9e
MD5 ac0da6b7bfd38e841e5bbbaec9c112cf
BLAKE2b-256 7b13926fa0e9f90f51a127cd3623e3ac29c83f8012713627a3a46e6cfb367204

See more details on using hashes here.

File details

Details for the file packrat_cli-1.1.1-py3-none-any.whl.

File metadata

  • Download URL: packrat_cli-1.1.1-py3-none-any.whl
  • Upload date:
  • Size: 10.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.1

File hashes

Hashes for packrat_cli-1.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 d5df1d9cb78ea2ef22155b331275e19b93e923a4fb3997ac4525a9ded9ac1964
MD5 6207534371353e7a628afd200508366b
BLAKE2b-256 3e9591517a0d67df4d468ac39824bcad3e7ca4a4dfbd79deb784deae0416b0d3

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page