Skip to main content

pcap-ioc

Python tool to extract potential IOCs from a pcap file using pyshark

List of IOCs extracted :

  • IP addresses from IP packets
  • Domains and IP addresses from DNS requests
  • Domains, url and user-agents from HTTP requests
  • Domains from HTTPs X509 certificates

To install it, you can just do pip install pcap_ioc or install it from this repository with pip install ..

Usage

As a library

from pcap_ioc import Pcap

p = Pcap('FILE.pcap')
for i in p.indicators:
    print(i)

CLI tool

$ pcap_ioc
usage: pcap_ioc [-h] {ioc,misp,shell} ...

Process some pcaps.

positional arguments:
  {ioc,misp,shell}  Subcommand
    ioc             Extract IOCs
    misp            Extract IOCs and search in MISP
    shell           Open a shell with pyshark

optional arguments:
  -h, --help        show this help message and exit

To query MISP servers, you need to create a file ~/.misp with one entry for every MISP server for instance :

[server1]
url: https://misp1.example.org/
key: KEYHERE
default: true

[server2]
url: https://misp2.example.org/
key: KEYHERE

Then you can query one of these server with pcap_ioc misp -s misp2 file.pcap

License

This software is released under the MIT license.

Metadata

Release files for pcap-ioc 0.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pcap-ioc 0.1.2
File Size Uploaded
pcap_ioc-0.1.2.tar.gz 3.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pcap-ioc 0.1.2
File Interpreter ABI Platform
pcap_ioc-0.1.2-py3-none-any.whl Python 3 none any Details

Total release size: 9.0 kB

Release files / pcap_ioc-0.1.2.tar.gz

Download URL pcap_ioc-0.1.2.tar.gz
Size 3.7 kB
Tags Source
SHA-256 checksum
How to use checksums
d477acf1d4db634bc176a75a86deef97eaf7136a36a549ed88ad71b08eae0185
BLAKE2b-256 checksum
How to use checksums
8abcfddec4889bb2ed8fdfaced509351e949f5ffeb17d62f0061ac3cf3292230
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/1.12.1 pkginfo/1.4.2 requests/2.19.1 setuptools/40.6.3 requests-toolbelt/0.8.0 tqdm/4.25.0 CPython/3.7.2rc1

Release files / pcap_ioc-0.1.2-py3-none-any.whl

Download URL pcap_ioc-0.1.2-py3-none-any.whl
Size 5.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0bd8c794daaa31b51b847357f36ac5ffc9a0039403c18df9877e7d1f08ceb918
BLAKE2b-256 checksum
How to use checksums
236788a200017191ea3f742794f18cd9da29355e4b009568f6f9c6fd5bb45904
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/1.12.1 pkginfo/1.4.2 requests/2.19.1 setuptools/40.6.3 requests-toolbelt/0.8.0 tqdm/4.25.0 CPython/3.7.2rc1

Release history Release notifications | RSS feed

This release

0.1.2 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page