Skip to main content

Analyst-focused PCAP behavior analysis and finding engine

Project description

PCAPX

PCAPX is a lightweight, analyst-focused PCAP analysis tool designed to extract actionable security findings from packet captures without relying on signatures, malware labels, or assumptions.

It focuses on behavioral evidence, protocol misuse, and cleartext exposure, presenting results in a format familiar to SOC analysts, blue teams, and incident responders.

PCAPX does not claim malware detection.
It highlights observable behaviors that may warrant investigation.


Why PCAPX?

Most PCAP tools fall into one of two extremes:

  • Low-level packet viewers (e.g., Wireshark)
  • Heavy IDS engines with opaque alerts

PCAPX sits in the middle.

It answers questions like:

  • Were credentials exposed?
  • Are hosts communicating in automated or periodic patterns?
  • Is there evidence of service discovery or probing?
  • Are application payloads behaving unusually?

All without guessing intent.


Key Features

🔐 Cleartext Authentication Detection

  • Detects FTP cleartext credentials
  • Extracts:
    • Username
    • Password
    • Client & server IPs
  • Aggregated into a single SOC-style finding
  • No duplication across sessions

🌐 Network Behavior Analysis

  • High-frequency and periodic communication patterns
  • Bidirectional traffic deduplication
  • Broad port interaction (recon-like behavior)

📡 DNS & Application Observations

  • Unusual DNS query structures
  • Application payloads loosely associated with exploitation techniques
    (low confidence, informational only)

📊 Analyst-Friendly Output

  • Clean terminal tables
  • Findings grouped with:
    • ID
    • Severity
    • What happened
    • Why it matters
    • Affected assets

🧠 Safe, Generalized Language

  • No malware family names
  • No attribution claims
  • No intent assumptions
  • Suitable for reports, audits, and legal review

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pcapx-1.1.1.tar.gz (15.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pcapx-1.1.1-py3-none-any.whl (18.6 kB view details)

Uploaded Python 3

File details

Details for the file pcapx-1.1.1.tar.gz.

File metadata

  • Download URL: pcapx-1.1.1.tar.gz
  • Upload date:
  • Size: 15.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for pcapx-1.1.1.tar.gz
Algorithm Hash digest
SHA256 4c2aca09a9c7e4bee3423b87954d0239f8725f3743a153f3094e7583dd578823
MD5 933281bf9a21ce157c09c5a4b450940b
BLAKE2b-256 db580c7e161d90d33e7243f2d09e8151ef780977deed02f04b2aa3d90a130626

See more details on using hashes here.

File details

Details for the file pcapx-1.1.1-py3-none-any.whl.

File metadata

  • Download URL: pcapx-1.1.1-py3-none-any.whl
  • Upload date:
  • Size: 18.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for pcapx-1.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 5b6eb897c002a85a5fff4561206fe2381c683b8fc0b391beba4dd4067712b725
MD5 4d01d247206d8eacb36de140ae5f6585
BLAKE2b-256 66b46b8a215d85abeb1564793a773aa970e334326651d2318a9f2881a65905b3

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page