Analyst-focused PCAP behavior analysis and finding engine
Project description
PCAPX
PCAPX is a lightweight, analyst-focused PCAP analysis tool designed to extract actionable security findings from packet captures without relying on signatures, malware labels, or assumptions.
It focuses on behavioral evidence, protocol misuse, and cleartext exposure, presenting results in a format familiar to SOC analysts, blue teams, and incident responders.
PCAPX does not claim malware detection.
It highlights observable behaviors that may warrant investigation.
Why PCAPX?
Most PCAP tools fall into one of two extremes:
- Low-level packet viewers (e.g., Wireshark)
- Heavy IDS engines with opaque alerts
PCAPX sits in the middle.
It answers questions like:
- Were credentials exposed?
- Are hosts communicating in automated or periodic patterns?
- Is there evidence of service discovery or probing?
- Are application payloads behaving unusually?
All without guessing intent.
Key Features
🔐 Cleartext Authentication Detection
- Detects FTP cleartext credentials
- Extracts:
- Username
- Password
- Client & server IPs
- Aggregated into a single SOC-style finding
- No duplication across sessions
🌐 Network Behavior Analysis
- High-frequency and periodic communication patterns
- Bidirectional traffic deduplication
- Broad port interaction (recon-like behavior)
📡 DNS & Application Observations
- Unusual DNS query structures
- Application payloads loosely associated with exploitation techniques
(low confidence, informational only)
📊 Analyst-Friendly Output
- Clean terminal tables
- Findings grouped with:
- ID
- Severity
- What happened
- Why it matters
- Affected assets
🧠 Safe, Generalized Language
- No malware family names
- No attribution claims
- No intent assumptions
- Suitable for reports, audits, and legal review
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file pcapx-1.1.1.tar.gz.
File metadata
- Download URL: pcapx-1.1.1.tar.gz
- Upload date:
- Size: 15.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4c2aca09a9c7e4bee3423b87954d0239f8725f3743a153f3094e7583dd578823
|
|
| MD5 |
933281bf9a21ce157c09c5a4b450940b
|
|
| BLAKE2b-256 |
db580c7e161d90d33e7243f2d09e8151ef780977deed02f04b2aa3d90a130626
|
File details
Details for the file pcapx-1.1.1-py3-none-any.whl.
File metadata
- Download URL: pcapx-1.1.1-py3-none-any.whl
- Upload date:
- Size: 18.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
5b6eb897c002a85a5fff4561206fe2381c683b8fc0b391beba4dd4067712b725
|
|
| MD5 |
4d01d247206d8eacb36de140ae5f6585
|
|
| BLAKE2b-256 |
66b46b8a215d85abeb1564793a773aa970e334326651d2318a9f2881a65905b3
|