Skip to main content

pktai

AI-assisted packet analysis in your terminal 🚀🤖📦💻

pktai_logo

Meet pktai — a modern, Textual-powered TUI that blends Wireshark-like workflows with an AI copilot. Open a pcap, browse packets, and chat with an on-device LLM (via Ollama) to explain what’s going on. Apply Wireshark-style display filters or just ask in natural language — pktai routes the request to the right tool, instantly.

Project URL: https://github.com/kspviswa/pktai

Demo : https://www.youtube.com/watch?v=GnPRs-cBtQM

Highlights

  • Packet-first UI: Left pane shows packets and expandable per-layer details.
  • Built-in Chat Copilot: Right pane is a chat that understands your capture context.
  • Wireshark-like Filters: Apply display filters inline or via slash commands.
  • NL → Filter: Ask “get me all NGAP packets” — pktai applies ngap automatically.
  • Instant Stop: Cancel in-flight LLM responses with a Stop button.
  • Zero mouse, pure keyboard: Fast and ergonomic terminal UX powered by Textual.

Installation

Requires Python 3.10+.

  • Using pip:
    pip install pktai
    
  • Using uv:
    uv add pktai
    

This installs the pktai command.

Quickstart

  1. Optional: run a local LLM with Ollama (default model qwen3:latest):
ollama run qwen3:latest
  1. Launch pktai:
pktai
  1. Open a capture file: press o and pick a .pcap/.pcapng.

Using pktai

  • Browse packets: Navigate the left pane; expand layers to inspect fields.
  • Chat analysis: Ask questions in the right chat pane (e.g., “summarize traffic patterns”).
  • Stop generation: While the model is responding, click Stop to cancel.
  • Display filter (slash command): Type:
    • /df ngap && sctp.dstport == 38412
    • /df ip.src == 10.0.0.1 && tcp This applies the filter immediately without calling the LLM.
  • Natural language filter: Ask “show only NGAP packets with dst port 38412” — pktai converts NL → display filter and applies it.
  • Settings: Press s to open a compact Settings modal; choose model and tune generation parameters.

Feature Deep Dive

  • Agentic Orchestrator: Routes your input between Filter, Packet, and Chat agents.
  • Filtering Engine: Tokenizer + parser + evaluator for a practical Wireshark-like subset:
    • Protocol tokens (e.g., tcp, ngap), field presence (e.g., ip.src), equality/inequality on common fields (e.g., ip.src == 1.2.3.4, sctp.dstport != 38412), boolean &&/|| with parentheses.
    • Unsupported operators like contains/matches raise a clear error.
  • LLM Abstraction: LLMService (OpenAI-compatible) talks to Ollama; switch models easily.
  • Markdown Chat: Renders assistant replies nicely; optional expandable “Thought process”.
  • Responsive UX: Soft-wrapping chat log, tight spacing, and a cancelable generation flow.

Tips & Troubleshooting

  • If the chat doesn’t work, ensure Ollama is running and the model is available: ollama run qwen3:latest.
  • To start without chat, simply use filtering and packet browsing; chat can be configured later.

Project

License

MIT — see LICENSE.

Metadata

Release files for pktai 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pktai 0.2.0
File Size Uploaded
pktai-0.2.0.tar.gz 2.0 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for pktai 0.2.0
File Interpreter ABI Platform
pktai-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 2.1 MB

Release files / pktai-0.2.0.tar.gz

Download URL pktai-0.2.0.tar.gz
Size 2.0 MB
Tags Source
SHA-256 checksum
How to use checksums
93b85dcb8c680603ca6798452b2778e2b460edeab2fb794bf0ac7920cd1b2aa5
BLAKE2b-256 checksum
How to use checksums
c564be102bf33f24f67d13773826479a20d4b1beda0b2cca9f875fe519e03db6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.1

Release files / pktai-0.2.0-py3-none-any.whl

Download URL pktai-0.2.0-py3-none-any.whl
Size 37.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
add2dec5956876d6d83b78b0d92d6fd74bd7abc4a509ce8f0caf356c6e9187ed
BLAKE2b-256 checksum
How to use checksums
bc3283540907f7e4843d116ef90646e55ddc1b97719544997b0bea6a75bd3b62
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.1

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page