Skip to main content
pyshark
=======

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors.

There are quite a few python packet parsing modules, this one is different because it doesn't actually parse any packets, it simply uses tshark's (wireshark command-line utility) ability to export XMLs to use its parsing.

This package allows parsing from a capture file or a live capture, using all wireshark dissectors you have installed.
Tested on windows/linux.

Usage
=====

Reading from a capture file:
----------------------------

::

import pyshark
cap = pyshark.FileCapture('/tmp/mycapture.cap')
cap
>>> <FileCapture /tmp/mycapture.cap (589 packets)>
print cap[0]
Packet (Length: 698)
Layer ETH:
Destination: BLANKED
Source: BLANKED
Type: IP (0x0800)
Layer IP:
Version: 4
Header Length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00: Not-ECT (Not ECN-Capable Transport))
Total Length: 684s
Identification: 0x254f (9551)
Flags: 0x00
Fragment offset: 0
Time to live: 1
Protocol: UDP (17)
Header checksum: 0xe148 [correct]
Source: BLANKED
Destination: BLANKED
...


Reading from a live interface:
------------------------------

::

capture = pyshark.LiveCapture(interface='eth0')
capture.sniff(timeout=50)
capture
>>> <LiveCapture (5 packets)>
capture[3]
<UDP/HTTP Packet>

for packet in capture.sniff_continuously(packet_count=5):
print 'Just arrived:', packet

Infinite reading from a live interface with capture filter:
------------------------------

::

def packet_captured(packet):
print 'Just arrived:', packet

capture = pyshark.LiveCapture(interface='eth0', capture_filter='tcp')
capture.apply_on_packets(packet_captured)

Accessing packet data:
----------------------

Data can be accessed in multiple ways.
Packets are divided into layers, first you have to reach the appropriate layer and then you can select your field.

All of the following work::

packet['ip'].dst
>>> 192.168.0.1
packet.ip.src
>>> 192.168.0.100
packet[2].src
>>> 192.168.0.100



Release files for py3shark 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for py3shark 0.4.0
File Size Uploaded
py3shark-0.4.0.tar.gz 21.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for py3shark 0.4.0
File Interpreter ABI Platform
py3shark-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 52.7 kB

Release files / py3shark-0.4.0.tar.gz

Download URL py3shark-0.4.0.tar.gz
Size 21.2 kB
Tags Source
SHA-256 checksum
How to use checksums
6cdfc547fce76bfeffede7e0807dd8bda487e5393a4ec28743d1836f9d35bfdc
BLAKE2b-256 checksum
How to use checksums
3e6a2e6da925b931ab7d5cf6469a1bbc35ea5b389a47ac999748c8384e07f5fd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / py3shark-0.4.0-py3-none-any.whl

Download URL py3shark-0.4.0-py3-none-any.whl
Size 31.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a543d10e162a32e82ed071ef89fb14904fbf6ab51a51c9a7164de8d8130de015
BLAKE2b-256 checksum
How to use checksums
04bafb9d2b5d21f6e00b7583fe44b88659755c5faf31ef7fd7ab7e80bd6bccd4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

0.4.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page