Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

PyPCAPKit -- Comprehensive Network Packet Analysis Library

For any technical and/or maintenance information, please kindly refer to the Official Documentation.

The PyPCAPKit project is an open source Python program focused on network packet parsing and analysis, which works as a comprehensive PCAP file extraction, construction and analysis library, with DictDumper as its formatted output dumper.

Unlike popular PCAP file extractors such as Scapy, DPKT and PyShark, pcapkit is designed to be much more comprehensive: it reports more detailed information about each packet, and offers a more Pythonic interface to work with it. When that depth is not what you need, the same interface will also drive six third-party extraction engines instead.

The whole project supports Python 3.6 or later.

Installation

pip install pypcapkit

Or from a clone, for the latest version and for development:

git clone https://github.com/JarryShaw/PyPCAPKit.git
cd PyPCAPKit
pip install -e .

The extraction engines and plug-ins are optional extras:

pip install pypcapkit[DPKT]         # or Scapy, PyShark, PyPCAPFile, PyPCAP, PCAP_CT
pip install pypcapkit[crypto]       # ESP payload decryption
pip install pypcapkit[cli]          # command line interface
pip install pypcapkit[all]          # every pure-Python extra

Four of the engines need something beyond a pip install -- a tshark binary, a C compiler, libpcap headers, or an older interpreter -- and all deliberately excludes both pypcap and pcap-ct, which must never be installed together. The installation guide covers every constraint and the reason for it, and pcapkit enforces each one in code: asking for an engine that cannot run in the current environment warns with the actual cause and falls back to pcapkit's own parser.

Usage

>>> import pcapkit
>>> extraction = pcapkit.extract('in.pcap', nofile=True)
>>> len(extraction.frame)
6
>>> frame = extraction.frame[0]
>>> str(frame.protochain)
'Ethernet:IPv6:IPv6_ICMP'
>>> frame.info.time
datetime.datetime(2017, 11, 19, 15, 49, 5, 471719, tzinfo=datetime.timezone.utc)
>>> frame.payload.payload.src
IPv6Address('fe80::a6:87f9:2793:16ee')

The output above is from examples/captures/in.pcap, which is committed, so it is reproducible from a clone.

Reassembly, TCP flow tracing and a different engine are all keyword arguments on the same call:

>>> scapy = pcapkit.extract('in.pcap', nofile=True, engine='scapy')
>>> reasm = pcapkit.extract('in.pcap', nofile=True, reassembly=True, ipv6=True)
>>> flows = pcapkit.extract('in.pcap', nofile=True, trace=True, tcp=True)
>>> len(flows.trace)
3

More worked examples, including the command line interface, are in How to ....

Documentation

The official documentation is the reference for everything below. The pages worth knowing by name:

Page What is in it
API reference Every module, protocol and constant
Module structure What each of the eight subpackages is for
Engine comparison Which engines exist, which Python versions they run on, and measured speed per packet
Engine support What each engine does not support, and how the gap is surfaced
Installation Extras, engine prerequisites and the local development setup
Testing Running the suite, and the sample captures it needs
How to ... Worked examples, library and CLI
Extensions Registering your own protocols, engines and dumpers

Release history is in CHANGELOG.md, and contribution guidelines are in CONTRIBUTING.md.

Metadata

Release files for pypcapkit 1.5.0b5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pypcapkit 1.5.0b5
File Size Uploaded
pypcapkit-1.5.0b5.tar.gz 2.7 MB Details

Built distributions (wheels)

Table of built distributions (wheels) for pypcapkit 1.5.0b5
File
pypcapkit-1.5.0b5-pp311-none-any.whl PyPy 3.11 none any Details
pypcapkit-1.5.0b5-pp310-none-any.whl PyPy 3.10 none any Details
pypcapkit-1.5.0b5-cp314-none-any.whl CPython 3.14 none any Details
pypcapkit-1.5.0b5-cp313-none-any.whl CPython 3.13 none any Details
pypcapkit-1.5.0b5-cp312-none-any.whl CPython 3.12 none any Details
pypcapkit-1.5.0b5-cp311-none-any.whl CPython 3.11 none any Details
pypcapkit-1.5.0b5-cp310-none-any.whl CPython 3.10 none any Details

Total release size: 13.9 MB

Release files / pypcapkit-1.5.0b5.tar.gz

Download URL pypcapkit-1.5.0b5.tar.gz
Size 2.7 MB
Tags Source
SHA-256 checksum
How to use checksums
6b2ee263a24689381c92a4f70f8fb55e4a7c76d694b90e119cb73e464116723a
BLAKE2b-256 checksum
How to use checksums
8c8dd37df81f7038a159c6f1aabd54dc73e34415eb3503bd6ab69959b8d437e5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b5-pp311-none-any.whl

Download URL pypcapkit-1.5.0b5-pp311-none-any.whl
Size 1.6 MB
Tags PyPy 3.11
SHA-256 checksum
How to use checksums
3f4d99c8cfa4335e116bd397417ab5ac3eda307ecaf99f0d604a409ade422f1f
BLAKE2b-256 checksum
How to use checksums
0684684a9fa2528b23cc23029ee7e63ade588dc00171b4eaeabbb495286350b4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b5-pp310-none-any.whl

Download URL pypcapkit-1.5.0b5-pp310-none-any.whl
Size 1.6 MB
Tags PyPy 3.10
SHA-256 checksum
How to use checksums
dac483e609c7bf5354c755e8c4ba4aa474da001dc04c8e30ad01627233901d27
BLAKE2b-256 checksum
How to use checksums
cfecfda6a219a3eb0923ce96c2c994f08cab024f57fef8348e965831e0aead3a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b5-cp314-none-any.whl

Download URL pypcapkit-1.5.0b5-cp314-none-any.whl
Size 1.6 MB
Tags CPython 3.14
SHA-256 checksum
How to use checksums
c0ef662eb1f195580fec2b4fcee24f1857658f2b6d2ef30fc5fdc412722d28fc
BLAKE2b-256 checksum
How to use checksums
7255c06a8e6349848f46af96be24d3e02c02c6c2bff947f6b858d40e4e0d59e3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b5-cp313-none-any.whl

Download URL pypcapkit-1.5.0b5-cp313-none-any.whl
Size 1.6 MB
Tags CPython 3.13
SHA-256 checksum
How to use checksums
aac23d738251327962bb8157a1d1879258d58354afccccbbfc2e6cb592af1c74
BLAKE2b-256 checksum
How to use checksums
b9554f62d934a06d37510f4c7b5b0b5c09f8fd94821f0f34423e9853ff8d40ea
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b5-cp312-none-any.whl

Download URL pypcapkit-1.5.0b5-cp312-none-any.whl
Size 1.6 MB
Tags CPython 3.12
SHA-256 checksum
How to use checksums
7619b98ec90b8d1d93f84cb01323ae2f773c8fe6cc5284a5ff658db9f5d25b80
BLAKE2b-256 checksum
How to use checksums
6547095065417426a72d8d73d0c529354fc15231678b994501148b98333305d3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b5-cp311-none-any.whl

Download URL pypcapkit-1.5.0b5-cp311-none-any.whl
Size 1.6 MB
Tags CPython 3.11
SHA-256 checksum
How to use checksums
24139d69e41262b553db9ad226b253fd3091dacf984b621131d832218865e8f6
BLAKE2b-256 checksum
How to use checksums
66781404503d0bdd3ebeae98e1b3df247ad83399f9fa56750b07f62164e94fdf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b5-cp310-none-any.whl

Download URL pypcapkit-1.5.0b5-cp310-none-any.whl
Size 1.6 MB
Tags CPython 3.10
SHA-256 checksum
How to use checksums
3bace0f7fe4d3eb8f8a1eb6afead6265d898dfd34ea6c8a57259112e29bd595b
BLAKE2b-256 checksum
How to use checksums
991c5f4a02d034c57fef0a4d8c2799c548e9b2b823a78ce901e25141f10373b0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

This release

1.5.0b5 This release

8 release files

1.4.1

8 release files

1.4.0

8 release files

1.3.5

8 release files

1.3.4

9 release files

1.3.3

7 release files

1.3.1

6 release files

1.3.0

7 release files

1.2.2

6 release files

1.2.1

7 release files

1.2.0

7 release files

1.1.1

7 release files

1.1.0

7 release files

1.0.3

6 release files

1.0.2

5 release files

1.0.1

2 release files

1.0.0

2 release files

0.16.2

1 release file

0.16.1

1 release file

0.16.0

1 release file

0.15.5

2 release files

0.15.4

2 release files

0.15.3

2 release files

0.15.2

2 release files

0.15.1

2 release files

0.12.9

3 release files

0.12.8

3 release files

0.12.7

3 release files

0.12.6

3 release files

0.12.5

2 release files

0.12.2

2 release files

0.12.1

2 release files

0.12.0

2 release files

0.11.3

2 release files

0.11.2

2 release files

0.10.2

2 release files

0.10.1

2 release files

0.10.0

2 release files

0.9.10

2 release files

0.9.9

2 release files

0.9.8

2 release files

0.9.7

2 release files

0.9.6

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page