Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

PyPCAPKit -- Comprehensive Network Packet Analysis Library

For any technical and/or maintenance information, please kindly refer to the Official Documentation.

The PyPCAPKit project is an open source Python program focused on network packet parsing and analysis, which works as a comprehensive PCAP file extraction, construction and analysis library, with DictDumper as its formatted output dumper.

Unlike popular PCAP file extractors such as Scapy, DPKT and PyShark, pcapkit is designed to be much more comprehensive: it reports more detailed information about each packet, and offers a more Pythonic interface to work with it. When that depth is not what you need, the same interface will also drive six third-party extraction engines instead.

The whole project supports Python 3.6 or later.

Installation

pip install pypcapkit

Or from a clone, for the latest version and for development:

git clone https://github.com/JarryShaw/PyPCAPKit.git
cd PyPCAPKit
pip install -e .

The extraction engines and plug-ins are optional extras:

pip install pypcapkit[DPKT]         # or Scapy, PyShark, PyPCAPFile, PyPCAP, PCAP_CT
pip install pypcapkit[crypto]       # ESP payload decryption
pip install pypcapkit[cli]          # command line interface
pip install pypcapkit[all]          # core addons only: cli + crypto + NGAP (pycrate)

Every engine above is on demand; all bundles only the core addons the library needs for full functionality. Four of the engines also need something beyond a pip install -- a tshark binary, a C compiler, libpcap headers, or an older interpreter -- and pypcap/pcap-ct must never be installed together. The installation guide covers every constraint and the reason for it, and pcapkit enforces each one in code: asking for an engine that cannot run in the current environment warns with the actual cause and falls back to pcapkit's own parser.

Usage

>>> import pcapkit
>>> extraction = pcapkit.extract('in.pcap', nofile=True)
>>> len(extraction.frame)
6
>>> frame = extraction.frame[0]
>>> str(frame.protochain)
'Ethernet:IPv6:IPv6_ICMP'
>>> frame.info.time
datetime.datetime(2017, 11, 19, 15, 49, 5, 471719, tzinfo=datetime.timezone.utc)
>>> frame.payload.payload.src
IPv6Address('fe80::a6:87f9:2793:16ee')

The output above is from examples/captures/in.pcap, which is committed, so it is reproducible from a clone.

Reassembly, TCP flow tracing and a different engine are all keyword arguments on the same call:

>>> scapy = pcapkit.extract('in.pcap', nofile=True, engine='scapy')
>>> reasm = pcapkit.extract('in.pcap', nofile=True, reassembly=True, ipv6=True)
>>> flows = pcapkit.extract('in.pcap', nofile=True, trace=True, tcp=True)
>>> len(flows.trace)
3

More worked examples, including the command line interface, are in How to ....

Documentation

The official documentation is the reference for everything below. The pages worth knowing by name:

Page What is in it
API reference Every module, protocol and constant
Module structure What each of the eight subpackages is for
Engine comparison Which engines exist, which Python versions they run on, and measured speed per packet
Engine support What each engine does not support, and how the gap is surfaced
Installation Extras, engine prerequisites and the local development setup
Testing Running the suite, and the sample captures it needs
How to ... Worked examples, library and CLI
Extensions Registering your own protocols, engines and dumpers

Release history is in CHANGELOG.md, and contribution guidelines are in CONTRIBUTING.md.

Metadata

Release files for pypcapkit 1.5.0b7

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pypcapkit 1.5.0b7
File Size Uploaded
pypcapkit-1.5.0b7.tar.gz 2.8 MB Details

Built distributions (wheels)

Table of built distributions (wheels) for pypcapkit 1.5.0b7
File
pypcapkit-1.5.0b7-pp311-none-any.whl PyPy 3.11 none any Details
pypcapkit-1.5.0b7-pp310-none-any.whl PyPy 3.10 none any Details
pypcapkit-1.5.0b7-cp314-none-any.whl CPython 3.14 none any Details
pypcapkit-1.5.0b7-cp313-none-any.whl CPython 3.13 none any Details
pypcapkit-1.5.0b7-cp312-none-any.whl CPython 3.12 none any Details
pypcapkit-1.5.0b7-cp311-none-any.whl CPython 3.11 none any Details
pypcapkit-1.5.0b7-cp310-none-any.whl CPython 3.10 none any Details

Total release size: 14.4 MB

Release files / pypcapkit-1.5.0b7.tar.gz

Download URL pypcapkit-1.5.0b7.tar.gz
Size 2.8 MB
Tags Source
SHA-256 checksum
How to use checksums
ce224a69c5a795262495acf8859512428c747438faacd94028f0dee755bdc8db
BLAKE2b-256 checksum
How to use checksums
eb25382a26a491cbfb7dd9b71747e0cb83e598c39aaa21e17b411f6b94ca4953
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b7-pp311-none-any.whl

Download URL pypcapkit-1.5.0b7-pp311-none-any.whl
Size 1.7 MB
Tags PyPy 3.11
SHA-256 checksum
How to use checksums
dc8f5427b5e7cf8c96e45a7902abc99d841a866fcd233add433e5bb7f72273ab
BLAKE2b-256 checksum
How to use checksums
0cc704424b5a601f99a40e1988eb3cbd17b8ed72efbd3907c874debf468cb6c3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b7-pp310-none-any.whl

Download URL pypcapkit-1.5.0b7-pp310-none-any.whl
Size 1.7 MB
Tags PyPy 3.10
SHA-256 checksum
How to use checksums
4e17564b8c4b87b1bc26184531c54a7e0c0843a3a7469321eccdd3a1ae6ce575
BLAKE2b-256 checksum
How to use checksums
f4054c6367205560f67c199b89237d722bc0b0f46399d6c63e7456921008968c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b7-cp314-none-any.whl

Download URL pypcapkit-1.5.0b7-cp314-none-any.whl
Size 1.7 MB
Tags CPython 3.14
SHA-256 checksum
How to use checksums
7cd66c719d90bfbe6edd17e805d6f1ca3ffb276fe81f4529406c8577e45c96b4
BLAKE2b-256 checksum
How to use checksums
a369fe228c4ec4847d14551138ca12469801ac872e5704090bf091d8ee4072a3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b7-cp313-none-any.whl

Download URL pypcapkit-1.5.0b7-cp313-none-any.whl
Size 1.7 MB
Tags CPython 3.13
SHA-256 checksum
How to use checksums
aa9d3c27964ba93658534c50f669a1de9eb1c314d599ad7e82c7004f8a5d6ce6
BLAKE2b-256 checksum
How to use checksums
ae737491321f603d40dbc3c0ed4ea15a1491a2970e786b378c82bb1188607941
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b7-cp312-none-any.whl

Download URL pypcapkit-1.5.0b7-cp312-none-any.whl
Size 1.7 MB
Tags CPython 3.12
SHA-256 checksum
How to use checksums
85ec086fe281c2948e0e5ea9176ce89a8721da48fa5ae036ba257137a97468ad
BLAKE2b-256 checksum
How to use checksums
8d7cc26d152276d6bc89d135370d8b5b63f9783ae29700ffe5db00309c5e5096
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b7-cp311-none-any.whl

Download URL pypcapkit-1.5.0b7-cp311-none-any.whl
Size 1.7 MB
Tags CPython 3.11
SHA-256 checksum
How to use checksums
5c33849a81fbd16fa8cd4b13e9dd7d26766bc1c8ad1fdf9ce58d18cecff55aaf
BLAKE2b-256 checksum
How to use checksums
6690856943f89fe623fa05cdd9061e04d0f00d3f4f8cfadad4faccf121da1ff2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b7-cp310-none-any.whl

Download URL pypcapkit-1.5.0b7-cp310-none-any.whl
Size 1.7 MB
Tags CPython 3.10
SHA-256 checksum
How to use checksums
4d88c49f55462ba7898da374aaf049193f577156676809532e9b942110ceca18
BLAKE2b-256 checksum
How to use checksums
9c9442f03eb250465f841e51dee904738671e7dc6e6c018be85390b97b2e655c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

This release

1.5.0b7 This release

8 release files

1.4.1

8 release files

1.4.0

8 release files

1.3.5

8 release files

1.3.4

9 release files

1.3.3

7 release files

1.3.1

6 release files

1.3.0

7 release files

1.2.2

6 release files

1.2.1

7 release files

1.2.0

7 release files

1.1.1

7 release files

1.1.0

7 release files

1.0.3

6 release files

1.0.2

5 release files

1.0.1

2 release files

1.0.0

2 release files

0.16.2

1 release file

0.16.1

1 release file

0.16.0

1 release file

0.15.5

2 release files

0.15.4

2 release files

0.15.3

2 release files

0.15.2

2 release files

0.15.1

2 release files

0.12.9

3 release files

0.12.8

3 release files

0.12.7

3 release files

0.12.6

3 release files

0.12.5

2 release files

0.12.2

2 release files

0.12.1

2 release files

0.12.0

2 release files

0.11.3

2 release files

0.11.2

2 release files

0.10.2

2 release files

0.10.1

2 release files

0.10.0

2 release files

0.9.10

2 release files

0.9.9

2 release files

0.9.8

2 release files

0.9.7

2 release files

0.9.6

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page