This release is a pre-release and may not be stable for production use.
PyPCAPKit -- Comprehensive Network Packet Analysis Library
For any technical and/or maintenance information, please kindly refer to the Official Documentation.
The PyPCAPKit project is an open source Python program focused on network packet parsing and analysis, which works as a comprehensive PCAP file extraction, construction and analysis library, with DictDumper as its formatted output dumper.
Unlike popular PCAP file extractors such as Scapy,
DPKT and PyShark,
pcapkit is designed to be much more comprehensive: it reports more detailed
information about each packet, and offers a more Pythonic interface to work
with it. When that depth is not what you need, the same interface will also drive
six third-party extraction engines instead.
The whole project supports Python 3.6 or later.
Installation
pip install pypcapkit
Or from a clone, for the latest version and for development:
git clone https://github.com/JarryShaw/PyPCAPKit.git
cd PyPCAPKit
pip install -e .
The extraction engines and plug-ins are optional extras:
pip install pypcapkit[DPKT] # or Scapy, PyShark, PyPCAPFile, PyPCAP, PCAP_CT
pip install pypcapkit[crypto] # ESP payload decryption
pip install pypcapkit[cli] # command line interface
pip install pypcapkit[all] # core addons only: cli + crypto + NGAP (pycrate)
Every engine above is on demand; all bundles only the core addons the library
needs for full functionality. Four of the engines also need something beyond a
pip install -- a tshark binary, a C compiler, libpcap headers, or an older
interpreter -- and pypcap/pcap-ct must never be installed together.
The installation guide
covers every constraint and the reason for it, and pcapkit enforces each one in
code: asking for an engine that cannot run in the current environment warns with
the actual cause and falls back to pcapkit's own parser.
Usage
>>> import pcapkit
>>> extraction = pcapkit.extract('in.pcap', nofile=True)
>>> len(extraction.frame)
6
>>> frame = extraction.frame[0]
>>> str(frame.protochain)
'Ethernet:IPv6:IPv6_ICMP'
>>> frame.info.time
datetime.datetime(2017, 11, 19, 15, 49, 5, 471719, tzinfo=datetime.timezone.utc)
>>> frame.payload.payload.src
IPv6Address('fe80::a6:87f9:2793:16ee')
The output above is from examples/captures/in.pcap, which is committed, so it
is reproducible from a clone.
Reassembly, TCP flow tracing and a different engine are all keyword arguments on the same call:
>>> scapy = pcapkit.extract('in.pcap', nofile=True, engine='scapy')
>>> reasm = pcapkit.extract('in.pcap', nofile=True, reassembly=True, ipv6=True)
>>> flows = pcapkit.extract('in.pcap', nofile=True, trace=True, tcp=True)
>>> len(flows.trace)
3
More worked examples, including the command line interface, are in How to ....
Documentation
The official documentation is the reference for everything below. The pages worth knowing by name:
| Page | What is in it |
|---|---|
| API reference | Every module, protocol and constant |
| Module structure | What each of the eight subpackages is for |
| Engine comparison | Which engines exist, which Python versions they run on, and measured speed per packet |
| Engine support | What each engine does not support, and how the gap is surfaced |
| Installation | Extras, engine prerequisites and the local development setup |
| Testing | Running the suite, and the sample captures it needs |
| How to ... | Worked examples, library and CLI |
| Extensions | Registering your own protocols, engines and dumpers |
Release history is in CHANGELOG.md, and contribution guidelines are in CONTRIBUTING.md.
Metadata
Release files for pypcapkit 1.5.0b7
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pypcapkit-1.5.0b7.tar.gz | 2.8 MB | Details |
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| pypcapkit-1.5.0b7-pp311-none-any.whl | PyPy 3.11 | none | any | Details |
| pypcapkit-1.5.0b7-pp310-none-any.whl | PyPy 3.10 | none | any | Details |
| pypcapkit-1.5.0b7-cp314-none-any.whl | CPython 3.14 | none | any | Details |
| pypcapkit-1.5.0b7-cp313-none-any.whl | CPython 3.13 | none | any | Details |
| pypcapkit-1.5.0b7-cp312-none-any.whl | CPython 3.12 | none | any | Details |
| pypcapkit-1.5.0b7-cp311-none-any.whl | CPython 3.11 | none | any | Details |
| pypcapkit-1.5.0b7-cp310-none-any.whl | CPython 3.10 | none | any | Details |
Total release size: 14.4 MB
Release files / pypcapkit-1.5.0b7.tar.gz
| Download URL | pypcapkit-1.5.0b7.tar.gz |
|---|---|
| Size | 2.8 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ce224a69c5a795262495acf8859512428c747438faacd94028f0dee755bdc8db
|
|
BLAKE2b-256 checksum How to use checksums |
eb25382a26a491cbfb7dd9b71747e0cb83e598c39aaa21e17b411f6b94ca4953
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / pypcapkit-1.5.0b7-pp311-none-any.whl
| Download URL | pypcapkit-1.5.0b7-pp311-none-any.whl |
|---|---|
| Size | 1.7 MB |
| Tags | PyPy 3.11 |
|
SHA-256 checksum How to use checksums |
dc8f5427b5e7cf8c96e45a7902abc99d841a866fcd233add433e5bb7f72273ab
|
|
BLAKE2b-256 checksum How to use checksums |
0cc704424b5a601f99a40e1988eb3cbd17b8ed72efbd3907c874debf468cb6c3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / pypcapkit-1.5.0b7-pp310-none-any.whl
| Download URL | pypcapkit-1.5.0b7-pp310-none-any.whl |
|---|---|
| Size | 1.7 MB |
| Tags | PyPy 3.10 |
|
SHA-256 checksum How to use checksums |
4e17564b8c4b87b1bc26184531c54a7e0c0843a3a7469321eccdd3a1ae6ce575
|
|
BLAKE2b-256 checksum How to use checksums |
f4054c6367205560f67c199b89237d722bc0b0f46399d6c63e7456921008968c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / pypcapkit-1.5.0b7-cp314-none-any.whl
| Download URL | pypcapkit-1.5.0b7-cp314-none-any.whl |
|---|---|
| Size | 1.7 MB |
| Tags | CPython 3.14 |
|
SHA-256 checksum How to use checksums |
7cd66c719d90bfbe6edd17e805d6f1ca3ffb276fe81f4529406c8577e45c96b4
|
|
BLAKE2b-256 checksum How to use checksums |
a369fe228c4ec4847d14551138ca12469801ac872e5704090bf091d8ee4072a3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / pypcapkit-1.5.0b7-cp313-none-any.whl
| Download URL | pypcapkit-1.5.0b7-cp313-none-any.whl |
|---|---|
| Size | 1.7 MB |
| Tags | CPython 3.13 |
|
SHA-256 checksum How to use checksums |
aa9d3c27964ba93658534c50f669a1de9eb1c314d599ad7e82c7004f8a5d6ce6
|
|
BLAKE2b-256 checksum How to use checksums |
ae737491321f603d40dbc3c0ed4ea15a1491a2970e786b378c82bb1188607941
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / pypcapkit-1.5.0b7-cp312-none-any.whl
| Download URL | pypcapkit-1.5.0b7-cp312-none-any.whl |
|---|---|
| Size | 1.7 MB |
| Tags | CPython 3.12 |
|
SHA-256 checksum How to use checksums |
85ec086fe281c2948e0e5ea9176ce89a8721da48fa5ae036ba257137a97468ad
|
|
BLAKE2b-256 checksum How to use checksums |
8d7cc26d152276d6bc89d135370d8b5b63f9783ae29700ffe5db00309c5e5096
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / pypcapkit-1.5.0b7-cp311-none-any.whl
| Download URL | pypcapkit-1.5.0b7-cp311-none-any.whl |
|---|---|
| Size | 1.7 MB |
| Tags | CPython 3.11 |
|
SHA-256 checksum How to use checksums |
5c33849a81fbd16fa8cd4b13e9dd7d26766bc1c8ad1fdf9ce58d18cecff55aaf
|
|
BLAKE2b-256 checksum How to use checksums |
6690856943f89fe623fa05cdd9061e04d0f00d3f4f8cfadad4faccf121da1ff2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / pypcapkit-1.5.0b7-cp310-none-any.whl
| Download URL | pypcapkit-1.5.0b7-cp310-none-any.whl |
|---|---|
| Size | 1.7 MB |
| Tags | CPython 3.10 |
|
SHA-256 checksum How to use checksums |
4d88c49f55462ba7898da374aaf049193f577156676809532e9b942110ceca18
|
|
BLAKE2b-256 checksum How to use checksums |
9c9442f03eb250465f841e51dee904738671e7dc6e6c018be85390b97b2e655c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|