Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

PyPCAPKit -- Comprehensive Network Packet Analysis Library

For any technical and/or maintenance information, please kindly refer to the Official Documentation.

The PyPCAPKit project is an open source Python program focused on network packet parsing and analysis, which works as a comprehensive PCAP file extraction, construction and analysis library, with DictDumper as its formatted output dumper.

Unlike popular PCAP file extractors such as Scapy, DPKT and PyShark, pcapkit is designed to be much more comprehensive: it reports more detailed information about each packet, and offers a more Pythonic interface to work with it. When that depth is not what you need, the same interface will also drive six third-party extraction engines instead.

The whole project supports Python 3.6 or later.

Installation

pip install pypcapkit

Or from a clone, for the latest version and for development:

git clone https://github.com/JarryShaw/PyPCAPKit.git
cd PyPCAPKit
pip install -e .

The extraction engines and plug-ins are optional extras:

pip install pypcapkit[DPKT]         # or Scapy, PyShark, PyPCAPFile, PyPCAP, PCAP_CT
pip install pypcapkit[crypto]       # ESP payload decryption
pip install pypcapkit[cli]          # command line interface
pip install pypcapkit[all]          # core addons only: cli + crypto + NGAP (pycrate)

Every engine above is on demand; all bundles only the core addons the library needs for full functionality. Four of the engines also need something beyond a pip install -- a tshark binary, a C compiler, libpcap headers, or an older interpreter -- and pypcap/pcap-ct must never be installed together. The installation guide covers every constraint and the reason for it, and pcapkit enforces each one in code: asking for an engine that cannot run in the current environment warns with the actual cause and falls back to pcapkit's own parser.

Usage

>>> import pcapkit
>>> extraction = pcapkit.extract('in.pcap', nofile=True)
>>> len(extraction.frame)
6
>>> frame = extraction.frame[0]
>>> str(frame.protochain)
'Ethernet:IPv6:IPv6_ICMP'
>>> frame.info.time
datetime.datetime(2017, 11, 19, 15, 49, 5, 471719, tzinfo=datetime.timezone.utc)
>>> frame.payload.payload.src
IPv6Address('fe80::a6:87f9:2793:16ee')

The output above is from examples/captures/in.pcap, which is committed, so it is reproducible from a clone.

Reassembly, TCP flow tracing and a different engine are all keyword arguments on the same call:

>>> scapy = pcapkit.extract('in.pcap', nofile=True, engine='scapy')
>>> reasm = pcapkit.extract('in.pcap', nofile=True, reassembly=True, ipv6=True)
>>> flows = pcapkit.extract('in.pcap', nofile=True, trace=True, tcp=True)
>>> len(flows.trace)
3

More worked examples, including the command line interface, are in How to ....

Documentation

The official documentation is the reference for everything below. The pages worth knowing by name:

Page What is in it
API reference Every module, protocol and constant
Module structure What each of the eight subpackages is for
Engine comparison Which engines exist, which Python versions they run on, and measured speed per packet
Engine support What each engine does not support, and how the gap is surfaced
Installation Extras, engine prerequisites and the local development setup
Testing Running the suite, and the sample captures it needs
How to ... Worked examples, library and CLI
Extensions Registering your own protocols, engines and dumpers

Release history is in CHANGELOG.md, and contribution guidelines are in CONTRIBUTING.md.

Metadata

Release files for pypcapkit 1.5.0b8

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pypcapkit 1.5.0b8
File Size Uploaded
pypcapkit-1.5.0b8.tar.gz 3.0 MB Details

Built distributions (wheels)

Table of built distributions (wheels) for pypcapkit 1.5.0b8
File
pypcapkit-1.5.0b8-pp311-none-any.whl PyPy 3.11 none any Details
pypcapkit-1.5.0b8-pp310-none-any.whl PyPy 3.10 none any Details
pypcapkit-1.5.0b8-cp314-none-any.whl CPython 3.14 none any Details
pypcapkit-1.5.0b8-cp313-none-any.whl CPython 3.13 none any Details
pypcapkit-1.5.0b8-cp312-none-any.whl CPython 3.12 none any Details
pypcapkit-1.5.0b8-cp311-none-any.whl CPython 3.11 none any Details
pypcapkit-1.5.0b8-cp310-none-any.whl CPython 3.10 none any Details

Total release size: 14.6 MB

Release files / pypcapkit-1.5.0b8.tar.gz

Download URL pypcapkit-1.5.0b8.tar.gz
Size 3.0 MB
Tags Source
SHA-256 checksum
How to use checksums
c467233212d14fa4fc8699f0911fd3fb3ad6fac2c5b9fc126ac69346fd593667
BLAKE2b-256 checksum
How to use checksums
7966a976cdd001959aba228971872c9d894536aea1d84bd964aa0f97707efa9a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b8-pp311-none-any.whl

Download URL pypcapkit-1.5.0b8-pp311-none-any.whl
Size 1.7 MB
Tags PyPy 3.11
SHA-256 checksum
How to use checksums
c5117d0827215f307d461b97c2f3f80aabebf712ad32896399b27846fb0d12e3
BLAKE2b-256 checksum
How to use checksums
3fa2eec9a714d8c632cb8ec33453321afe620b7867c2b9d6846255a879886d25
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b8-pp310-none-any.whl

Download URL pypcapkit-1.5.0b8-pp310-none-any.whl
Size 1.7 MB
Tags PyPy 3.10
SHA-256 checksum
How to use checksums
0f747359ae4e9eeb3b4df4037fd7b7f7db1cccac3e58790a55bcbe90c35c2fbd
BLAKE2b-256 checksum
How to use checksums
d13efd5063fb94fb7e108aa49d01c8480da85c735db8e6a6a5ff06e310fc0b56
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b8-cp314-none-any.whl

Download URL pypcapkit-1.5.0b8-cp314-none-any.whl
Size 1.7 MB
Tags CPython 3.14
SHA-256 checksum
How to use checksums
b9f360c41291b896e1035dc32145e33995afc746610649b899de9038ceff9313
BLAKE2b-256 checksum
How to use checksums
b1699946b17d1abb9b1e4df77bfce52915f5b795971acc6af309370c3149f1f0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b8-cp313-none-any.whl

Download URL pypcapkit-1.5.0b8-cp313-none-any.whl
Size 1.7 MB
Tags CPython 3.13
SHA-256 checksum
How to use checksums
613e4485fbd8b99535e79276e06656a36eac165f8fdb3e474c9dd9e2f640e358
BLAKE2b-256 checksum
How to use checksums
d712710fc9f01f4ff6ddc7e697c3d55eb5a37b84498f4baaa05aa18b0acf9856
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b8-cp312-none-any.whl

Download URL pypcapkit-1.5.0b8-cp312-none-any.whl
Size 1.7 MB
Tags CPython 3.12
SHA-256 checksum
How to use checksums
ddbf44cacfb6e8780018d776b5e5479694a82b1099011811274f1898161fe2af
BLAKE2b-256 checksum
How to use checksums
1e9add88a6dfb87c374bdeb8b155ddefc0286555de8d5f8065291f0c68bc805c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b8-cp311-none-any.whl

Download URL pypcapkit-1.5.0b8-cp311-none-any.whl
Size 1.7 MB
Tags CPython 3.11
SHA-256 checksum
How to use checksums
144ab029abeb58b7542d249e97a3fc33823878239fe87db10a25d7edb76d8a69
BLAKE2b-256 checksum
How to use checksums
015ee06a4edca9db358ed4086609e3941929f6c0fe5a2bcc17813a7657c1de21
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / pypcapkit-1.5.0b8-cp310-none-any.whl

Download URL pypcapkit-1.5.0b8-cp310-none-any.whl
Size 1.7 MB
Tags CPython 3.10
SHA-256 checksum
How to use checksums
893e68eabdcb84fa6d3f43d319eef4d41819bed119c938bea67959e4d0a23d9b
BLAKE2b-256 checksum
How to use checksums
31f672b5fa60288252dceea54114e7ed397b9fa1ba10c5fc3f50a286ed679a71
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

This release

1.5.0b8 This release

8 release files

1.4.1

8 release files

1.4.0

8 release files

1.3.5

8 release files

1.3.4

9 release files

1.3.3

7 release files

1.3.1

6 release files

1.3.0

7 release files

1.2.2

6 release files

1.2.1

7 release files

1.2.0

7 release files

1.1.1

7 release files

1.1.0

7 release files

1.0.3

6 release files

1.0.2

5 release files

1.0.1

2 release files

1.0.0

2 release files

0.16.2

1 release file

0.16.1

1 release file

0.16.0

1 release file

0.15.5

2 release files

0.15.4

2 release files

0.15.3

2 release files

0.15.2

2 release files

0.15.1

2 release files

0.12.9

3 release files

0.12.8

3 release files

0.12.7

3 release files

0.12.6

3 release files

0.12.5

2 release files

0.12.2

2 release files

0.12.1

2 release files

0.12.0

2 release files

0.11.3

2 release files

0.11.2

2 release files

0.10.2

2 release files

0.10.1

2 release files

0.10.0

2 release files

0.9.10

2 release files

0.9.9

2 release files

0.9.8

2 release files

0.9.7

2 release files

0.9.6

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page