Analyzing Network Packets With Scapy

mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-network-packets-with-scapy

作者 mukul97554a798831d2266a3ca61ce68a7acb80b81160d57Apache-2.034K 个星标收录于 2026年10月9日更新于 2026年10月9日仓库5周前更新

Use Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets. Use when performing authorized network reconnaissance, protocol-level forensic analysis, or building traffic anomaly detection during security testing.

包含脚本Security
AI 生成的概览

使用 Scapy 构造、嗅探和解析数据包,分析 pcap 文件并检测异常网络流量。

功能
指导代理使用 Scapy 这个 Python 库,在协议层粒度上构造、发送、嗅探和解析 TCP、UDP、ICMP 与 DNS 数据包。内容包括离线读取 pcap 与 pcapng 文件、提取协议层与字段值,以及统计流量特征,例如主要通信方、协议分布和端口频率。还介绍如何通过 TCP 标志位比例识别 SYN 洪水模式、通过查询长度与熵值发现 DNS 外泄迹象,并将结果导出为结构化 JSON 报告,包含数据包统计、异常项和逐流摘要。
适用场景
适用于经授权的网络侦察、对抓取流量的协议级取证分析,或在安全测试中构建流量异常检测。也适合事件调查、检测规则与威胁狩猎工作,以及验证相关攻击技术的安全监控覆盖情况。请仅在获得授权的网络上执行数据包操作。
运行要求
需要 Python 3.8 或更高版本并安装 scapy 库;原始套接字抓包与发包需要 root 或管理员权限;Windows 上需 Npcap,Linux 上需 libpcap;需获得对目标网络执行数据包操作的授权。随附可执行脚本(scripts/agent.py)以及一份 API 参考文档。

Analyzing Network Packets with Scapy

Overview

Scapy is a Python packet manipulation library that enables crafting, sending, sniffing, and dissecting network packets at granular protocol layers. This skill covers using Scapy for security-relevant tasks including TCP/UDP/ICMP packet crafting, pcap file analysis, protocol field extraction, SYN scan implementation, DNS query analysis, and detecting anomalous traffic patterns such as unusually fragmented packets or malformed headers.

When to Use

  • When investigating security incidents that require analyzing network packets with scapy
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Python 3.8+ with scapy library installed (pip install scapy)
  • Root/administrator privileges for raw socket operations (sniffing, sending)
  • Npcap (Windows) or libpcap (Linux) for packet capture
  • Authorization to perform packet operations on target network

Steps

  1. Read and parse pcap/pcapng files with rdpcap() for offline analysis
  2. Extract protocol layers (IP, TCP, UDP, DNS, HTTP) and field values
  3. Compute traffic statistics: top talkers, protocol distribution, port frequency
  4. Detect SYN flood patterns by analyzing TCP flag ratios
  5. Identify DNS exfiltration indicators via query length and entropy analysis
  6. Craft custom probe packets for authorized network testing
  7. Export findings as structured JSON report

Expected Output

JSON report containing packet statistics, protocol distribution, top source/destination IPs, detected anomalies (SYN floods, DNS tunneling indicators, fragmentation attacks), and per-flow summaries.

来源与署名

来源:mukul975/Anthropic-Cybersecurity-Skills位于skills/analyzing-network-packets-with-scapy提交54a7988

许可证: Apache-2.0

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架