Analyzing Network Packets With Scapy

mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-network-packets-with-scapy

作者 mukul97554a798831d2266a3ca61ce68a7acb80b81160d57Apache-2.034K 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫5 週前更新

Use Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets. Use when performing authorized network reconnaissance, protocol-level forensic analysis, or building traffic anomaly detection during security testing.

包含腳本Security
AI 產生的概覽

使用 Scapy 建構、嗅探與解析封包,分析 pcap 檔案並偵測異常網路流量。

功能
引導代理使用 Scapy 這個 Python 函式庫,在協定層粒度上建構、傳送、嗅探與解析 TCP、UDP、ICMP 與 DNS 封包。內容涵蓋離線讀取 pcap 與 pcapng 檔案、擷取協定層與欄位值,以及統計流量特徵,例如主要通訊對象、協定分布與連接埠頻率。也說明如何透過 TCP 旗標比例辨識 SYN 洪水模式、藉由查詢長度與熵值找出 DNS 外洩跡象,並將結果匯出為結構化 JSON 報告,內含封包統計、異常項目與逐流摘要。
適用情境
適用於經授權的網路偵察、對擷取流量的協定層鑑識分析,或在安全測試中建置流量異常偵測。也適合事件調查、偵測規則與威脅狩獵工作,以及驗證相關攻擊技術的安全監控涵蓋範圍。請僅在獲得授權的網路上執行封包操作。
執行需求
需要 Python 3.8 以上版本並安裝 scapy 函式庫;原始套接字抓取與傳送封包需要 root 或系統管理員權限;Windows 需 Npcap,Linux 需 libpcap;需取得對目標網路執行封包操作的授權。隨附可執行指令碼(scripts/agent.py)以及一份 API 參考文件。

Analyzing Network Packets with Scapy

Overview

Scapy is a Python packet manipulation library that enables crafting, sending, sniffing, and dissecting network packets at granular protocol layers. This skill covers using Scapy for security-relevant tasks including TCP/UDP/ICMP packet crafting, pcap file analysis, protocol field extraction, SYN scan implementation, DNS query analysis, and detecting anomalous traffic patterns such as unusually fragmented packets or malformed headers.

When to Use

  • When investigating security incidents that require analyzing network packets with scapy
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Python 3.8+ with scapy library installed (pip install scapy)
  • Root/administrator privileges for raw socket operations (sniffing, sending)
  • Npcap (Windows) or libpcap (Linux) for packet capture
  • Authorization to perform packet operations on target network

Steps

  1. Read and parse pcap/pcapng files with rdpcap() for offline analysis
  2. Extract protocol layers (IP, TCP, UDP, DNS, HTTP) and field values
  3. Compute traffic statistics: top talkers, protocol distribution, port frequency
  4. Detect SYN flood patterns by analyzing TCP flag ratios
  5. Identify DNS exfiltration indicators via query length and entropy analysis
  6. Craft custom probe packets for authorized network testing
  7. Export findings as structured JSON report

Expected Output

JSON report containing packet statistics, protocol distribution, top source/destination IPs, detected anomalies (SYN floods, DNS tunneling indicators, fragmentation attacks), and per-flow summaries.

來源與署名

來源:mukul975/Anthropic-Cybersecurity-Skills位於skills/analyzing-network-packets-with-scapy提交54a7988

授權條款: Apache-2.0

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架