Offline analysis: pcap files in a sandbox - #22
Merged
Merged
Conversation
…data - internal/pcapfile reads pcap (us/ns, both byte orders) and pcapng (IDB resolution, EPB/SPB/OPB); no compressed files. - internal/sandbox: up to 3 files of at most 50 MB, checked while they stream to disk; packets become flows (60 s active / 15 s idle) in a database of their own under <data>/sandbox; detection rules run over the capture; Delete removes files and data. Each file is a device. - API: ds=sb serves overview/topn/sankey/series/records/threats/findings from the sandbox; /api/sandbox, /api/sandbox/files. - Web UI: Offline analysis page, orange bar while capture files are shown, Back to live data; 13 languages. - Demo: an example capture with a port scan, SMB sweep and RDP guessing. - README x13, CHANGELOG 0.3.1. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XEUxFQp8ivofZLm1o6KiXm
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Upload .pcap/.pcapng (up to 3 files, each at most 50 MB; no compressed files). They go into a separate database under
<data>/sandbox; the live data is not touched. Analyse shows them on every page with an orange bar; Back to live data returns; Delete removes files and data. Detection rules run over the capture (scan, port scan, brute force found in the demo example). Demo ships an example capture.Tests: pcapfile (pcap, pcapng with two interfaces and ns resolution, truncated, non-captures), sandbox (import + findings + delete, limits, name cleaning), api (ds=sb routing, live store untouched, 415 for non-captures).
🤖 Generated with Claude Code
https://claude.ai/code/session_01XEUxFQp8ivofZLm1o6KiXm
Generated by Claude Code