Skip to content

Offline analysis: pcap files in a sandbox - #22

Merged
githubflyideas merged 1 commit into
mainfrom
pcap-sandbox
Oct 2, 2026
Merged

githubflyideas merged 1 commit into
mainfrom
pcap-sandbox

Conversation

@githubflyideas

Copy link
Copy Markdown
Owner

Upload .pcap/.pcapng (up to 3 files, each at most 50 MB; no compressed files). They go into a separate database under <data>/sandbox; the live data is not touched. Analyse shows them on every page with an orange bar; Back to live data returns; Delete removes files and data. Detection rules run over the capture (scan, port scan, brute force found in the demo example). Demo ships an example capture.

Tests: pcapfile (pcap, pcapng with two interfaces and ns resolution, truncated, non-captures), sandbox (import + findings + delete, limits, name cleaning), api (ds=sb routing, live store untouched, 415 for non-captures).

🤖 Generated with Claude Code

https://claude.ai/code/session_01XEUxFQp8ivofZLm1o6KiXm


Generated by Claude Code

…data

- internal/pcapfile reads pcap (us/ns, both byte orders) and pcapng (IDB
  resolution, EPB/SPB/OPB); no compressed files.
- internal/sandbox: up to 3 files of at most 50 MB, checked while they
  stream to disk; packets become flows (60 s active / 15 s idle) in a
  database of their own under <data>/sandbox; detection rules run over the
  capture; Delete removes files and data. Each file is a device.
- API: ds=sb serves overview/topn/sankey/series/records/threats/findings
  from the sandbox; /api/sandbox, /api/sandbox/files.
- Web UI: Offline analysis page, orange bar while capture files are shown,
  Back to live data; 13 languages.
- Demo: an example capture with a port scan, SMB sweep and RDP guessing.
- README x13, CHANGELOG 0.3.1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XEUxFQp8ivofZLm1o6KiXm
@githubflyideas
githubflyideas merged commit d994d8b into main Oct 2, 2026
16 of 17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants