{"repo":"srixivas/PcapXray","free":true,"listed":false,"github":"https://github.com/srixivas/PcapXray","clone":"git clone https://github.com/srixivas/PcapXray.git","description":":snowflake: PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight important communication and file extraction","language":"Python","stars":1876,"topics":["forensics","pcap","network","python","computer-forensics","tor-traffic","forensic-analysis","cybersecurity","network-diagram","tor"],"license":"GPL-2.0","category":"security-tools","readme_excerpt":"PcapXray A network forensics tool — visualize PCAP files or live traffic as an annotated network diagram with device identification, protocol classification, Tor detection, and malicious traffic flagging. --- Module Overview --- Design Specification Goal Given a PCAP file or a live network interface, plot a network diagram displaying hosts, traffic flows, important/Tor/malicious communication, and data involved in each session. Problem - Investigation of a PCAP file takes a long time given the initial glitch to start the investigation - Faced by every forensics investigator and anyone analyzing network traffic Solution: Speed up the investigation process Make a network diagram with the following features: Tool Highlights: - Network Diagram — summary network diagram of the full network - Web traffic with server details - Tor traffic detection - Possible malicious traffic flagging - Data obtained from packets in report — device/traffic/payloads - Device details — OUI vendor, hostname resolution, whois - Live traffic capture with real-time graph updates - Interactive graph — pyvis HTML for in-browser exploration - Session persistence — SQLite cache for reload without re-analysis --- Screenshots Main application panel Static network graph — natural layout with auto-fit zoom --- Demo --- Setup Requirements: Python 3.10+ Linux (Ubuntu/Debian) If using a specific Python version (3.11, 3.12), replace python3-tk with python3.11-tk or python3.12-tk . Install Pillow via pip only — do no","default_branch":null,"files":null,"tree":[],"storefront":"/r/srixivas","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/srixivas/PcapXray/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}