NetScope is a Rust packet and flow investigation tool. It reads a PCAP or captures live traffic, tracks bidirectional TCP/UDP flows, reports two configurable anomaly heuristics, and can serve an optional local dashboard. Offline analysis is the rootless, reproducible starting point.
cargo build --locked --release
./target/release/netscope --read-pcap examples/pcaps/normal.pcap --quiet \
--summary-json /tmp/netscope-summary.json \
--export-json /tmp/netscope-flows.jsonThe checked-in trace contains eight synthetic packets across one TCP/TLS and one UDP/DNS flow. It is small, deterministic, and requires no capture privileges. See all PCAP investigations for expected fields and parser-edge cases.
Live capture requires permission to read the interface, usually sudo or Linux CAP_NET_RAW. The dashboard binds to 127.0.0.1 by default. See Quickstart for setup, live capture, and troubleshooting.
- Quickstart: build, first PCAP, live permissions, and troubleshooting.
- Reference: config precedence, output formats, and summary semantics.
- Design: parsing scope, flows, anomalies, pipeline, and dashboard boundaries.
- Performance: reproducible offline measurements and the Linux live-loss procedure.
- Tool comparison: commands against the same sample PCAP and tool-selection guidance.
- Changelog: release history and cleanup record.
MIT. See LICENSE. Chart.js is vendored for the embedded dashboard; its license is retained at web/static/vendor/chartjs/LICENSE.md.