Skip to content

Repository files navigation

NetScope

NetScope is a Rust packet and flow investigation tool. It reads a PCAP or captures live traffic, tracks bidirectional TCP/UDP flows, reports two configurable anomaly heuristics, and can serve an optional local dashboard. Offline analysis is the rootless, reproducible starting point.

cargo build --locked --release
./target/release/netscope --read-pcap examples/pcaps/normal.pcap --quiet \
  --summary-json /tmp/netscope-summary.json \
  --export-json /tmp/netscope-flows.json

The checked-in trace contains eight synthetic packets across one TCP/TLS and one UDP/DNS flow. It is small, deterministic, and requires no capture privileges. See all PCAP investigations for expected fields and parser-edge cases.

Live capture requires permission to read the interface, usually sudo or Linux CAP_NET_RAW. The dashboard binds to 127.0.0.1 by default. See Quickstart for setup, live capture, and troubleshooting.

Documentation

  • Quickstart: build, first PCAP, live permissions, and troubleshooting.
  • Reference: config precedence, output formats, and summary semantics.
  • Design: parsing scope, flows, anomalies, pipeline, and dashboard boundaries.
  • Performance: reproducible offline measurements and the Linux live-loss procedure.
  • Tool comparison: commands against the same sample PCAP and tool-selection guidance.
  • Changelog: release history and cleanup record.

License

MIT. See LICENSE. Chart.js is vendored for the embedded dashboard; its license is retained at web/static/vendor/chartjs/LICENSE.md.

About

Rust packet and flow analyzer with offline PCAP analysis, live capture, TCP/UDP flow tracking, anomaly heuristics, and a local dashboard.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Used by

Contributors

Languages