TUI network packet sniffer.
Provides live packet capture, per-layer dissection, BPF filtering, and pcap export. Useful for troubleshooting over SSH, learning how protocols are structured on the wire, or inspecting your own traffic.
- Scapy's
AsyncSnifferopens a raw socket on the selected interface (or all interfaces) and captures frames matching the optional BPF filter, in a background thread so the UI never blocks, including while waiting for traffic on an idle interface. - Each captured packet is walked layer by layer using Scapy's dissection,
following its actual class chain (
Ether/IP/TCP/...), producing a summary row (time, source, destination, protocol, length) and a full field tree. - The summary is pushed into the live table; selecting any row rebuilds the detail tree with every layer and field for that exact packet, from Ethernet MAC addresses down to TCP flags.
- If PCAP output is armed, each packet is also written immediately to a
timestamped
.pcapfile incaptures/, opened lazily on the first packet so toggling it on and off never creates an empty file. - Protocol and byte counters update live as packets arrive.
Requirements: uv and root/administrator privileges.
Linux/macOS also need libpcap for BPF filters, usually already installed;
otherwise sudo dnf install libpcap (Fedora) or sudo apt install libpcap0.8
(Debian/Ubuntu).
Windows needs Npcap with WinPcap Compatibility Mode enabled.
uv tool install git+https://github.com/batusaribay/network-snifferCapture needs elevated privileges. sudo resets PATH, so give it the full
path to the installed binary:
sudo $(which network-sniffer)For educational purposes and authorized security testing only.
This project is licensed under the MIT License.
