packetsniffer_ops
Capture live network, USB, and Bluetooth packets, decode PCAP files, and analyze flows to debug protocols and reverse-engineer device communications.
Instructions
Network interface discovery, live packet capture, and PCAP analysis.
[RATIONALE] Consolidates local packet sniffing, background captures, and offline PCAP analysis tools to stay under tool limits while providing full companion hacking capability.
Operations:
list_interfaces: List active network interfaces with details.
sniff: Blocking capture for the given count/timeout (requires admin privileges). Pass save_path to persist the capture to a PCAP file for later analysis or evidence.
start_capture: Start a capture in the background (non-blocking). Returns a capture_id immediately; the capture runs in a server thread until count/timeout is reached or stop_capture is called. In HTTP daemon mode the capture survives across agent sessions. Poll with capture_status.
capture_status: Status of one capture (capture_id) or all active captures.
stop_capture: Request a stop (takes effect on the next packet, or at timeout). Returns packets captured so far; pass save_path to persist them.
decode_pcap: Deep protocol decode of a PCAP/PCAPNG file via tshark (optional dependency - install Wireshark). Extracts decoded fields Scapy's thin dissectors miss: DNS query/answer names, HTTP requests, TLS SNI hostnames (catches encrypted phone-home domains). Use limit to bound output.
analyze_pcap: Parse a PCAP/PCAPNG capture file and summarize network flows.
Hardware-protocol reverse engineering (pure Python, no tshark needed; for working out what bytes a host sends a device such as a label printer):
usb_list_hubs: List USB root hubs USBPcap can capture on (needs USBPcap installed; UNVERIFIED live).
usb_capture: Capture USB traffic with USBPcapCMD for 'timeout' seconds into save_path (needs USBPcap and administrator rights; UNVERIFIED live). Print/operate the device during the window.
usb_payloads: From a USBPcap capture, the data of each transfer (default host-to-device bulk/interrupt), per-endpoint totals, and any device/interface descriptors in the capture (answers "printer class, HID, or vendor-specific?"). export_path writes the concatenated stream to a .bin file.
btsnoop_payloads: From a Bluetooth HCI capture (btsnoop, or pcap/pcapng link type 187/201), the RFCOMM serial-port-profile data. Best effort: capture from before the connection is made.
diff_captures: Compare two captures' host-to-device streams (file_path vs file_path_b): shared prefix and suffix, changed byte ranges, per-transfer differences. For controlled experiments (blank label vs one dot).
Return Format
{"success": bool, "operation": str, "data": dict | list}
Examples
await packetsniffer_ops(operation="list_interfaces") await packetsniffer_ops(operation="sniff", interface="WiFi", count=10) await packetsniffer_ops(operation="sniff", filter_expr="udp port 53", count=200, timeout=120, save_path="C:/captures/dns.pcap") await packetsniffer_ops(operation="start_capture", filter_expr="udp port 53", count=1000, timeout=300) await packetsniffer_ops(operation="capture_status", capture_id="a1b2c3d4") await packetsniffer_ops(operation="stop_capture", capture_id="a1b2c3d4", save_path="C:/captures/dns.pcap") await packetsniffer_ops(operation="decode_pcap", file_path="C:/captures/dns.pcap", limit=100) await packetsniffer_ops(operation="analyze_pcap", file_path="C:/captures/dns.pcap") await packetsniffer_ops(operation="usb_list_hubs") await packetsniffer_ops(operation="usb_capture", usb_hub="\.\USBPcap1", timeout=30, save_path="C:/captures/02-dot.pcap") await packetsniffer_ops(operation="usb_payloads", file_path="C:/captures/02-dot.pcap", export_path="C:/captures/02-dot.bin") await packetsniffer_ops(operation="btsnoop_payloads", file_path="C:/captures/btsnoop_hci.log", direction="tx") await packetsniffer_ops(operation="diff_captures", file_path="C:/captures/01-blank.pcap", file_path_b="C:/captures/02-dot.pcap")
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| count | No | Number of packets to capture (default: 50, max: 500). | |
| limit | No | Max packets/transfers returned by 'decode_pcap', 'usb_payloads' and 'btsnoop_payloads' (default: 100, max: 500). | |
| timeout | No | Timeout in seconds for capture (default: 10, max: 60). | |
| usb_hub | No | USBPcap filter device for 'usb_capture', e.g. '\\.\USBPcap1' (see 'usb_list_hubs'). | |
| direction | No | Which way the bytes travelled. USB: 'out' (host to device, default), 'in', 'both'. Bluetooth: 'tx' (host to device, default), 'rx', 'both'. 'diff_captures' accepts either spelling. | out |
| file_path | No | Absolute path to the PCAP file for 'analyze_pcap' operation. | |
| interface | No | Network interface identifier (name or GUID) for sniffing. | |
| max_bytes | No | Bytes of hex shown per transfer in 'usb_payloads' / 'btsnoop_payloads' (default: 256, max: 4096). | |
| operation | Yes | Operation to perform. | |
| save_path | No | Absolute path to write captured packets as a PCAP file (e.g. 'C:/captures/out.pcap'). Used by 'sniff' and 'stop_capture'. | |
| capture_id | No | Capture ID from 'start_capture'. Required for 'capture_status' and 'stop_capture'. | |
| usb_device | No | USB device address to select in 'usb_payloads' / 'diff_captures' (default: all devices). | |
| export_path | No | Write the selected byte stream to this file (.bin/.dat/.raw) for 'usb_payloads' / 'btsnoop_payloads'. | |
| file_path_b | No | Second capture file for 'diff_captures' (file_path is the first). | |
| filter_expr | No | BPF filter expression (e.g. 'tcp port 80', 'udp', 'host 192.168.1.100'). | |
| usb_devices | No | 'usb_capture' only: comma list of device addresses to capture (default: all devices on the hub). | |
| usb_endpoint | No | USB endpoint number to select in 'usb_payloads' / 'diff_captures' (e.g. 2 for endpoint 0x02). | |
| transfer_types | No | Comma list of USB transfer types for 'usb_payloads': bulk, interrupt, control, isochronous (default: bulk,interrupt). | |
| inject_descriptors | No | 'usb_capture': ask USBPcap to inject descriptors of already-connected devices (default: false). |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||