一个零依赖的PCAP/PCAPNG分析工具,专注于身份验证故障排除,完全使用Python标准库构建。

Stars

11

7 天增长

暂无数据

Fork 数

4

开放 Issue

0

开源协议

暂无数据

最近更新

2026-06-26

AI 仓库情报摘要
FR-AI / ANALYSIS

为什么值得关注

无需安装scapy或Wireshark等外部包,却能深入分析Kerberos、NTLM、RADIUS、WPA、TLS等多种协议,并内置Web仪表板,可选集成hashcat进行密码破解。

适合谁使用

  • 安全专业人员与渗透测试人员
  • 排查身份验证问题的网络管理员
  • 诊断登录故障的IT支持人员
  • 分析网络抓包的取证分析师

典型使用场景

  • 诊断Kerberos错误代码(如PREAUTH_FAILED、CLIENT_REVOKED)
  • 提取可破解的NetNTLMv1/v2、Kerberoast和AS-REP roast哈希
  • 无需外部工具即可验证PCAP文件完整性和元数据
  • 评估遗留协议(FTP、TELNET、SNMP)中的明文凭据

项目优势

  • 纯Python实现,零依赖(仅使用标准库)
  • 广泛的协议覆盖:Kerberos、NTLM、RADIUS、WPA、TLS、LDAP、HTTP、MSSQL等
  • 内置Web仪表板,支持hashcat作业管理和基于令牌的安全机制
  • 导出hashcat就绪文件,并智能优先处理可破解账户

使用前须知

  • 无法读取未提供密钥的加密TLS流量
  • 轻量级TCP重组可能在大量碎片或乱序的抓包中丢失数据
  • 不解密Kerberos或NTLM的密文内容(仅提供元数据和错误信息)

README 快速开始

Quick start

项目描述

a packet capture tool to identify and extract key material and clear text credentials from common networking protocols. very alpha, use at own risk. Copyright (c) Xservus Limited

相关仓库与替代方案

根据分类、Topic 和编程语言匹配的相似项目。

nsdkinx
精选
nsdkinx GitHub avatar

twell

Twell is a tiny, embeddable, zero-allocation physics engine for interruptible, Apple-style UI animations, available as a single-header C library with Python bindings.

移动开发设计与创意
17
V4bel
V4bel GitHub avatar

Januscape

Januscape (CVE-2026-53359) is a 16-year-old use-after-free vulnerability in KVM/x86's shadow MMU that allows a guest to escape to the host on both Intel and AMD architectures.

C
512
bryanthaboi
bryanthaboi GitHub avatar

pokemon-gen1-recomp-project

A native LÖVE2D recreation of Pokémon Red and Blue that extracts game data from a player-supplied ROM to provide enhanced features like modding, controls rebinding, and link play.

C
349