packet-craft
Craft, send, and analyze network packets via Scapy — ARP scan, ping, traceroute, DNS, sniff, pcap analysis
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
メニュー
Craft, send, and analyze network packets via Scapy — ARP scan, ping, traceroute, DNS, sniff, pcap analysis
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
SOC 職業分類に基づく
Run sustained security assessment campaigns against targets using the Ralph Wiggum autonomous loop pattern. Use when asked to start, continue, or manage a pentest campaign.
Control a Flipper Zero and scan BLE targets for authorized security research. Use when asked to interact with Flipper hardware, scan BLE devices, or control RF/IR/NFC/RFID.
Start an autonomous pentest loop. Spawns fresh-context subagents for each phase. Use: /ralph-loop
BLE GATT exploitation methodology — scanning, enumeration, characteristic analysis, payload crafting, and write attacks against Bluetooth Low Energy devices
Run a sustained security assessment campaign — a real pentest, not a simulation
Credential testing methodology — default credential checking, password spraying, credential reuse, and OSINT for leaked credentials
| name | packet-craft |
| description | Craft, send, and analyze network packets via Scapy — ARP scan, ping, traceroute, DNS, sniff, pcap analysis |
Run Scapy commands via Python one-liners in Bash. Requires scapy installed (pip install scapy). Some operations (ARP scan, sniffing) require root/sudo.
Discover devices on a local network by sending ARP requests. Returns IP and MAC address pairs.
sudo python3 -c "
from scapy.all import ARP, Ether, srp
pkt = Ether(dst='ff:ff:ff:ff:ff:ff')/ARP(pdst='192.168.1.0/24')
ans, _ = srp(pkt, timeout=3, verbose=False)
print(f'ARP scan: {len(ans)} host(s) found')
for r in ans:
print(f' {r[1].psrc} -> {r[1].hwsrc}')
"
Adjust timeout= for slower networks (default 3 seconds). Change the CIDR to target the desired subnet.
Check if a host is alive using ICMP echo requests.
sudo python3 -c "
from scapy.all import IP, ICMP, sr1
target = '192.168.1.1'
count = 3
for i in range(count):
reply = sr1(IP(dst=target)/ICMP(), timeout=2, verbose=False)
if reply:
print(f'Reply from {reply.src}: ttl={reply.ttl}')
else:
print('Request timed out')
"
Trace the network path to a target by incrementing TTL.
sudo python3 -c "
from scapy.all import IP, ICMP, sr1
target = '8.8.8.8'
max_ttl = 20
print(f'Traceroute to {target}:')
for ttl in range(1, max_ttl + 1):
reply = sr1(IP(dst=target, ttl=ttl)/ICMP(), timeout=2, verbose=False)
if reply:
print(f' {ttl}: {reply.src}')
if reply.src == target:
break
else:
print(f' {ttl}: * * *')
"
Perform DNS lookups using Scapy (bypasses system resolver). Supports A, AAAA, MX, TXT, NS, etc.
sudo python3 -c "
from scapy.all import IP, UDP, DNS, DNSQR, sr1
domain = 'example.com'
qtype = 'A'
pkt = IP(dst='8.8.8.8')/UDP(dport=53)/DNS(rd=1, qd=DNSQR(qname=domain, qtype=qtype))
reply = sr1(pkt, timeout=3, verbose=False)
if reply and reply.haslayer(DNS):
print(f'DNS {qtype} {domain}:')
for i in range(reply[DNS].ancount):
rr = reply[DNS].an[i] if reply[DNS].ancount > 1 else reply[DNS].an
print(f' {rr.rrname.decode()} -> {rr.rdata}')
if reply[DNS].ancount == 1:
break
else:
print('No DNS response')
"
Capture network packets on an interface for a short duration.
sudo python3 -c "
from scapy.all import sniff
# Adjust: iface='en0', count=20, timeout=5, filter='tcp port 80'
pkts = sniff(count=20, timeout=5, verbose=False)
print(f'Captured {len(pkts)} packets:')
for p in pkts:
print(f' {p.summary()}')
"
Optional BPF filter examples:
filter='tcp port 80' -- HTTP traffic onlyfilter='udp' -- UDP traffic onlyfilter='arp' -- ARP traffic onlyfilter='host 192.168.1.1' -- traffic to/from specific hostTo capture on a specific interface, add iface='en0' (or wlan0 on Linux).
Read and summarize a captured pcap/pcapng file.
python3 -c "
from scapy.all import rdpcap
pkts = rdpcap('capture.pcap')
print(f'Total packets: {len(pkts)}')
protocols = {}
for p in pkts[:50]:
proto = p.lastlayer().__class__.__name__
protocols[proto] = protocols.get(proto, 0) + 1
print('Protocol breakdown:')
for proto, count in sorted(protocols.items(), key=lambda x: -x[1]):
print(f' {proto}: {count} packets')
"
sudo on macOS/Linux.verbose=False to keep output clean.