-
Notifications
You must be signed in to change notification settings - Fork 1
pcap export
Summary: Three independent pcap-export paths: per-alert (driven by --pcap-dir), manual from the packets view (w key), and per-EAPOL-handshake (driven by --eapol-dir).
Sources: docs/views/packets.md, docs/views/alerts.md, docs/views/eapol.md.
Last updated: 2026-10-01 (#92 handshake pcap record lengths).
- CLI flag:
--pcap-dir DIR. - Triggered by alerts whose rule passes
match_ip+match_porttofire(). - Implementation:
src/alert_pcap.c. - New dedup key → fresh file
alert_<YYYYmmdd_HHMMSS>_<title>.pcapcontaining the packets currently in the ring that match. Each dump is its own file, created exclusively; two in the same second get a_2,_3… suffix instead of overwriting each other. - Clearing alerts (
cin the Alerts view) resets dedup state, so a future hit re-arms and opens a new file.
-
win the Packets view ([4]). - Writes a timestamped
ntop_<YYYYmmdd_HHMMSS>.pcapto cwd containing the packet ring, created exclusively at 0600 (same-second exports get a suffix). A failed write removes the partial file and the view showsexport failed. - Useful for ad-hoc carving when you've narrowed via
/to a flow of interest.
- CLI flag:
--eapol-dir DIR, which requires the--collect-handshakesopt-in (off by default) and expires on--handshake-retentiondays (default 7) — see retention. - For each completed (BSSID, STA) 4-way handshake, writes:
-
DIR/eapol.22000in hashcat 22000 mixed format (WPA*01*…for PMKIDs,WPA*02*…for full handshakes with the MIC field zeroed per spec). -
DIR/<bssid>_<sta>.pcapcontaining the raw 802.11 EAPOL-Key frames (M1..M4, no radiotap, DLT 105). Replayable inaircrack-ng -w wordlist.txt -e <SSID> <file>.pcap, openable in Wireshark / tshark. At most 512 bytes per frame are stored; each record header reportscaplen(stored) andoriglen(as captured) separately, so a truncated frame is visible as one.
-
- Re-completion of the same (BSSID, STA) atomically replaces the prior
.pcapwith the freshest capture (temp file + rename); the.22000file appends.
Each path has its own writer — src/alert_pcap.c, src/pcap_write.c,
src/eapol_log.c — all emitting the classic pcap header (no pcapng) so
the output is portable to every reasonable tool.
Every one of these files holds captured traffic; the EAPOL ones are offline-crackable. Modes do not depend on the umask:
| Path | Dir | File | Create mode |
|---|---|---|---|
--pcap-dir DIR |
0700 | 0600 | exclusive, suffixed on collision |
w in Packets |
(cwd, not checked) | 0600 | exclusive, suffixed on collision |
--eapol-dir DIR |
0700 | 0600 |
eapol.22000 append; per-handshake pcap atomic replace |
--pcap-dir and --eapol-dir are created 0700 when absent. An
existing directory must be owned by sloth's effective uid with no
group/other bits and must not be a symlink — otherwise sloth refuses it
at startup and exits non-zero. It never chmods the path. So --pcap-dir /tmp is refused: /tmp is shared. Files are opened O_NOFOLLOW
relative to the directory descriptor validated at startup, and an
existing file sloth would reuse must itself be private.
Write failures are reported, not swallowed: the first prints one
sloth: <alert pcap|eapol> export failed: … line to stderr and every
one is counted (the EAPOL view shows its count). Partial files are
removed; a failed per-handshake replace keeps the previous capture.
Details for the handshake export: docs/views/eapol.md.
- alerts
- wifi-sigint — the EAPOL view that drives the handshake export.
- architecture
Mirrored from docs/wiki/ on main by .github/scripts/wiki_sync.sh. Edit there, not here — hand edits to this wiki are overwritten on the next push.
Read this first — the complete reference
- what-sloth-does
- how-wifi-works
- monitor-mode
- where-exploits-happen
- wifi-sigint-techniques
- cli-reference
- wifi-state-of-the-art
Start here
Engines
WiFi SIGINT
- wifi-sigint
- non-ip-sensors
- mac-randomisation
- evil-twin-reproducer
- btm-abuse
- action-frames
- research-corpus
- captive-portal
- fragattacks
- tool-fingerprints
- enterprise-rogue
- ipv6-ndp
- smb-snoop
- kerberos-snoop
- ldap-snoop
- bgp-snoop
- ssh-snoop
- rdp-snoop
- snmp-snoop
- mqtt-snoop
UI and infrastructure
- ip-palette
- platform-vtable
- version-checkin
- manifest-format
- pcap-export
- jsonl-schema
- data-socket-exposure
- sqlite-schema
- ring-buffers
Factory infrastructure
Reference
Source material
Maintenance