v0.1.0
·
730 commits
to develop
since this release
Added
Core pipeline
- PCAP reader supporting five link types: Ethernet (1), Raw IP (101), Linux
Cooked / SLL (113), IPv4 (228), and IPv6 (229). Snaplen-truncated captures
(e.g.tcpdump -s 96) are accepted via the unvalidated raw-record path.
pcapng is not supported. - Zero-copy L2–L4 packet decoding via
etherparse. The full capture is loaded
into memory as aVec<RawPacket>before analysis; available RAM determines
the practical file-size limit. - Single-pass analysis pipeline: Reader → Decoder → Analyzers → Reporter,
producing host/service/protocol summaries and threat findings in one pass. - Directory expansion: pass a directory path and wirerust processes every
.pcapfile found within it (.pcapngfiles are excluded).
TCP stream reassembly engine
- Forensic-grade TCP stream reassembly with a first-wins overlap policy
(earlier-arriving data wins on byte conflicts). - Configurable per-direction depth limit (
--reassembly-depth, default 10 MB)
and global memory cap (--reassembly-memcap, default 1024 MB). - Evasion and anomaly detection: overlapping-segment counting
(--overlap-threshold, default 50 per flow direction), consecutive
small-segment detection (--small-segment-threshold, default 100 run
length;--small-segment-max-bytes, default 16 B), and out-of-window
segment counting (--out-of-window-threshold, default 100). - Interactive-protocol port exemption from small-segment detection (default:
ports 23 and 513; overridable via--small-segment-ignore-ports). - Idle-flow expiry: flows silent longer than
--flow-timeoutseconds
(default 300) are evicted from the flow table. - Reassembly statistics surfaced in all output formats: bytes reassembled,
segment-limit drops, overlap count, out-of-window count, and small-segment
count.
Protocol analyzers
- DNS analyzer: traffic statistics including query/response counts,
top queried hostnames, and query-type distribution. - HTTP/1.x analyzer (requires TCP reassembly): stream-level request and
response parsing with detection for path traversal sequences, web-shell
indicators, unusual HTTP methods, missing or empty Host headers, and other
header anomalies. Parse-error isolation prevents one poisoned stream from
affecting other flows. - TLS analyzer: ClientHello and ServerHello parsing; SNI extraction and
classification (clean ASCII, ASCII control bytes C0/DEL, valid non-ASCII
UTF-8, non-UTF-8 bytes); JA3 and JA3S fingerprinting with GREASE
value filtering; weak cipher detection; deprecated SSL 2.0 and 3.0
detection. - Stream dispatcher: content-first protocol classification (TLS record
signature, HTTP prefix, then port-based fallback) with classification
caching and a configurable retry budget (max_classification_attempts).
Threat detection and MITRE ATT&CK
- Finding system with verdict, confidence score, source IP, direction tag,
and optional MITRE ATT&CK technique ID. - Static MITRE ATT&CK catalog mapping technique IDs (T-format) to tactic and
technique name, consumed by the terminal reporter when--mitreis passed. --mitreflag groups terminal output by ATT&CK tactic with technique names
displayed alongside each finding.
Output formats and CLI
- Colored terminal reporter with MITRE tactic grouping, top-SNI and top-host
tables, reassembly statistics section, and skipped-packet accounting.
Deterministic tie-ordering for top-SNI and top-host tables. - JSON reporter: structured output with deterministic field ordering,
skipped_packetscounter, anddropped_findingscounter.#[non_exhaustive]
on public enums for forward compatibility. - CSV reporter: 9-column findings table (tactic, verdict, confidence,
source IP, destination IP, port, protocol, description, MITRE technique).
CSV-injection neutralization applied to all string fields. Evidence strings
joined with a pipe separator. - Output routing:
--output-format json|csvwrites to stdout;--json [FILE]
and--csv [FILE]write to a file (or stdout if no path is given).
--jsonand--csvare mutually exclusive. analyzesubcommand with--dns,--http,--tls,--mitre, and
-a/--allflags. HTTP analysis automatically enables TCP reassembly.summarysubcommand with optional--hostsflag for a per-host IP
breakdown. Outputs total packets, bytes, protocol distribution, and
service-hint counts.--no-colorflag disables ANSI color globally.- Zero, non-integer, or out-of-range values for
--reassembly-depthand
--reassembly-memcapare rejected at argument-parse time.
Observability
dropped_findingscounter tracks findings discarded when the per-analyzer
cap is reached; surfaced in JSON output.skipped_packetscounter tracks packets skipped during decode; surfaced in
all output formats.truncated_recordscounter tracks snaplen-truncated records; surfaced in
JSON output.- Criterion micro-benchmarks for hot paths in the decoder and reassembly
engine.
Security
- Bumped
indicatiffrom 0.17 to 0.18 to transitively drop the unmaintained
number_prefixcrate (RUSTSEC-2025-0119). cargo auditandcargo denysupply-chain checks added to CI.- Release profile enables
overflow-checks = trueso integer overflows are
caught in release builds. - Output sanitization in the terminal reporter guards against C1 control bytes
in packet-derived strings.