🛠️ A collection of Python-based network utilities for scanning, sniffing, and manipulating network traffic. Originally part of JeddahSec/dotfiles, now maintained as a standalone repo.
| Script | Description |
|---|---|
arp_scan.py |
Scans the local network for active hosts using ARP requests |
arp_spoof.py |
Performs ARP spoofing / cache poisoning between hosts |
dns_sniffer.py |
Captures and inspects DNS traffic on the network |
http_sniffer.py |
Captures and inspects HTTP traffic on the network |
icmp_scanner.py |
Discovers live hosts using ICMP (ping) requests |
macchanger.py |
Changes the MAC address of a network interface |
port_scanner.py |
Scans a target host for open TCP ports |
- Python 3.x
- Root/administrator privileges (required for raw sockets, packet sniffing, and interface changes)
- Common packet libraries depending on script, e.g.:
pip install scapy
Each script can be run directly, typically with root privileges:
sudo python3 arp_scan.py
sudo python3 port_scanner.py <target-ip>Check each script's
--helpflag or source for specific arguments and options.
These tools interact directly with network traffic and can disrupt, intercept, or compromise systems on a network. They are intended only for:
- Authorized penetration testing
- Personal lab / homelab environments
- Educational and learning purposes
Do not use these tools against networks or devices you do not own or do not have explicit written permission to test. Unauthorized use of ARP spoofing, packet sniffing, or scanning tools may be illegal in your jurisdiction. The author assumes no liability for misuse.
Provided as-is for educational and authorized security testing purposes. No warranty provided — use at your own risk.