major-ai-skills
Version:
Installable agentic skills / AI agent skills (SKILL.md) for Claude Code, Cursor, Codex CLI, Gemini CLI & Antigravity - 402+ professional app, token-efficiency, and common-sense skills. SEO/GEO ready.
141 lines (109 loc) • 7.3 kB
Markdown
---
name: sniffnet
description: "Inspect network traffic with Sniffnet, configure packet filters and bandwidth alerts, and troubleshoot capture drivers."
category: cross-platform
risk: safe
source: self
source_type: self
date_added: "2026-08-26"
tags: ["sniffnet", "pcap", "npcap", "network-monitoring", "packet-capture", "rust", "claude"]
tools: ["claude", "cursor", "gemini", "codex"]
---
# Sniffnet Network Traffic Monitor AI Skill Guide (Claude)
## Overview & Engine Architecture
Sniffnet is a multi-platform, open-source network traffic analyzer written in **Rust**, powered by the `pcap` / `npcap` packet capture driver and the `iced` GUI framework. Claude operates as a Senior Network Security Analyst and Systems Engineer, specializing in **zero-copy packet sniffing**, **Berkeley Packet Filter (BPF) syntax**, **IP ASN and Geolocation lookup mechanics**, and **network interface permission auditing (`CAP_NET_RAW`)**.
### Sniffnet Capture Architecture & Rust Stack
```
┌─────────────────────────────────────────────────────────────┐
│ Sniffnet Engine Architecture │
│ │
│ Kernel Packet Ingestion Layer │
│ ├── Npcap Driver (Windows) / libpcap (Linux & macOS) │
│ ├── Promiscuous & Monitor Mode Network Adapter Hook │
│ └── Kernel-Level Berkeley Packet Filter (BPF) Virtual Mach.│
│ │
│ Rust Processing & Analytics Layer │
│ ├── `pnet` & `etherparse` Zero-Copy Protocol Parsing │
│ ├── MaxMind GeoLite2 ASN / Geolocation Enrichment Engine │
│ └── Ring Buffer Aggregator & Iced Reactive UI Graphs │
└─────────────────────────────────────────────────────────────┘
```
---
## Operational Capabilities & Agent Directives
1. **Packet Capture Driver Remediation**: Diagnose missing adapter enumeration and packet capture failures across Windows (Npcap driver installation with WinPcap API compatibility) and Linux (`setcap cap_net_raw,cap_net_admin=eip`).
2. **BPF Filter Rule Formulation**: Construct high-performance capture filters (`tcp and port 443 and not src host 192.168.1.1`) to isolate target network conversations without overwhelming CPU buffers.
3. **Bandwidth Alert Thresholding**: Configure custom byte and packet rate thresholds to detect port scanning, DDoS volumetric spikes, and unauthorized external data exfiltration.
4. **Network Protocol Auditing**: Identify unencrypted legacy protocol leaks (HTTP, Telnet, FTP, DNS over plaintext) and inspect TLS SNI headers.
---
## Production Python Automation: Automated BPF Packet Sniffer & Flow Inspector
Save this script as `packet_flow_inspector.py` (requires `pip install scapy`) to verify network interface capture rules and analyze packet bandwidth distributions programmatically:
```python
"""
Network Traffic & BPF Filter Verification Tool
Captures and classifies packets across local adapters using Scapy/pcap.
"""
import sys
import time
from collections import defaultdict
from scapy.all import sniff, IP, TCP, UDP
traffic_by_protocol = defaultdict(int)
traffic_by_ip = defaultdict(int)
total_bytes = 0
def packet_callback(packet):
global total_bytes
if IP in packet:
src = packet[IP].src
dst = packet[IP].dst
proto = "TCP" if TCP in packet else "UDP" if UDP in packet else "OTHER"
pkt_len = len(packet)
total_bytes += pkt_len
traffic_by_protocol[proto] += pkt_len
traffic_by_ip[f"{src} -> {dst}"] += pkt_len
def start_capture(interface: str = None, bpf_filter: str = "", duration_sec: int = 10):
print(f"Starting Packet Capture [Duration: {duration_sec}s | Filter: '{bpf_filter or 'ALL'}']...")
sniff(
iface=interface,
filter=bpf_filter if bpf_filter else None,
prn=packet_callback,
timeout=duration_sec,
store=False
)
print("\n--- [CAPTURE ANALYSIS SUMMARY] ---")
print(f"Total Traffic Captured: {total_bytes / 1024:.2f} KB")
print("\nBandwidth by Protocol:")
for proto, b in traffic_by_protocol.items():
print(f" • {proto:<6}: {b / 1024:.2f} KB ({(b / max(total_bytes, 1))*100:.1f}%)")
print("\nTop 5 Active Network Flows:")
sorted_flows = sorted(traffic_by_ip.items(), key=lambda x: x[1], reverse=True)[:5]
for flow, b in sorted_flows:
print(f" • {flow:<35}: {b / 1024:.2f} KB")
if __name__ == "__main__":
# Example: Sniff HTTPS and DNS traffic for 5 seconds
start_capture(bpf_filter="tcp port 443 or udp port 53", duration_sec=5)
```
---
## Technical Troubleshooting Matrix
| Issue & Failure Signature | Root Cause Analysis | Diagnostic & Resolution Pathway |
| :--- | :--- | :--- |
| **`No network adapters found` (Windows)** | Npcap is not installed, or installed without WinPcap API compatibility mode. | 1. Download and install latest **Npcap**.<br>2. Check **Install Npcap in WinPcap API-compatible Mode** during setup.<br>3. Ensure service is active: `net start npcap`. |
| **`Permission Denied` during Packet Capture (Linux)** | Binary lacks Linux raw socket privileges (`CAP_NET_RAW` / `CAP_NET_ADMIN`). | 1. Grant Linux capabilities: `sudo setcap cap_net_raw,cap_net_admin=eip $(which sniffnet)`.<br>2. Alternatively, run with `sudo sniffnet`. |
| **High Packet Drop Rate on High-Throughput (>1Gbps) Interfaces** | Kernel packet buffer overrun before the user-space process can drain packets. | 1. In Sniffnet, specify tighter BPF filters to discard unwanted traffic at the kernel level.<br>2. Increase socket buffer sizes: `sysctl -w net.core.rmem_max=16777216`. |
| **IP Geolocation / Country Flags Show 'Unknown'** | MaxMind GeoLite2 mmdb database failed to download on startup or local offline mode enabled. | 1. Ensure internet connection during initial launch to fetch geolocation database.<br>2. Check `%APPDATA%\sniffnet` or `~/.config/sniffnet/` for database files. |
---
## Command Line Syntax & Permissions
```bash
# Windows CLI: Verify Npcap Service Status via PowerShell
Get-Service -Name npcap
# Linux: Set Persistent Raw Socket Capabilities on Sniffnet Binary
sudo setcap cap_net_raw,cap_net_admin=eip /usr/local/bin/sniffnet
# Launch Sniffnet Application
sniffnet
```
### Essential File Locations
- **Windows User Settings**: `%APPDATA%\sniffnet`
- **Linux User Settings**: `~/.config/sniffnet`
- **macOS User Settings**: `~/Library/Application Support/sniffnet`
- **Npcap Driver Root**: `C:\Program Files\Npcap\`
---
## Agent Operational Directive
> **MANDATORY**: On Linux, execute `setcap cap_net_raw,cap_net_admin=eip` rather than recommending unrestricted `sudo` execution. On Windows, verify Npcap WinPcap API compatibility mode before running packet captures.