Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

64 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

β—† NetPhantom v3.2.2 β€” Professional Network Packet Analyzer


  β–ˆβ–ˆβ–ˆβ•—   β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—    β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•—  β–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ•—   β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ•—   β–ˆβ–ˆβ–ˆβ•—
  β–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•β•β•β•šβ•β•β–ˆβ–ˆβ•”β•β•β•    β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ•‘β•šβ•β•β–ˆβ–ˆβ•”β•β•β•β–ˆβ–ˆβ•”β•β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ•‘
  β–ˆβ–ˆβ•”β–ˆβ–ˆβ•— β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—     β–ˆβ–ˆβ•‘       β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β–ˆβ–ˆβ•— β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β–ˆβ–ˆβ–ˆβ–ˆβ•”β–ˆβ–ˆβ•‘
  β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•     β–ˆβ–ˆβ•‘       β–ˆβ–ˆβ•”β•β•β•β• β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘
  β–ˆβ–ˆβ•‘ β•šβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—   β–ˆβ–ˆβ•‘       β–ˆβ–ˆβ•‘     β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘ β•šβ–ˆβ–ˆβ–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘   β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘ β•šβ•β• β–ˆβ–ˆβ•‘
  β•šβ•β•  β•šβ•β•β•β•β•šβ•β•β•β•β•β•β•   β•šβ•β•       β•šβ•β•     β•šβ•β•  β•šβ•β•β•šβ•β•  β•šβ•β•β•šβ•β•  β•šβ•β•β•β•   β•šβ•β•    β•šβ•β•β•β•β•β• β•šβ•β•     β•šβ•β•
                                                          NetPhantom v3.2.2

A Wireshark-inspired network packet sniffer & analyzer built with Python, Scapy, and Tkinter.


πŸ“ Project Structure

NetPhantom/
β”œβ”€β”€ main.py          ← Entry point: CLI launcher & GUI bootstrap
β”œβ”€β”€ capture.py       ← Packet capture engine (Scapy + threading + PCAP import)
β”œβ”€β”€ analyzer.py      ← Deep packet inspection, protocol dissection, threat detection
β”œβ”€β”€ gui.py           ← Professional Tkinter GUI (Midnight Blue theme, 3-pane layout)
β”œβ”€β”€ setup.py         ← Package config: enables `netphantom` CLI command
β”œβ”€β”€ requirements.txt ← Python dependencies
β”œβ”€β”€ SECURITY.md      ← Security policy
└── README.md        ← This file

βš™οΈ Installation

πŸ’» Windows Setup Installer (Recommended)

You can install NetPhantom on Windows using the pre-compiled graphic setup installer:

  1. Navigate to the dist/ directory.
  2. Double-click NetPhantom_Setup.exe.
  3. Follow the wizard steps to install NetPhantom, create Desktop and Start Menu shortcuts, and launch the application.

🐍 Standard Python Installation (Cross-Platform)

1. Prerequisites

  • Python 3.10+
  • Windows: Npcap installed (required by Scapy)
  • Linux/macOS: libpcap (usually pre-installed)

2. Install Dependencies

pip install -r requirements.txt

3. Install NetPhantom CLI Command

# From the project directory:
pip install -e .

# Now you can launch NetPhantom from anywhere:
netphantom

This registers the netphantom command system-wide. Works on Windows, Linux, and macOS.

4. Privileges (REQUIRED for full capture)

Platform How to Run
Windows Right-click terminal β†’ Run as Administrator β†’ netphantom
Linux sudo netphantom
macOS sudo netphantom

πŸš€ Usage

Launch GUI (Default)

netphantom
# or:
python main.py

Open a PCAP File

netphantom --open capture.pcap
netphantom -o traffic.pcap

List Network Interfaces

netphantom -l

Check Version

netphantom --version

🎨 GUI Features β€” Wireshark-Inspired Layout

Three-Pane Layout

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ β—† NetPhantom v3.2.2   [Fileβ”‚Captureβ”‚Analyzeβ”‚Viewβ”‚Help]         β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ [Interface β–Ό] [Capture Filter  ] [β–Ά Start] [β–  Stop] [Proto β–Ό]β”‚
β”‚ πŸ” [Display Filter                              ] [Apply]    β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚                    PACKET LIST (color-coded rows)            β”‚
β”‚ No. β”‚ Time β”‚ Source β”‚ Destination β”‚ Protocol β”‚ Length β”‚ Info  β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚  PROTOCOL TREE       β”‚  HEX DUMP                            β”‚
β”‚  β–Έ Frame: 74 bytes   β”‚  0000  45 00 00 4a 1b 3e  E..J.>    β”‚
β”‚  β–Έ Ethernet II       β”‚  0010  80 11 00 00 0a 00  ......    β”‚
β”‚  β–Έ IPv4: 10.0β†’8.8    β”‚  0020  08 08 08 08 d5 3e  .....>    β”‚
β”‚  β–Έ UDP: 54590β†’53     β”‚                                      β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ ● CAPTURING on Wi-Fi β”‚ 1,247 packets β”‚ 38.2 pkt/s β”‚ 14:32  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Panel Descriptions

Panel Description
Menu Bar File (Open/Save PCAP, Export JSON), Capture, Analyze, View, Help
Toolbar Interface selector, BPF capture filter, Start/Stop buttons
Display Filter Post-capture search & protocol filter
Packet List Color-coded rows: click to inspect, double-click for detail popup
Protocol Tree Wireshark-style expandable protocol dissection (Ethernet β†’ IP β†’ TCP β†’ App)
Hex Dump Raw packet bytes with offset, hex, and ASCII columns
Side Panel Tabbed: πŸ“Š Stats, πŸ”— Streams, ⚠ Alerts, 🌐 Endpoints, πŸ“ˆ Graph

⌨️ Keyboard Shortcuts

Key Action
F5 Start capture
F6 Stop capture
Ctrl+O Open PCAP file
Ctrl+S Save as PCAP
Ctrl+F Focus display filter
Ctrl+L Clear all packets
Ctrl+R Restart capture
Ctrl++ Zoom in
Ctrl+- Zoom out
Escape Stop capture
Double-click Open packet detail popup

🎨 Color Coding (Packet Rows)

Color Protocol
🟒 Emerald TCP
πŸ”΅ Blue UDP
🟑 Amber ICMP
🟣 Violet ARP
🩡 Cyan DNS / TLS
🟠 Orange HTTP
🟒 Teal HTTPS / QUIC
πŸ’— Pink TLS Handshake
πŸ”΄ Red BG Threat / Alert packets

πŸ” Threat Detection

Threat Detection
Port Scan > 15 unique dst ports from one IP
SYN Flood > 50 SYN packets/sec from one IP
DoS / High Traffic > 100 packets/sec from one IP
ICMP Flood > 50 ICMP packets/sec from one IP
DNS Flood > 30 DNS queries/sec from one IP
ARP Spoofing IP address changes MAC address

Alerts appear in the ⚠ Alerts tab and as red-highlighted rows in the packet list.


πŸ“¦ Export Formats

Format Description
.pcap Standard packet capture (open in Wireshark)
.json Parsed packet summaries (for scripting/analysis)

🧠 Architecture

main.py  (NetPhantom Entry Point)
  β”œβ”€ parse_arguments()   β†’ argparse (--open, -l, --version)
  β”œβ”€ check_privileges()  β†’ admin/root check
  └─ run_gui()           β†’ gui.py β†’ PacketSnifferGUI
                                    β”‚
                              capture.py β†’ CaptureEngine
                                    β”‚        β”œβ”€ sniff() [background thread]
                                    β”‚        β”œβ”€ load_pcap() [PCAP import]
                                    β”‚        β”œβ”€ Queue<pkt_info> (10000)
                                    β”‚        └─ export_pcap / export_json
                                    β”‚
                              analyzer.py β†’ PacketAnalyzer
                                             β”œβ”€ parse(pkt) β†’ dict
                                             β”œβ”€ build_protocol_tree(pkt) β†’ dissection
                                             β”œβ”€ format_hex_dump(pkt) β†’ hex view
                                             β”œβ”€ get_stats() β†’ dict
                                             β”œβ”€ _detect_threats() β†’ alerts
                                             └─ endpoint/stream tracking

πŸ“‹ Requirements

Python >= 3.10
scapy >= 2.5.0
colorama >= 0.4.6
psutil >= 5.9.0
tkinter (bundled with Python)
Npcap (Windows only) β€” https://npcap.com

πŸ›‘οΈ Security & Ethics

⚠ Warning: Only use this tool on networks you own or have explicit written permission to monitor.

This tool is built for:

  • βœ… Authorized penetration testing
  • βœ… Network troubleshooting on your own network
  • βœ… Cybersecurity education and learning
  • βœ… CTF/lab environments
  • ❌ NOT for unauthorized surveillance

πŸ§ͺ Testing

# Generate test traffic
ping 8.8.8.8
curl http://example.com
nslookup google.com

πŸ› Troubleshooting

Issue Fix
Permission denied Run as Administrator (Windows) or sudo (Linux)
No packets captured Install Npcap (Windows) or check interface name
Interface not found Run netphantom -l to list available interfaces
Scapy import error pip install -r requirements.txt
GUI doesn't open Ensure tkinter is installed (python -m tkinter)
netphantom not found Run pip install -e . from the project directory

πŸ‘¨β€πŸ’» Author

Lucky β€” Ethical Hacker

Tool Name: NetPhantom v3.2.2

πŸ“œ License

This project is licensed under the Apache License 2.0. See the LICENSE file for details.


"With great packet-sniffing power comes great responsibility."

About

NetPhantom is a modern network packet sniffer and analyzer that provides real-time traffic visibility, protocol insights, and deep packet analysis through a clean GUI interface.

Topics

Resources

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages