wtfbbqhax / pcapfifo

Spool pcaps through a pipe

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

pcapfifo

Spool pcaps through a pipe

Whats it good for?

Tools that support readback via pcap_open_offline() etc.. will stop processing packets once EOF occurs, by feeding pcap's through a pipe this can be avoided.

Like what?

Compile

~ ❯❯❯ c++ -std=c++11 -lpcap -o pcapfifo pcapfifo.cc

Run

~ ❯❯❯ mkfifo pcap.fifo
~ ❯❯❯ ./pcapfifo in.pcap <in2...N.pcap> pcap.fifo
~ ❯❯❯ snort -c snort.lua -Acmg -r pcap.fifo

About

Spool pcaps through a pipe


Languages

Language:C++ 100.0%