Skip to content

Add PCAP / PCAPNG packet-capture parser - #39

Merged
copyleftdev merged 1 commit into
mainfrom
feat/pcap
May 31, 2026
Merged

copyleftdev merged 1 commit into
mainfrom
feat/pcap

Conversation

@copyleftdev

Copy link
Copy Markdown
Owner

Implements the PCAP / PCAPNG plugin — issue #15 (binary, hard).

What

Decodes a capture to one row per packet with the columns the detectors need:

  • timestamp (epoch seconds, Float) — the marquee input for
    beaconing/C2 detection via cadence on inter-arrival times;
  • length (original) + caplen — volume point spikes;
  • src_ip / dst_ip / ip_proto (Ethernet or raw IPv4/IPv6, via etherparse)
    — mv over per-packet features.

The container is decoded by pcap-parser, covering both legacy PCAP and
PCAPNG
, either byte order, and µs or ns resolution: the legacy header sets
the link type + precision; the PCAPNG interface block sets the link type +
timestamp resolution; enhanced and simple packet blocks decode accordingly. L3
decode is best-effort — an unsupported link type or undecodable packet just
yields no L3 columns (the packet keeps its timestamp/length).

Routing

  • Binary magic (the four legacy magics + the PCAPNG section-header magic),
    confidence MAGIC; extensions .pcap / .pcapng / .cap.

Feature gating

Behind the default-on pcap feature (mirrors the polars/evtx binary
readers), so the text-only --no-default-features build stays lean.

Testing

Hand-built legacy + PCAPNG fixtures roundtrip (timestamps, original vs captured
length, ns precision, PCAPNG µs resolution); real Ethernet/IPv4/UDP and IPv6/UDP
frames exercise the L3 decode (incl. the raw-IP from_ip path); malformed input
is a clean AxError::Parse.

Gates

  • fmt / clippy -D warnings / full workspace tests green (default and
    --no-default-features).
  • Mutation gate: 0 surviving mutants on pcap.rs.
  • Smoke: a capture beaconing every 60s routes as pcap and the C2 regularity is
    flagged by cadence on timestamp (exit 1).

Closes #15

🤖 Generated with Claude Code

New PcapParser in ax-normalize. Decodes a capture to one row per packet: the
marquee timestamp column (epoch seconds, Float) for beaconing/C2 detection via
cadence on inter-arrival times, plus length (original) and caplen for volume
point spikes, and src_ip/dst_ip/ip_proto (Ethernet or raw IPv4/IPv6, via
etherparse) for mv over per-packet features.

The container is decoded by pcap-parser, covering both legacy PCAP and PCAPNG,
either byte order, and microsecond or nanosecond resolution: the legacy header
sets the link type and ns/us precision; the PCAPNG interface-description block
sets the link type and timestamp resolution, and enhanced/simple packet blocks
are decoded accordingly. L3 decode is best-effort — an unsupported link type or
an undecodable packet just yields no L3 columns.

Binary magic (the four legacy magics plus the PCAPNG section-header magic),
confidence MAGIC; extensions .pcap/.pcapng/.cap. Behind the default-on pcap
feature (mirrors the polars/evtx binary readers), so the text-only build stays
lean. Hand-built legacy + PCAPNG fixtures roundtrip; a real Ethernet/IPv4/UDP
and IPv6/UDP frame exercise the L3 decode; malformed input is a clean Parse error.

Mutation gate: 0 surviving mutants on the new file.

Closes #15

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented May 31, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@copyleftdev, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 6 minutes and 55 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 6f0e03eb-dbf4-4285-8469-3d2db7ab2a14

📥 Commits

Reviewing files that changed from the base of the PR and between 0777c56 and 0c01ea9.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (4)
  • crates/ax-normalize/Cargo.toml
  • crates/ax-normalize/src/parser.rs
  • crates/ax-normalize/src/parsers/mod.rs
  • crates/ax-normalize/src/parsers/pcap.rs
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/pcap

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@copyleftdev
copyleftdev merged commit 6c915a3 into main May 31, 2026
2 checks passed
@copyleftdev
copyleftdev deleted the feat/pcap branch May 31, 2026 07:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add a PCAP / PCAPNG parser (packet capture)

1 participant