PCAP Sentry
Learn Malware Network Traffic Analysis - Beginner-friendly educational tool
PCAP Sentry is a beginner-friendly educational tool for learning to identify malware network traffic patterns. It analyzes network packet captures (.pcap / .pcapng) and teaches you how to recognize suspicious activity with clear explanations and hands-on practice. Features: - Beginner-focused explanations for understanding suspicious network traffic - Risk scoring (0-100) to learn which patterns indicate malicious behavior - Behavioral detection for beaconing, DNS tunneling, port scanning, data exfiltration - Real-world threat intelligence integration (OTX, URLhaus, AbuseIPDB) - AI-powered guidance with local LLM chat support - Credential extraction learning from unencrypted protocols - C2 pattern detection and Wireshark filter generation - Trainable knowledge base for building malware signature libraries - Works offline with local models and threat databases
winget install --id industrial-dave.PCAP-Sentry --exact --source winget Latest 2026.2.17.2
| Architecture | Scope | Download | SHA256 |
|---|---|---|---|
x64 | — | Download | BFAF4D6C7655B477D0A8D7755DFD1DA998A4E5233E2F79949911CF26EEC2CD84 |
Details
- Homepage
- https://github.com/industrial-dave/PCAP-Sentry
- License
- GPL-3.0
- Publisher
- industrial-dave
- Support
- https://github.com/industrial-dave/PCAP-Sentry/issues
- Copyright
- Copyright (C) 2026 industrial-dave
- Moniker
pcap-sentry