March 2019
Beginner
490 pages
12h 40m
English
As we saw previously, you can use the FileCapture method to open a previously saved trace file. You can also use pyshark to sniff from an interface in real time with the LiveCapture method, like so:
import pyshark # Sniff from interface in real time capture = pyshark.LiveCapture(interface='eth0') capture.sniff(timeout=10) <LiveCapture (5 packets)>
Once a capture object is created, either from a LiveCapture or FileCapture method, several methods and attributes are available at both the capture and packet level. The power of pyshark is that it has access to all of the packet decoders that are built into TShark.
Now, let's see what methods provide the returned capture object.
To check this, we can use the ...
Read now
Unlock full access