Scapy getlayer options

Viewed 7045

This is my code:

from scapy.all import *

packets = rdpcap('secret.pcap')

packet_join = []

for packet in packets:
    if packet.haslayer('TCP'):
        raw_data = packet.getlayer(Raw)
        packet_join.append(raw_data)

I only found the getlayer(Raw) from some googling.

My question is, is there a list of the layers I can use for getlayer somewhere? Or more detailed documentation on its use? I couldn't find much in the Scapy documentation.

I know you can also use things like getlayer(TCP)

2 Answers

You can use any Scapy layer as attribute of .getlayer() and .haslayer(). You can list the loaded layers by using ls().

By the way, it's better to write TCP in x rather than x.haslayer(TCP) and x[Raw] rather than x.getlayer(Raw).

for packet in scapy_cap:
    # code = scapy.layers.http.HTTPResponse.(packet)
    if IP in packet:
        ip_src=packet[IP].src
        #save the ip in set
        SRC_IP.update()
        ip_dst=packet[IP].dst
        #save the ip in set
        DST_IP.update()
        if packet.haslayer(DNS) and packet.getlayer(DNS).qr == 0:
            print(str(ip_src)+ " -> " + str(ip_dst) + " : "+ "(" + str(packet.getlayer(DNS).qd.qname)+ ")")

I am currently working with scapy. Here I am using scapy layer option to get the DNS domain name form the pcap file.

Related