Ross ROSS = Recommend OSS · open-source software intelligence for agents

USArmyResearchLab/Dshell

Dshell is a network forensic analysis framework. observed · 2026-08-28

github.com/USArmyResearchLab/Dshell · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4277
  • days_rel: n/a
  • days_push: 848
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

5492 stars · 1135 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Dshell is an extensible network forensic analysis framework written in Python for dissecting network packet captures (pcap/pcapng). It supports plugin development, stream reassembly, IPv4/IPv6, chainable plugins, and parallel processing.

Use cases

  • analyze pcap files for network forensics
  • dissect network packet captures with custom plugins
  • reassemble TCP streams from packet captures
  • investigate suspicious network traffic during incident response
  • extract TLS metadata like JA3 fingerprints from pcaps
  • chain multiple analysis plugins over a capture
  • geolocate IP addresses seen in network traffic

When to choose

  • you need to perform deep packet analysis on pcap files
  • you want an extensible framework to write custom network forensic plugins
  • you need stream reassembly with IPv4 and IPv6 support
  • you are doing incident response or network security investigations on Linux

When to avoid

  • you need a real-time network intrusion detection system rather than offline pcap analysis
  • you require a GUI-based packet analyzer like Wireshark
  • you need live traffic capture and analysis rather than processing saved capture files
  • you work primarily on Windows or macOS since it is developed for Linux

Facets

framework · maturity active

security networking parser plugin-system developer-tools security networking developer-tools python cli network-forensics pcap-analysis packet-capture stream-reassembly digital-forensics incident-response forensics linux

1 source

Member repositories

RepositoryRoleHealth v2
USArmyResearchLab/Dshellmain23

For agents

markdown · JSON · MCP: product_card(name="USArmyResearchLab/Dshell")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem