{"adoption": {"forks": 67, "observed_at": "2026-08-28T04:04:10.565015+00:00", "stars": 1264}, "canonical_url": "https://ross.abutalabs.com/products/ptcpdump", "card": {"archived": false, "artifact_type": "cli-tool", "description": "Process-aware, eBPF-based tcpdump", "domain": ["networking", "security", "developer-tools"], "enriched": true, "function": ["networking", "monitoring", "security", "developer-tools"], "health_score": 95, "homepage": null, "language": "C", "license": "MIT", "license_family": "permissive", "maturity": "active", "member_repos": ["mozillazg/ptcpdump"], "name": "mozillazg/ptcpdump", "platform": ["cli"], "pushed_at": "2026-08-23T06:24:16+00:00", "repo": "mozillazg/ptcpdump", "stars": 1264, "tags": ["ebpf", "tcpdump", "packet-capture", "pcapng", "wireshark", "process-aware", "container-observability", "kubernetes", "forensics", "sniffer", "containers", "command-line", "linux", "docker"], "topics": ["ebpf", "ebpf-tc", "tcpdump", "tcpdump-like", "ebpf-go", "network-capture", "packet-capture", "forensics", "bpf", "pcap", "pcapng", "sniffer", "process-aware", "container", "kubernetes"], "urls": [], "use_cases": ["capture network packets filtered by process id or process name", "troubleshoot which container or pod is generating network traffic", "capture packets with tcpdump-like syntax but with process context", "analyze packet captures in Wireshark with embedded process metadata", "debug network issues in Kubernetes pods", "perform low-overhead kernel-space packet filtering with eBPF", "capture traffic across multiple network namespaces", "network forensics identifying which process sent specific packets"], "what_it_is": "ptcpdump is a tcpdump-compatible packet analyzer built on eBPF that automatically annotates captured packets with process, container, and Kubernetes pod metadata. It supports tcpdump-style flags and pcap-filter syntax, and writes PcapNG files with embedded metadata viewable in Wireshark.", "when_to_avoid": ["you are on Linux kernels older than 5.2 or without BPF/BTF support", "you need a cross-platform sniffer for macOS or Windows", "you just need plain tcpdump without process/container context", "you cannot mount debugfs or load eBPF programs due to restricted privileges"], "when_to_choose": ["you need to know which process, container, or pod generated captured traffic", "you want tcpdump compatibility with richer metadata", "you are debugging networking on modern Linux (kernel >= 5.2) with BTF support", "you want kernel-space filtering to reduce capture overhead", "you need PcapNG output with metadata for Wireshark analysis"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/ptcpdump", "repo": "mozillazg/ptcpdump", "role": "main", "score": 77}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:10.565015+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T05:04:03.570061+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "53b2ef790b7470e4a05428d3e1220c4e1f06d6f0ab236f087a5e87bc8397b31c", "fetched_at": "2026-08-28T04:04:10.565015+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mozillazg/ptcpdump"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:10.565015+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T05:04:03.570061+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "53b2ef790b7470e4a05428d3e1220c4e1f06d6f0ab236f087a5e87bc8397b31c", "fetched_at": "2026-08-28T04:04:10.565015+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mozillazg/ptcpdump"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T05:04:03.570061+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "53b2ef790b7470e4a05428d3e1220c4e1f06d6f0ab236f087a5e87bc8397b31c", "fetched_at": "2026-08-28T04:04:10.565015+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mozillazg/ptcpdump"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:10.565015+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:10.565015+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:10.565015+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T05:04:03.570061+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "53b2ef790b7470e4a05428d3e1220c4e1f06d6f0ab236f087a5e87bc8397b31c", "fetched_at": "2026-08-28T04:04:10.565015+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mozillazg/ptcpdump"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:10.565015+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:10.565015+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T05:04:03.570061+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "53b2ef790b7470e4a05428d3e1220c4e1f06d6f0ab236f087a5e87bc8397b31c", "fetched_at": "2026-08-28T04:04:10.565015+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mozillazg/ptcpdump"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:10.565015+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:10.565015+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:10.565015+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T05:04:03.570061+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "53b2ef790b7470e4a05428d3e1220c4e1f06d6f0ab236f087a5e87bc8397b31c", "fetched_at": "2026-08-28T04:04:10.565015+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mozillazg/ptcpdump"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:10.565015+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:10.565015+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T05:04:03.570061+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "53b2ef790b7470e4a05428d3e1220c4e1f06d6f0ab236f087a5e87bc8397b31c", "fetched_at": "2026-08-28T04:04:10.565015+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mozillazg/ptcpdump"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T05:04:03.570061+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "53b2ef790b7470e4a05428d3e1220c4e1f06d6f0ab236f087a5e87bc8397b31c", "fetched_at": "2026-08-28T04:04:10.565015+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mozillazg/ptcpdump"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T05:04:03.570061+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "53b2ef790b7470e4a05428d3e1220c4e1f06d6f0ab236f087a5e87bc8397b31c", "fetched_at": "2026-08-28T04:04:10.565015+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mozillazg/ptcpdump"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T05:04:03.570061+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "53b2ef790b7470e4a05428d3e1220c4e1f06d6f0ab236f087a5e87bc8397b31c", "fetched_at": "2026-08-28T04:04:10.565015+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mozillazg/ptcpdump"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 99, "longevity": 62, "rhythm": 57}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 880, "days_push": 10, "days_rel": 290, "gap_med": 20.5, "n_releases_24m": 19}, "score": 77, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}