{"adoption": {"forks": 233, "observed_at": "2026-08-28T04:05:37.567315+00:00", "stars": 1796}, "canonical_url": "https://ross.abutalabs.com/products/stenographer", "card": {"archived": true, "artifact_type": "cli-tool", "description": "Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets.  Discussion/announcements at stenographer@googlegroups.com", "domain": ["security", "networking", "developer-tools"], "enriched": true, "function": ["monitoring", "security", "search-engine", "cli"], "health_score": 10, "homepage": null, "language": "Go", "license": "Apache-2.0", "license_family": "permissive", "maturity": "maintenance", "member_repos": ["google/stenographer"], "name": "google/stenographer", "platform": ["go", "cli"], "pushed_at": "2021-07-26T14:40:13+00:00", "repo": "google/stenographer", "stars": 1796, "tags": ["packet-capture", "full-packet-capture", "pcap", "network-forensics", "incident-response", "intrusion-detection", "bpf-query", "disk-buffering", "command-line", "linux"], "topics": [], "urls": [], "use_cases": ["capture all network traffic to disk for incident response", "buffer packets for intrusion detection analysis", "quickly retrieve specific packets from a large capture history", "query captured packets by IP, port, protocol, and time range", "retain as much packet history as disk allows with automatic rotation", "investigate a security incident after the fact with full packet data"], "what_it_is": "Stenographer is a high-performance full-packet-capture utility that spools network packets to disk at up to ~10Gbps and manages disk usage by deleting the oldest files. It provides a simple BPF-like query language with time filters for quickly retrieving small subsets of captured packets.", "when_to_avoid": ["you need complex packet processing like TCP stream reassembly", "you need to read back large portions of captured traffic", "you need real-time packet analysis or deep protocol inspection", "you need a tool that runs on non-Linux platforms"], "when_to_choose": ["you need full-packet capture at high throughput for forensics or IDS", "you only need to read back a small fraction (<1%) of captured packets", "you want automatic disk management with rolling deletion of old captures", "you prefer a simple BPF-subset query language with time filters"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/stenographer", "repo": "google/stenographer", "role": "main", "score": 10}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:37.567315+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:22:49.113028+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c8abd2bd6ad88440c9c05780a045a670d3f570f1793d71a7ef6d545327ed198e", "fetched_at": "2026-08-28T04:05:37.567315+00:00", "kind": "readme", "missing": false, "url": "https://github.com/google/stenographer"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:37.567315+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:22:49.113028+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c8abd2bd6ad88440c9c05780a045a670d3f570f1793d71a7ef6d545327ed198e", "fetched_at": "2026-08-28T04:05:37.567315+00:00", "kind": "readme", "missing": false, "url": "https://github.com/google/stenographer"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:22:49.113028+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c8abd2bd6ad88440c9c05780a045a670d3f570f1793d71a7ef6d545327ed198e", "fetched_at": "2026-08-28T04:05:37.567315+00:00", "kind": "readme", "missing": false, "url": "https://github.com/google/stenographer"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:37.567315+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:37.567315+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:37.567315+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:22:49.113028+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c8abd2bd6ad88440c9c05780a045a670d3f570f1793d71a7ef6d545327ed198e", "fetched_at": "2026-08-28T04:05:37.567315+00:00", "kind": "readme", "missing": false, "url": "https://github.com/google/stenographer"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:37.567315+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:37.567315+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:22:49.113028+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c8abd2bd6ad88440c9c05780a045a670d3f570f1793d71a7ef6d545327ed198e", "fetched_at": "2026-08-28T04:05:37.567315+00:00", "kind": "readme", "missing": false, "url": "https://github.com/google/stenographer"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:37.567315+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:37.567315+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:37.567315+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:22:49.113028+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c8abd2bd6ad88440c9c05780a045a670d3f570f1793d71a7ef6d545327ed198e", "fetched_at": "2026-08-28T04:05:37.567315+00:00", "kind": "readme", "missing": false, "url": "https://github.com/google/stenographer"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:37.567315+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:37.567315+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:22:49.113028+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c8abd2bd6ad88440c9c05780a045a670d3f570f1793d71a7ef6d545327ed198e", "fetched_at": "2026-08-28T04:05:37.567315+00:00", "kind": "readme", "missing": false, "url": "https://github.com/google/stenographer"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:22:49.113028+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c8abd2bd6ad88440c9c05780a045a670d3f570f1793d71a7ef6d545327ed198e", "fetched_at": "2026-08-28T04:05:37.567315+00:00", "kind": "readme", "missing": false, "url": "https://github.com/google/stenographer"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:22:49.113028+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c8abd2bd6ad88440c9c05780a045a670d3f570f1793d71a7ef6d545327ed198e", "fetched_at": "2026-08-28T04:05:37.567315+00:00", "kind": "readme", "missing": false, "url": "https://github.com/google/stenographer"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:22:49.113028+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c8abd2bd6ad88440c9c05780a045a670d3f570f1793d71a7ef6d545327ed198e", "fetched_at": "2026-08-28T04:05:37.567315+00:00", "kind": "readme", "missing": false, "url": "https://github.com/google/stenographer"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases", "archived"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 4342, "days_push": 1864, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 10, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}