Version 2 is a release candidate

Packet analysis.
Pure Ruby.

Capture live traffic, read pcap files, and inspect protocols from the command line or your Ruby application. Runs on Linux and macOS using Ruby's standard libraries.

Protocol treeOutput excerpt
$ redhound -r trace.pcapng -T tree

Frame 1: 60 bytes on wire, 60 captured
└─ Ethernet
   eth.src: 02:00:00:00:00:01
   └─ Internet Protocol v4
      ip.src: 192.0.2.1
      ip.dst: 192.0.2.2
      └─ Transmission Control Protocol
         tcp.srcport: 40000
         tcp.dstport: 9999
         tcp.flags.syn: true
         tcp.stream: 0
Ruby 3.3+Linux · macOSpcap · pcapngCLI · Ruby API

From live traffic
to decoded fields.

Use the same capture files, filters, and packet model in a terminal session or inside your application.

Live capture
Linux socket/ring and macOS BPF backends, kernel timestamps, direction selection, and drop statistics.
Portable capture files
Read and write pcap/pcapng, stream through standard input/output, and rotate files by size or time.
Protocol dissection
Inspect Ethernet, IPv4/IPv6, TCP/UDP, DNS, HTTP/1.x, TLS hellos, and tunneled traffic.
Capture filters
Compile tcpdump-style expressions to classic BPF in Ruby, with the same filter for live traffic and saved files.
Stateful analysis
Follow TCP streams, reassemble application data, and report conversations, endpoints, and traffic intervals.
Ruby integration
Access typed fields and structured diagnostics, export JSON, and register custom protocol dissectors.
gem install redhound --pre
redhound --version

# Open an existing capture; no root required.
redhound -r trace.pcapng -T tree
redhound -r trace.pcapng -T ndjson 'udp port 53'

Live capture needs root or capture permissions. Start with the sample capture to try file analysis as your regular user.

Start with a capture.
Keep going in Ruby.

Install the release candidate, choose the output you need, and use the packet API when you're ready to build.

require 'redhound'

Redhound.open('trace.pcapng') do |reader|
  reader.each do |packet|
    puts packet.summary
    p packet['ip.src']
  end
end
Explore the Ruby API