Version 2 is a release candidate
Packet analysis.
Packet analysis.
Pure Ruby.
Capture live traffic, read pcap files, and inspect protocols from the command line or your Ruby application. Runs on Linux and macOS using Ruby's standard libraries.
Protocol treeOutput excerpt
$ redhound -r trace.pcapng -T tree
Frame 1: 60 bytes on wire, 60 captured
└─ Ethernet
eth.src: 02:00:00:00:00:01
└─ Internet Protocol v4
ip.src: 192.0.2.1
ip.dst: 192.0.2.2
└─ Transmission Control Protocol
tcp.srcport: 40000
tcp.dstport: 9999
tcp.flags.syn: true
tcp.stream: 0
Ruby 3.3+Linux · macOSpcap · pcapngCLI · Ruby API
From live traffic
to decoded fields.
Use the same capture files, filters, and packet model in a terminal session or inside your application.
- Live capture
- Linux socket/ring and macOS BPF backends, kernel timestamps, direction selection, and drop statistics.
- Portable capture files
- Read and write pcap/pcapng, stream through standard input/output, and rotate files by size or time.
- Protocol dissection
- Inspect Ethernet, IPv4/IPv6, TCP/UDP, DNS, HTTP/1.x, TLS hellos, and tunneled traffic.
- Capture filters
- Compile tcpdump-style expressions to classic BPF in Ruby, with the same filter for live traffic and saved files.
- Stateful analysis
- Follow TCP streams, reassemble application data, and report conversations, endpoints, and traffic intervals.
- Ruby integration
- Access typed fields and structured diagnostics, export JSON, and register custom protocol dissectors.
gem install redhound --pre
redhound --version
# Open an existing capture; no root required.
redhound -r trace.pcapng -T tree
redhound -r trace.pcapng -T ndjson 'udp port 53'
Live capture needs root or capture permissions. Start with the sample capture to try file analysis as your regular user.
Start with a capture.
Keep going in Ruby.
Install the release candidate, choose the output you need, and use the packet API when you're ready to build.
require 'redhound'
Redhound.open('trace.pcapng') do |reader|
reader.each do |packet|
puts packet.summary
p packet['ip.src']
end
end
Explore the Ruby API