Repository files navigation

pcap2tensor

Vixero Tech

PCAP → ML tensor extraction for network intrusion detection research.

A fast, streaming, production-grade Python library for turning raw packet captures into training-ready tensors. Built for NIDS researchers tired of rolling their own extraction pipeline for every paper.

PyPIPythonLicense: MITarXivCI

Why this exists

Every ML-based network intrusion detection paper reinvents the same pipeline:

  1. Parse a PCAP
  2. Extract per-packet features (size, inter-arrival time, direction, TCP flags, ...)
  3. Slide a window across the sequence
  4. Save as a tensor

Every implementation is a one-file script that doesn't handle PCAPs larger than RAM, doesn't expose clean extension points for custom features, and quietly crashes on the first malformed packet. pcap2tensor is that pipeline, packaged properly — streaming, extensible, and published on PyPI.

Install

pip install pcap2tensor

Python ≥ 3.9. Depends on Scapy, PyTorch, NumPy, tqdm.

Quickstart

frompcap2tensorimportextracttensor=extract("capture.pcap", features="aegis-6d", window_size=1000, stride=500)
print(tensor.shape) # torch.Size([num_windows, 1000, 6])

Feed straight into any sequence model — Transformer, LSTM, SSM, CNN.

Large PCAPs

Streaming chunked processing — never loads the full PCAP into memory:

frompcap2tensorimportPCAPExtractorextractor=PCAPExtractor(
features="aegis-6d",
window_size=1000,
stride=500,
chunk_size=2_000_000, # flush every 2M packets
)
# Option A: save chunked .pt filesextractor.save("massive.pcap", output_dir="./tensors/")
# Option B: stream chunks into your training loopforchunkinextractor.extract_chunks("massive.pcap"):
train_step(chunk)

Parallel batch

frompcap2tensorimportbatch_extractbatch_extract("./pcaps/", output_dir="./tensors/", features="aegis-6d", workers=8)

From the CLI:

pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8

Feature presets

PresetDimFeatures
basic-3d3size, IAT, direction
aegis-6d6size, IAT, direction, TCP window, TCP flags, payload ratio
extended-10d10aegis-6d + protocol one-hot (TCP/UDP/ICMP/other)
full-13d13extended-10d + destination port category (well-known/registered/dynamic)

The aegis-6d preset matches the feature set in AEGIS (Ferrel, 2026) — a TVD-HL-SSM architecture achieving F1 0.9952 on encrypted traffic detection at 262 μs inference latency.

Custom features

A Feature is any stateful callable returning a float or a flat list of floats. Subclass Feature, implement __call__, optionally override reset if you hold state:

importmathfromcollectionsimportCounterfromscapy.layers.inetimportTCPfrompcap2tensorimportPCAPExtractor, Feature, Size, IAT, DirectionclassPayloadEntropy(Feature):
name="payload_entropy"dim=1def__call__(self, pkt):
payload=bytes(pkt[TCP].payload) ifTCPinpktelseb""ifnotpayload:
return0.0counts=Counter(payload)
n=len(payload)
return-sum((c/n) *math.log2(c/n) forcincounts.values()) /8.0extractor=PCAPExtractor(
features=[Size(), IAT(), Direction(), PayloadEntropy()],
)
tensor=extractor.extract("capture.pcap")

Return a list[float] and set dim accordingly for multi-valued features (e.g. one-hots).

CLI

# Single PCAP
pcap2tensor extract capture.pcap -o ./tensors/
# Parallel batch over a directory
pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8
# List presets
pcap2tensor presets
# Override everything
pcap2tensor extract capture.pcap -f extended-10d -w 2000 -s 1000 -c 5000000

Design

ConcernHow it's handled
MemoryStreaming PcapReader, chunked flush every chunk_size packets
Malformed packetsCaught per-packet, silently skipped — a 4-hour run doesn't die on one pkt
Flow statePer-Feature instance, auto-reset between PCAPs
ParallelismProcessPoolExecutor for batch mode
IPv6First-class (IPv6 src/dst, port extraction, protocol number)
ReproducibilitySame PCAP + same config = bit-identical tensor output
Output formatPyTorch .pt on disk, torch.Tensor in memory

Performance

Rough single-core throughput with aegis-6d on a modern x86 machine: roughly 50–120k packets/sec, TCP-heavy captures slower than UDP-heavy. With 8 workers in batch mode, processing 100 GB+ of PCAPs per hour is achievable.

Your bottleneck is Scapy parsing, not feature extraction.

Output shape

Every extractor produces tensors of shape:

(num_windows, window_size, feature_dim)

where feature_dim = sum(f.dim for f in features). For aegis-6d, that's 6.

Citation

If you use this library in research, please cite the companion paper:

@article{ferrel2026aegis,
title = {AEGIS: Adversarial Entropy-Guided Immune System -- Thermodynamic State Space Models for Zero-Day Network Evasion Detection},
author = {Ferrel, Vickson},
journal = {arXiv preprint arXiv:2604.02149},
year = {2026},
url = {https://arxiv.org/abs/2604.02149}
}

License

MIT © Vickson Ferrel — Vixero Technology Enterprise


Built in Sarawak. For network defenders everywhere. 🛡️

About

PCAP → ML tensor extraction for network intrusion detection research.

Topics

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

pcap2tensor

Vixero Tech

PCAP → ML tensor extraction for network intrusion detection research.

A fast, streaming, production-grade Python library for turning raw packet captures into training-ready tensors. Built for NIDS researchers tired of rolling their own extraction pipeline for every paper.

PyPIPythonLicense: MITarXivCI

Why this exists

Every ML-based network intrusion detection paper reinvents the same pipeline:

  1. Parse a PCAP
  2. Extract per-packet features (size, inter-arrival time, direction, TCP flags, ...)
  3. Slide a window across the sequence
  4. Save as a tensor

Every implementation is a one-file script that doesn't handle PCAPs larger than RAM, doesn't expose clean extension points for custom features, and quietly crashes on the first malformed packet. pcap2tensor is that pipeline, packaged properly — streaming, extensible, and published on PyPI.

Install

pip install pcap2tensor

Python ≥ 3.9. Depends on Scapy, PyTorch, NumPy, tqdm.

Quickstart

frompcap2tensorimportextracttensor=extract("capture.pcap", features="aegis-6d", window_size=1000, stride=500)
print(tensor.shape) # torch.Size([num_windows, 1000, 6])

Feed straight into any sequence model — Transformer, LSTM, SSM, CNN.

Large PCAPs

Streaming chunked processing — never loads the full PCAP into memory:

frompcap2tensorimportPCAPExtractorextractor=PCAPExtractor(
features="aegis-6d",
window_size=1000,
stride=500,
chunk_size=2_000_000, # flush every 2M packets
)
# Option A: save chunked .pt filesextractor.save("massive.pcap", output_dir="./tensors/")
# Option B: stream chunks into your training loopforchunkinextractor.extract_chunks("massive.pcap"):
train_step(chunk)

Parallel batch

frompcap2tensorimportbatch_extractbatch_extract("./pcaps/", output_dir="./tensors/", features="aegis-6d", workers=8)

From the CLI:

pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8

Feature presets

PresetDimFeatures
basic-3d3size, IAT, direction
aegis-6d6size, IAT, direction, TCP window, TCP flags, payload ratio
extended-10d10aegis-6d + protocol one-hot (TCP/UDP/ICMP/other)
full-13d13extended-10d + destination port category (well-known/registered/dynamic)

The aegis-6d preset matches the feature set in AEGIS (Ferrel, 2026) — a TVD-HL-SSM architecture achieving F1 0.9952 on encrypted traffic detection at 262 μs inference latency.

Custom features

A Feature is any stateful callable returning a float or a flat list of floats. Subclass Feature, implement __call__, optionally override reset if you hold state:

importmathfromcollectionsimportCounterfromscapy.layers.inetimportTCPfrompcap2tensorimportPCAPExtractor, Feature, Size, IAT, DirectionclassPayloadEntropy(Feature):
name="payload_entropy"dim=1def__call__(self, pkt):
payload=bytes(pkt[TCP].payload) ifTCPinpktelseb""ifnotpayload:
return0.0counts=Counter(payload)
n=len(payload)
return-sum((c/n) *math.log2(c/n) forcincounts.values()) /8.0extractor=PCAPExtractor(
features=[Size(), IAT(), Direction(), PayloadEntropy()],
)
tensor=extractor.extract("capture.pcap")

Return a list[float] and set dim accordingly for multi-valued features (e.g. one-hots).

CLI

# Single PCAP
pcap2tensor extract capture.pcap -o ./tensors/
# Parallel batch over a directory
pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8
# List presets
pcap2tensor presets
# Override everything
pcap2tensor extract capture.pcap -f extended-10d -w 2000 -s 1000 -c 5000000

Design

ConcernHow it's handled
MemoryStreaming PcapReader, chunked flush every chunk_size packets
Malformed packetsCaught per-packet, silently skipped — a 4-hour run doesn't die on one pkt
Flow statePer-Feature instance, auto-reset between PCAPs
ParallelismProcessPoolExecutor for batch mode
IPv6First-class (IPv6 src/dst, port extraction, protocol number)
ReproducibilitySame PCAP + same config = bit-identical tensor output
Output formatPyTorch .pt on disk, torch.Tensor in memory

Performance

Rough single-core throughput with aegis-6d on a modern x86 machine: roughly 50–120k packets/sec, TCP-heavy captures slower than UDP-heavy. With 8 workers in batch mode, processing 100 GB+ of PCAPs per hour is achievable.

Your bottleneck is Scapy parsing, not feature extraction.

Output shape

Every extractor produces tensors of shape:

(num_windows, window_size, feature_dim)

where feature_dim = sum(f.dim for f in features). For aegis-6d, that's 6.

Citation

If you use this library in research, please cite the companion paper:

@article{ferrel2026aegis,
title = {AEGIS: Adversarial Entropy-Guided Immune System -- Thermodynamic State Space Models for Zero-Day Network Evasion Detection},
author = {Ferrel, Vickson},
journal = {arXiv preprint arXiv:2604.02149},
year = {2026},
url = {https://arxiv.org/abs/2604.02149}
}

License

MIT © Vickson Ferrel — Vixero Technology Enterprise


Built in Sarawak. For network defenders everywhere. 🛡️

About

PCAP → ML tensor extraction for network intrusion detection research.

Topics

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

pcap2tensor

Vixero Tech

PCAP → ML tensor extraction for network intrusion detection research.

A fast, streaming, production-grade Python library for turning raw packet captures into training-ready tensors. Built for NIDS researchers tired of rolling their own extraction pipeline for every paper.

PyPIPythonLicense: MITarXivCI

Why this exists

Every ML-based network intrusion detection paper reinvents the same pipeline:

  1. Parse a PCAP
  2. Extract per-packet features (size, inter-arrival time, direction, TCP flags, ...)
  3. Slide a window across the sequence
  4. Save as a tensor

Every implementation is a one-file script that doesn't handle PCAPs larger than RAM, doesn't expose clean extension points for custom features, and quietly crashes on the first malformed packet. pcap2tensor is that pipeline, packaged properly — streaming, extensible, and published on PyPI.

Install

pip install pcap2tensor

Python ≥ 3.9. Depends on Scapy, PyTorch, NumPy, tqdm.

Quickstart

frompcap2tensorimportextracttensor=extract("capture.pcap", features="aegis-6d", window_size=1000, stride=500)
print(tensor.shape) # torch.Size([num_windows, 1000, 6])

Feed straight into any sequence model — Transformer, LSTM, SSM, CNN.

Large PCAPs

Streaming chunked processing — never loads the full PCAP into memory:

frompcap2tensorimportPCAPExtractorextractor=PCAPExtractor(
features="aegis-6d",
window_size=1000,
stride=500,
chunk_size=2_000_000, # flush every 2M packets
)
# Option A: save chunked .pt filesextractor.save("massive.pcap", output_dir="./tensors/")
# Option B: stream chunks into your training loopforchunkinextractor.extract_chunks("massive.pcap"):
train_step(chunk)

Parallel batch

frompcap2tensorimportbatch_extractbatch_extract("./pcaps/", output_dir="./tensors/", features="aegis-6d", workers=8)

From the CLI:

pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8

Feature presets

PresetDimFeatures
basic-3d3size, IAT, direction
aegis-6d6size, IAT, direction, TCP window, TCP flags, payload ratio
extended-10d10aegis-6d + protocol one-hot (TCP/UDP/ICMP/other)
full-13d13extended-10d + destination port category (well-known/registered/dynamic)

The aegis-6d preset matches the feature set in AEGIS (Ferrel, 2026) — a TVD-HL-SSM architecture achieving F1 0.9952 on encrypted traffic detection at 262 μs inference latency.

Custom features

A Feature is any stateful callable returning a float or a flat list of floats. Subclass Feature, implement __call__, optionally override reset if you hold state:

importmathfromcollectionsimportCounterfromscapy.layers.inetimportTCPfrompcap2tensorimportPCAPExtractor, Feature, Size, IAT, DirectionclassPayloadEntropy(Feature):
name="payload_entropy"dim=1def__call__(self, pkt):
payload=bytes(pkt[TCP].payload) ifTCPinpktelseb""ifnotpayload:
return0.0counts=Counter(payload)
n=len(payload)
return-sum((c/n) *math.log2(c/n) forcincounts.values()) /8.0extractor=PCAPExtractor(
features=[Size(), IAT(), Direction(), PayloadEntropy()],
)
tensor=extractor.extract("capture.pcap")

Return a list[float] and set dim accordingly for multi-valued features (e.g. one-hots).

CLI

# Single PCAP
pcap2tensor extract capture.pcap -o ./tensors/
# Parallel batch over a directory
pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8
# List presets
pcap2tensor presets
# Override everything
pcap2tensor extract capture.pcap -f extended-10d -w 2000 -s 1000 -c 5000000

Design

ConcernHow it's handled
MemoryStreaming PcapReader, chunked flush every chunk_size packets
Malformed packetsCaught per-packet, silently skipped — a 4-hour run doesn't die on one pkt
Flow statePer-Feature instance, auto-reset between PCAPs
ParallelismProcessPoolExecutor for batch mode
IPv6First-class (IPv6 src/dst, port extraction, protocol number)
ReproducibilitySame PCAP + same config = bit-identical tensor output
Output formatPyTorch .pt on disk, torch.Tensor in memory

Performance

Rough single-core throughput with aegis-6d on a modern x86 machine: roughly 50–120k packets/sec, TCP-heavy captures slower than UDP-heavy. With 8 workers in batch mode, processing 100 GB+ of PCAPs per hour is achievable.

Your bottleneck is Scapy parsing, not feature extraction.

Output shape

Every extractor produces tensors of shape:

(num_windows, window_size, feature_dim)

where feature_dim = sum(f.dim for f in features). For aegis-6d, that's 6.

Citation

If you use this library in research, please cite the companion paper:

@article{ferrel2026aegis,
title = {AEGIS: Adversarial Entropy-Guided Immune System -- Thermodynamic State Space Models for Zero-Day Network Evasion Detection},
author = {Ferrel, Vickson},
journal = {arXiv preprint arXiv:2604.02149},
year = {2026},
url = {https://arxiv.org/abs/2604.02149}
}

License

MIT © Vickson Ferrel — Vixero Technology Enterprise


Built in Sarawak. For network defenders everywhere. 🛡️

About

PCAP → ML tensor extraction for network intrusion detection research.

Topics

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

pcap2tensor

Vixero Tech

PCAP → ML tensor extraction for network intrusion detection research.

A fast, streaming, production-grade Python library for turning raw packet captures into training-ready tensors. Built for NIDS researchers tired of rolling their own extraction pipeline for every paper.

PyPIPythonLicense: MITarXivCI

Why this exists

Every ML-based network intrusion detection paper reinvents the same pipeline:

  1. Parse a PCAP
  2. Extract per-packet features (size, inter-arrival time, direction, TCP flags, ...)
  3. Slide a window across the sequence
  4. Save as a tensor

Every implementation is a one-file script that doesn't handle PCAPs larger than RAM, doesn't expose clean extension points for custom features, and quietly crashes on the first malformed packet. pcap2tensor is that pipeline, packaged properly — streaming, extensible, and published on PyPI.

Install

pip install pcap2tensor

Python ≥ 3.9. Depends on Scapy, PyTorch, NumPy, tqdm.

Quickstart

frompcap2tensorimportextracttensor=extract("capture.pcap", features="aegis-6d", window_size=1000, stride=500)
print(tensor.shape) # torch.Size([num_windows, 1000, 6])

Feed straight into any sequence model — Transformer, LSTM, SSM, CNN.

Large PCAPs

Streaming chunked processing — never loads the full PCAP into memory:

frompcap2tensorimportPCAPExtractorextractor=PCAPExtractor(
features="aegis-6d",
window_size=1000,
stride=500,
chunk_size=2_000_000, # flush every 2M packets
)
# Option A: save chunked .pt filesextractor.save("massive.pcap", output_dir="./tensors/")
# Option B: stream chunks into your training loopforchunkinextractor.extract_chunks("massive.pcap"):
train_step(chunk)

Parallel batch

frompcap2tensorimportbatch_extractbatch_extract("./pcaps/", output_dir="./tensors/", features="aegis-6d", workers=8)

From the CLI:

pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8

Feature presets

PresetDimFeatures
basic-3d3size, IAT, direction
aegis-6d6size, IAT, direction, TCP window, TCP flags, payload ratio
extended-10d10aegis-6d + protocol one-hot (TCP/UDP/ICMP/other)
full-13d13extended-10d + destination port category (well-known/registered/dynamic)

The aegis-6d preset matches the feature set in AEGIS (Ferrel, 2026) — a TVD-HL-SSM architecture achieving F1 0.9952 on encrypted traffic detection at 262 μs inference latency.

Custom features

A Feature is any stateful callable returning a float or a flat list of floats. Subclass Feature, implement __call__, optionally override reset if you hold state:

importmathfromcollectionsimportCounterfromscapy.layers.inetimportTCPfrompcap2tensorimportPCAPExtractor, Feature, Size, IAT, DirectionclassPayloadEntropy(Feature):
name="payload_entropy"dim=1def__call__(self, pkt):
payload=bytes(pkt[TCP].payload) ifTCPinpktelseb""ifnotpayload:
return0.0counts=Counter(payload)
n=len(payload)
return-sum((c/n) *math.log2(c/n) forcincounts.values()) /8.0extractor=PCAPExtractor(
features=[Size(), IAT(), Direction(), PayloadEntropy()],
)
tensor=extractor.extract("capture.pcap")

Return a list[float] and set dim accordingly for multi-valued features (e.g. one-hots).

CLI

# Single PCAP
pcap2tensor extract capture.pcap -o ./tensors/
# Parallel batch over a directory
pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8
# List presets
pcap2tensor presets
# Override everything
pcap2tensor extract capture.pcap -f extended-10d -w 2000 -s 1000 -c 5000000

Design

ConcernHow it's handled
MemoryStreaming PcapReader, chunked flush every chunk_size packets
Malformed packetsCaught per-packet, silently skipped — a 4-hour run doesn't die on one pkt
Flow statePer-Feature instance, auto-reset between PCAPs
ParallelismProcessPoolExecutor for batch mode
IPv6First-class (IPv6 src/dst, port extraction, protocol number)
ReproducibilitySame PCAP + same config = bit-identical tensor output
Output formatPyTorch .pt on disk, torch.Tensor in memory

Performance

Rough single-core throughput with aegis-6d on a modern x86 machine: roughly 50–120k packets/sec, TCP-heavy captures slower than UDP-heavy. With 8 workers in batch mode, processing 100 GB+ of PCAPs per hour is achievable.

Your bottleneck is Scapy parsing, not feature extraction.

Output shape

Every extractor produces tensors of shape:

(num_windows, window_size, feature_dim)

where feature_dim = sum(f.dim for f in features). For aegis-6d, that's 6.

Citation

If you use this library in research, please cite the companion paper:

@article{ferrel2026aegis,
title = {AEGIS: Adversarial Entropy-Guided Immune System -- Thermodynamic State Space Models for Zero-Day Network Evasion Detection},
author = {Ferrel, Vickson},
journal = {arXiv preprint arXiv:2604.02149},
year = {2026},
url = {https://arxiv.org/abs/2604.02149}
}

License

MIT © Vickson Ferrel — Vixero Technology Enterprise


Built in Sarawak. For network defenders everywhere. 🛡️

About

PCAP → ML tensor extraction for network intrusion detection research.

Topics

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

pcap2tensor

Vixero Tech

PCAP → ML tensor extraction for network intrusion detection research.

A fast, streaming, production-grade Python library for turning raw packet captures into training-ready tensors. Built for NIDS researchers tired of rolling their own extraction pipeline for every paper.

PyPIPythonLicense: MITarXivCI

Why this exists

Every ML-based network intrusion detection paper reinvents the same pipeline:

  1. Parse a PCAP
  2. Extract per-packet features (size, inter-arrival time, direction, TCP flags, ...)
  3. Slide a window across the sequence
  4. Save as a tensor

Every implementation is a one-file script that doesn't handle PCAPs larger than RAM, doesn't expose clean extension points for custom features, and quietly crashes on the first malformed packet. pcap2tensor is that pipeline, packaged properly — streaming, extensible, and published on PyPI.

Install

pip install pcap2tensor

Python ≥ 3.9. Depends on Scapy, PyTorch, NumPy, tqdm.

Quickstart

frompcap2tensorimportextracttensor=extract("capture.pcap", features="aegis-6d", window_size=1000, stride=500)
print(tensor.shape) # torch.Size([num_windows, 1000, 6])

Feed straight into any sequence model — Transformer, LSTM, SSM, CNN.

Large PCAPs

Streaming chunked processing — never loads the full PCAP into memory:

frompcap2tensorimportPCAPExtractorextractor=PCAPExtractor(
features="aegis-6d",
window_size=1000,
stride=500,
chunk_size=2_000_000, # flush every 2M packets
)
# Option A: save chunked .pt filesextractor.save("massive.pcap", output_dir="./tensors/")
# Option B: stream chunks into your training loopforchunkinextractor.extract_chunks("massive.pcap"):
train_step(chunk)

Parallel batch

frompcap2tensorimportbatch_extractbatch_extract("./pcaps/", output_dir="./tensors/", features="aegis-6d", workers=8)

From the CLI:

pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8

Feature presets

PresetDimFeatures
basic-3d3size, IAT, direction
aegis-6d6size, IAT, direction, TCP window, TCP flags, payload ratio
extended-10d10aegis-6d + protocol one-hot (TCP/UDP/ICMP/other)
full-13d13extended-10d + destination port category (well-known/registered/dynamic)

The aegis-6d preset matches the feature set in AEGIS (Ferrel, 2026) — a TVD-HL-SSM architecture achieving F1 0.9952 on encrypted traffic detection at 262 μs inference latency.

Custom features

A Feature is any stateful callable returning a float or a flat list of floats. Subclass Feature, implement __call__, optionally override reset if you hold state:

importmathfromcollectionsimportCounterfromscapy.layers.inetimportTCPfrompcap2tensorimportPCAPExtractor, Feature, Size, IAT, DirectionclassPayloadEntropy(Feature):
name="payload_entropy"dim=1def__call__(self, pkt):
payload=bytes(pkt[TCP].payload) ifTCPinpktelseb""ifnotpayload:
return0.0counts=Counter(payload)
n=len(payload)
return-sum((c/n) *math.log2(c/n) forcincounts.values()) /8.0extractor=PCAPExtractor(
features=[Size(), IAT(), Direction(), PayloadEntropy()],
)
tensor=extractor.extract("capture.pcap")

Return a list[float] and set dim accordingly for multi-valued features (e.g. one-hots).

CLI

# Single PCAP
pcap2tensor extract capture.pcap -o ./tensors/
# Parallel batch over a directory
pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8
# List presets
pcap2tensor presets
# Override everything
pcap2tensor extract capture.pcap -f extended-10d -w 2000 -s 1000 -c 5000000

Design

ConcernHow it's handled
MemoryStreaming PcapReader, chunked flush every chunk_size packets
Malformed packetsCaught per-packet, silently skipped — a 4-hour run doesn't die on one pkt
Flow statePer-Feature instance, auto-reset between PCAPs
ParallelismProcessPoolExecutor for batch mode
IPv6First-class (IPv6 src/dst, port extraction, protocol number)
ReproducibilitySame PCAP + same config = bit-identical tensor output
Output formatPyTorch .pt on disk, torch.Tensor in memory

Performance

Rough single-core throughput with aegis-6d on a modern x86 machine: roughly 50–120k packets/sec, TCP-heavy captures slower than UDP-heavy. With 8 workers in batch mode, processing 100 GB+ of PCAPs per hour is achievable.

Your bottleneck is Scapy parsing, not feature extraction.

Output shape

Every extractor produces tensors of shape:

(num_windows, window_size, feature_dim)

where feature_dim = sum(f.dim for f in features). For aegis-6d, that's 6.

Citation

If you use this library in research, please cite the companion paper:

@article{ferrel2026aegis,
title = {AEGIS: Adversarial Entropy-Guided Immune System -- Thermodynamic State Space Models for Zero-Day Network Evasion Detection},
author = {Ferrel, Vickson},
journal = {arXiv preprint arXiv:2604.02149},
year = {2026},
url = {https://arxiv.org/abs/2604.02149}
}

License

MIT © Vickson Ferrel — Vixero Technology Enterprise


Built in Sarawak. For network defenders everywhere. 🛡️

About

PCAP → ML tensor extraction for network intrusion detection research.

Topics

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

pcap2tensor

Vixero Tech

PCAP → ML tensor extraction for network intrusion detection research.

A fast, streaming, production-grade Python library for turning raw packet captures into training-ready tensors. Built for NIDS researchers tired of rolling their own extraction pipeline for every paper.

PyPIPythonLicense: MITarXivCI

Why this exists

Every ML-based network intrusion detection paper reinvents the same pipeline:

  1. Parse a PCAP
  2. Extract per-packet features (size, inter-arrival time, direction, TCP flags, ...)
  3. Slide a window across the sequence
  4. Save as a tensor

Every implementation is a one-file script that doesn't handle PCAPs larger than RAM, doesn't expose clean extension points for custom features, and quietly crashes on the first malformed packet. pcap2tensor is that pipeline, packaged properly — streaming, extensible, and published on PyPI.

Install

pip install pcap2tensor

Python ≥ 3.9. Depends on Scapy, PyTorch, NumPy, tqdm.

Quickstart

frompcap2tensorimportextracttensor=extract("capture.pcap", features="aegis-6d", window_size=1000, stride=500)
print(tensor.shape) # torch.Size([num_windows, 1000, 6])

Feed straight into any sequence model — Transformer, LSTM, SSM, CNN.

Large PCAPs

Streaming chunked processing — never loads the full PCAP into memory:

frompcap2tensorimportPCAPExtractorextractor=PCAPExtractor(
features="aegis-6d",
window_size=1000,
stride=500,
chunk_size=2_000_000, # flush every 2M packets
)
# Option A: save chunked .pt filesextractor.save("massive.pcap", output_dir="./tensors/")
# Option B: stream chunks into your training loopforchunkinextractor.extract_chunks("massive.pcap"):
train_step(chunk)

Parallel batch

frompcap2tensorimportbatch_extractbatch_extract("./pcaps/", output_dir="./tensors/", features="aegis-6d", workers=8)

From the CLI:

pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8

Feature presets

PresetDimFeatures
basic-3d3size, IAT, direction
aegis-6d6size, IAT, direction, TCP window, TCP flags, payload ratio
extended-10d10aegis-6d + protocol one-hot (TCP/UDP/ICMP/other)
full-13d13extended-10d + destination port category (well-known/registered/dynamic)

The aegis-6d preset matches the feature set in AEGIS (Ferrel, 2026) — a TVD-HL-SSM architecture achieving F1 0.9952 on encrypted traffic detection at 262 μs inference latency.

Custom features

A Feature is any stateful callable returning a float or a flat list of floats. Subclass Feature, implement __call__, optionally override reset if you hold state:

importmathfromcollectionsimportCounterfromscapy.layers.inetimportTCPfrompcap2tensorimportPCAPExtractor, Feature, Size, IAT, DirectionclassPayloadEntropy(Feature):
name="payload_entropy"dim=1def__call__(self, pkt):
payload=bytes(pkt[TCP].payload) ifTCPinpktelseb""ifnotpayload:
return0.0counts=Counter(payload)
n=len(payload)
return-sum((c/n) *math.log2(c/n) forcincounts.values()) /8.0extractor=PCAPExtractor(
features=[Size(), IAT(), Direction(), PayloadEntropy()],
)
tensor=extractor.extract("capture.pcap")

Return a list[float] and set dim accordingly for multi-valued features (e.g. one-hots).

CLI

# Single PCAP
pcap2tensor extract capture.pcap -o ./tensors/
# Parallel batch over a directory
pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8
# List presets
pcap2tensor presets
# Override everything
pcap2tensor extract capture.pcap -f extended-10d -w 2000 -s 1000 -c 5000000

Design

ConcernHow it's handled
MemoryStreaming PcapReader, chunked flush every chunk_size packets
Malformed packetsCaught per-packet, silently skipped — a 4-hour run doesn't die on one pkt
Flow statePer-Feature instance, auto-reset between PCAPs
ParallelismProcessPoolExecutor for batch mode
IPv6First-class (IPv6 src/dst, port extraction, protocol number)
ReproducibilitySame PCAP + same config = bit-identical tensor output
Output formatPyTorch .pt on disk, torch.Tensor in memory

Performance

Rough single-core throughput with aegis-6d on a modern x86 machine: roughly 50–120k packets/sec, TCP-heavy captures slower than UDP-heavy. With 8 workers in batch mode, processing 100 GB+ of PCAPs per hour is achievable.

Your bottleneck is Scapy parsing, not feature extraction.

Output shape

Every extractor produces tensors of shape:

(num_windows, window_size, feature_dim)

where feature_dim = sum(f.dim for f in features). For aegis-6d, that's 6.

Citation

If you use this library in research, please cite the companion paper:

@article{ferrel2026aegis,
title = {AEGIS: Adversarial Entropy-Guided Immune System -- Thermodynamic State Space Models for Zero-Day Network Evasion Detection},
author = {Ferrel, Vickson},
journal = {arXiv preprint arXiv:2604.02149},
year = {2026},
url = {https://arxiv.org/abs/2604.02149}
}

License

MIT © Vickson Ferrel — Vixero Technology Enterprise


Built in Sarawak. For network defenders everywhere. 🛡️

About

PCAP → ML tensor extraction for network intrusion detection research.

Topics

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

pcap2tensor

Vixero Tech

PCAP → ML tensor extraction for network intrusion detection research.

A fast, streaming, production-grade Python library for turning raw packet captures into training-ready tensors. Built for NIDS researchers tired of rolling their own extraction pipeline for every paper.

PyPIPythonLicense: MITarXivCI

Why this exists

Every ML-based network intrusion detection paper reinvents the same pipeline:

  1. Parse a PCAP
  2. Extract per-packet features (size, inter-arrival time, direction, TCP flags, ...)
  3. Slide a window across the sequence
  4. Save as a tensor

Every implementation is a one-file script that doesn't handle PCAPs larger than RAM, doesn't expose clean extension points for custom features, and quietly crashes on the first malformed packet. pcap2tensor is that pipeline, packaged properly — streaming, extensible, and published on PyPI.

Install

pip install pcap2tensor

Python ≥ 3.9. Depends on Scapy, PyTorch, NumPy, tqdm.

Quickstart

frompcap2tensorimportextracttensor=extract("capture.pcap", features="aegis-6d", window_size=1000, stride=500)
print(tensor.shape) # torch.Size([num_windows, 1000, 6])

Feed straight into any sequence model — Transformer, LSTM, SSM, CNN.

Large PCAPs

Streaming chunked processing — never loads the full PCAP into memory:

frompcap2tensorimportPCAPExtractorextractor=PCAPExtractor(
features="aegis-6d",
window_size=1000,
stride=500,
chunk_size=2_000_000, # flush every 2M packets
)
# Option A: save chunked .pt filesextractor.save("massive.pcap", output_dir="./tensors/")
# Option B: stream chunks into your training loopforchunkinextractor.extract_chunks("massive.pcap"):
train_step(chunk)

Parallel batch

frompcap2tensorimportbatch_extractbatch_extract("./pcaps/", output_dir="./tensors/", features="aegis-6d", workers=8)

From the CLI:

pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8

Feature presets

PresetDimFeatures
basic-3d3size, IAT, direction
aegis-6d6size, IAT, direction, TCP window, TCP flags, payload ratio
extended-10d10aegis-6d + protocol one-hot (TCP/UDP/ICMP/other)
full-13d13extended-10d + destination port category (well-known/registered/dynamic)

The aegis-6d preset matches the feature set in AEGIS (Ferrel, 2026) — a TVD-HL-SSM architecture achieving F1 0.9952 on encrypted traffic detection at 262 μs inference latency.

Custom features

A Feature is any stateful callable returning a float or a flat list of floats. Subclass Feature, implement __call__, optionally override reset if you hold state:

importmathfromcollectionsimportCounterfromscapy.layers.inetimportTCPfrompcap2tensorimportPCAPExtractor, Feature, Size, IAT, DirectionclassPayloadEntropy(Feature):
name="payload_entropy"dim=1def__call__(self, pkt):
payload=bytes(pkt[TCP].payload) ifTCPinpktelseb""ifnotpayload:
return0.0counts=Counter(payload)
n=len(payload)
return-sum((c/n) *math.log2(c/n) forcincounts.values()) /8.0extractor=PCAPExtractor(
features=[Size(), IAT(), Direction(), PayloadEntropy()],
)
tensor=extractor.extract("capture.pcap")

Return a list[float] and set dim accordingly for multi-valued features (e.g. one-hots).

CLI

# Single PCAP
pcap2tensor extract capture.pcap -o ./tensors/
# Parallel batch over a directory
pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8
# List presets
pcap2tensor presets
# Override everything
pcap2tensor extract capture.pcap -f extended-10d -w 2000 -s 1000 -c 5000000

Design

ConcernHow it's handled
MemoryStreaming PcapReader, chunked flush every chunk_size packets
Malformed packetsCaught per-packet, silently skipped — a 4-hour run doesn't die on one pkt
Flow statePer-Feature instance, auto-reset between PCAPs
ParallelismProcessPoolExecutor for batch mode
IPv6First-class (IPv6 src/dst, port extraction, protocol number)
ReproducibilitySame PCAP + same config = bit-identical tensor output
Output formatPyTorch .pt on disk, torch.Tensor in memory

Performance

Rough single-core throughput with aegis-6d on a modern x86 machine: roughly 50–120k packets/sec, TCP-heavy captures slower than UDP-heavy. With 8 workers in batch mode, processing 100 GB+ of PCAPs per hour is achievable.

Your bottleneck is Scapy parsing, not feature extraction.

Output shape

Every extractor produces tensors of shape:

(num_windows, window_size, feature_dim)

where feature_dim = sum(f.dim for f in features). For aegis-6d, that's 6.

Citation

If you use this library in research, please cite the companion paper:

@article{ferrel2026aegis,
title = {AEGIS: Adversarial Entropy-Guided Immune System -- Thermodynamic State Space Models for Zero-Day Network Evasion Detection},
author = {Ferrel, Vickson},
journal = {arXiv preprint arXiv:2604.02149},
year = {2026},
url = {https://arxiv.org/abs/2604.02149}
}

License

MIT © Vickson Ferrel — Vixero Technology Enterprise


Built in Sarawak. For network defenders everywhere. 🛡️

About

PCAP → ML tensor extraction for network intrusion detection research.

Topics

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

pcap2tensor

Vixero Tech

PCAP → ML tensor extraction for network intrusion detection research.

A fast, streaming, production-grade Python library for turning raw packet captures into training-ready tensors. Built for NIDS researchers tired of rolling their own extraction pipeline for every paper.

PyPIPythonLicense: MITarXivCI

Why this exists

Every ML-based network intrusion detection paper reinvents the same pipeline:

  1. Parse a PCAP
  2. Extract per-packet features (size, inter-arrival time, direction, TCP flags, ...)
  3. Slide a window across the sequence
  4. Save as a tensor

Every implementation is a one-file script that doesn't handle PCAPs larger than RAM, doesn't expose clean extension points for custom features, and quietly crashes on the first malformed packet. pcap2tensor is that pipeline, packaged properly — streaming, extensible, and published on PyPI.

Install

pip install pcap2tensor

Python ≥ 3.9. Depends on Scapy, PyTorch, NumPy, tqdm.

Quickstart

frompcap2tensorimportextracttensor=extract("capture.pcap", features="aegis-6d", window_size=1000, stride=500)
print(tensor.shape) # torch.Size([num_windows, 1000, 6])

Feed straight into any sequence model — Transformer, LSTM, SSM, CNN.

Large PCAPs

Streaming chunked processing — never loads the full PCAP into memory:

frompcap2tensorimportPCAPExtractorextractor=PCAPExtractor(
features="aegis-6d",
window_size=1000,
stride=500,
chunk_size=2_000_000, # flush every 2M packets
)
# Option A: save chunked .pt filesextractor.save("massive.pcap", output_dir="./tensors/")
# Option B: stream chunks into your training loopforchunkinextractor.extract_chunks("massive.pcap"):
train_step(chunk)

Parallel batch

frompcap2tensorimportbatch_extractbatch_extract("./pcaps/", output_dir="./tensors/", features="aegis-6d", workers=8)

From the CLI:

pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8

Feature presets

PresetDimFeatures
basic-3d3size, IAT, direction
aegis-6d6size, IAT, direction, TCP window, TCP flags, payload ratio
extended-10d10aegis-6d + protocol one-hot (TCP/UDP/ICMP/other)
full-13d13extended-10d + destination port category (well-known/registered/dynamic)

The aegis-6d preset matches the feature set in AEGIS (Ferrel, 2026) — a TVD-HL-SSM architecture achieving F1 0.9952 on encrypted traffic detection at 262 μs inference latency.

Custom features

A Feature is any stateful callable returning a float or a flat list of floats. Subclass Feature, implement __call__, optionally override reset if you hold state:

importmathfromcollectionsimportCounterfromscapy.layers.inetimportTCPfrompcap2tensorimportPCAPExtractor, Feature, Size, IAT, DirectionclassPayloadEntropy(Feature):
name="payload_entropy"dim=1def__call__(self, pkt):
payload=bytes(pkt[TCP].payload) ifTCPinpktelseb""ifnotpayload:
return0.0counts=Counter(payload)
n=len(payload)
return-sum((c/n) *math.log2(c/n) forcincounts.values()) /8.0extractor=PCAPExtractor(
features=[Size(), IAT(), Direction(), PayloadEntropy()],
)
tensor=extractor.extract("capture.pcap")

Return a list[float] and set dim accordingly for multi-valued features (e.g. one-hots).

CLI

# Single PCAP
pcap2tensor extract capture.pcap -o ./tensors/
# Parallel batch over a directory
pcap2tensor batch ./pcaps/ -o ./tensors/ -n 8
# List presets
pcap2tensor presets
# Override everything
pcap2tensor extract capture.pcap -f extended-10d -w 2000 -s 1000 -c 5000000

Design

ConcernHow it's handled
MemoryStreaming PcapReader, chunked flush every chunk_size packets
Malformed packetsCaught per-packet, silently skipped — a 4-hour run doesn't die on one pkt
Flow statePer-Feature instance, auto-reset between PCAPs
ParallelismProcessPoolExecutor for batch mode
IPv6First-class (IPv6 src/dst, port extraction, protocol number)
ReproducibilitySame PCAP + same config = bit-identical tensor output
Output formatPyTorch .pt on disk, torch.Tensor in memory

Performance

Rough single-core throughput with aegis-6d on a modern x86 machine: roughly 50–120k packets/sec, TCP-heavy captures slower than UDP-heavy. With 8 workers in batch mode, processing 100 GB+ of PCAPs per hour is achievable.

Your bottleneck is Scapy parsing, not feature extraction.

Output shape

Every extractor produces tensors of shape:

(num_windows, window_size, feature_dim)

where feature_dim = sum(f.dim for f in features). For aegis-6d, that's 6.

Citation

If you use this library in research, please cite the companion paper:

@article{ferrel2026aegis,
title = {AEGIS: Adversarial Entropy-Guided Immune System -- Thermodynamic State Space Models for Zero-Day Network Evasion Detection},
author = {Ferrel, Vickson},
journal = {arXiv preprint arXiv:2604.02149},
year = {2026},
url = {https://arxiv.org/abs/2604.02149}
}

License

MIT © Vickson Ferrel — Vixero Technology Enterprise


Built in Sarawak. For network defenders everywhere. 🛡️

About

PCAP → ML tensor extraction for network intrusion detection research.

Topics

Resources

Contributing

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages