Skip to main content

Network Mode - Live Packet Capture

Applies to:
Live Interface CaptureTLS Handshake ParsingSSH KEX DetectionPQ Key Exchange DetectionFeature-gated (pcap-live)
Feature-gated, and distinct from Packet Capture

The network command performs live capture from a network interface and requires the scanner to be built with the pcap-live feature (plus the system capture library — libpcap/Npcap). It is a different command from Packet Capture, which analyzes an already-captured .pcap/.pcapng file offline and only requires the pcap feature.

Overview​

Network mode captures traffic live from a network interface, reconstructs network flows, and parses cryptographic handshakes to assess PQC readiness. Unlike domain mode (which actively connects to a specific endpoint), network mode passively observes whatever TLS/SSH traffic crosses the interface.

Capabilities

📡

Live Interface Capture

Captures directly from a network interface (libpcap/Npcap) — no capture file needed

🔒

TLS 1.2/1.3 Parsing

Extracts ClientHello, ServerHello, supported groups, key shares, and SNI

🔑

SSH 2.0 Parsing

Parses KEXINIT messages for key exchange algorithm negotiation

🛡

PQC Detection

Identifies post-quantum and hybrid key exchanges (ML-KEM, Kyber, SNTRUP)

How It Works​

1

Open the Interface

The scanner opens the specified network interface (requires elevated privileges).

2

Capture and Track Flows

It reconstructs bidirectional network flows using 5-tuple keys (src IP, src port, dst IP, dst port, protocol), for up to the configured capture duration or flow limit.

3

Parse Handshakes

The scanner extracts and parses TLS ClientHello/ServerHello and SSH KEXINIT messages from the reconstructed flows.

4

Classify Findings

Each connection is classified as PQC-ready (safe) or classical-only (quantum-vulnerable), with risk scores and severity levels.

Usage​

# Live-capture on eth0
sudo dke-scanner-agent network --interface eth0

# Bound the capture duration (seconds) and save results
sudo dke-scanner-agent network --interface eth0 --capture-duration-secs 300 --output results.json

# Filter to TLS traffic only
sudo dke-scanner-agent network --interface eth0 --bpf-filter "tcp port 443"

# Keep only PQC-relevant findings
sudo dke-scanner-agent network --interface eth0 --pqc-only

CLI Options​

OptionDescriptionDefault
-i, --interface <IF>(Required) Interface to capture from (e.g. eth0)-
--capture-duration-secs <SECS>Capture duration in secondsUnbounded
--max-flows <N>Maximum number of flows to trackUnbounded
--bpf-filter <FILTER>Optional BPF filter (e.g. "tcp port 443")-
--pqc-onlyKeep only PQC-relevant findingsfalse
-o, --output <FILE>Output file path (stdout if not specified)-
--format <FMT>Output format: json, summaryjson
Note

Live capture typically requires elevated privileges (root / Administrator) to open the network interface. For analyzing traffic already captured to a file with a tool like tcpdump or Wireshark, use Packet Capture instead.

PQC Detection​

The scanner detects post-quantum key exchange algorithms in both TLS and SSH handshakes:

TLS Named Groups​

CategoryAlgorithmsStatus
Hybrid PQC (IANA registered)X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024PQ-Safe
Pure ML-KEM (FIPS 203)MLKEM512, MLKEM768, MLKEM1024PQ-Safe
Pre-standard KyberKyber768_draft, Kyber1024_draftPQ-Safe (draft)
OQS Test IDsOQS_Kyber512, OQS_Kyber768, OQS_Kyber1024PQ-Safe (experimental)
OQS HybridX25519_Kyber768, SecP256r1_Kyber768PQ-Safe (experimental)
Classical onlyX25519, P-256, P-384, FFDHE, etc.Quantum-Vulnerable

SSH KEX Algorithms​

AlgorithmTypeStatus
[email protected]Hybrid (SNTRUP + X25519)PQ-Safe
mlkem768x25519-sha256Hybrid (ML-KEM + X25519)PQ-Safe
mlkem1024x448-sha512Hybrid (ML-KEM + X448)PQ-Safe
kyber-512-sha256Pure KyberPQ-Safe
kyber-768-sha384Pure KyberPQ-Safe
kyber-1024-sha512Pure KyberPQ-Safe
curve25519-sha256, ecdh-sha2-nistp256, etc.ClassicalQuantum-Vulnerable

Risk Classification​

FindingSeverityPriorityDescription
PQ key exchange detectedInfoP4Connection uses post-quantum or hybrid key exchange - safe against quantum attacks
Classical-only key exchangeHighP1Connection uses only classical algorithms - vulnerable to harvest-now-decrypt-later attacks

Flow Tracking​

The scanner reconstructs bidirectional network flows using canonical 5-tuple keys:

  • Source IP and Destination IP
  • Source Port and Destination Port
  • Protocol (TCP)

Packets in both directions are matched to the same flow. Each flow tracks first_seen, last_seen, and packet_count timestamps. Flow tracking is unbounded by default; pass --max-flows to cap memory usage on a long-running capture.

Note

For a very long capture, use --max-flows to control memory usage. Flows beyond the limit are silently dropped.

Use Cases​

📊

Production Traffic Audit

Capture live production traffic to discover all TLS endpoints and their cryptographic parameters

📋

PQ Migration Verification

After deploying PQ-capable TLS configurations, capture traffic and verify that clients are negotiating PQ key exchanges

🔄

Cipher Suite Compliance

Analyze captured traffic to verify all TLS connections use approved cipher suites and algorithms

🔑

SSH Security Assessment

Analyze SSH traffic to verify key exchange algorithms are PQ-ready across your infrastructure

Complementary Modes​

Network mode works best in combination with other scanning modes:

  • Domain mode with --pqc: Active PQ key exchange detection for specific targets
  • Packet Capture: Offline analysis of an already-captured .pcap/.pcapng file
  • Inventory mode: System-level certificate and keystore discovery
  • Filesystem mode: Certificate file analysis on disk
Tip

For a complete cryptographic posture assessment, combine network analysis (what's negotiated on the wire) with filesystem/inventory scanning (what's deployed on disk).