Directories
¶
| Path | Synopsis |
|---|---|
|
cmd
|
|
|
cliprobe
command
cliprobe: minimal pty driver that sends ONE prompt and dumps every byte the CLI emits for 60s.
|
cliprobe: minimal pty driver that sends ONE prompt and dumps every byte the CLI emits for 60s. |
|
clitest
command
clitest spawns `promptzero` in REPL mode under a pty (because the REPL refuses to enter raw mode without a TTY) and drives a few non-LLM slash commands to verify the CLI plumbing works end-to-end: banner prints, /help renders, /quit exits cleanly.
|
clitest spawns `promptzero` in REPL mode under a pty (because the REPL refuses to enter raw mode without a TTY) and drives a few non-LLM slash commands to verify the CLI plumbing works end-to-end: banner prints, /help renders, /quit exits cleanly. |
|
cliyolo
command
cliyolo drives the promptzero REPL through a pty with a curated set of natural-language prompts to exercise every non-destructive Flipper subsystem.
|
cliyolo drives the promptzero REPL through a pty with a curated set of natural-language prompts to exercise every non-destructive Flipper subsystem. |
|
coverage-diff
command
cmd/coverage-diff scrapes the awesome-flipperzero upstream lists for tool/verb names and cross-references them against PromptZero's registered tool registry (internal/tools).
|
cmd/coverage-diff scrapes the awesome-flipperzero upstream lists for tool/verb names and cross-references them against PromptZero's registered tool registry (internal/tools). |
|
flipper-usecases
command
Command flipper-usecases runs realistic operator tasks against a live Flipper Zero and reports pass/fail + concise summaries.
|
Command flipper-usecases runs realistic operator tasks against a live Flipper Zero and reports pass/fail + concise summaries. |
|
flipper-validate
command
flipper-validate is an integration harness that exercises Flipper wrapper methods against a live device over serial.
|
flipper-validate is an integration harness that exercises Flipper wrapper methods against a live device over serial. |
|
hwtest
command
hwtest is a developer-only smoke harness that drives a real Flipper Zero (and optional Marauder) over MCP.
|
hwtest is a developer-only smoke harness that drives a real Flipper Zero (and optional Marauder) over MCP. |
|
marauder-validate
command
marauder-validate is an integration harness that exercises the safe read/RX/inspection subset of Marauder wrapper methods against a live ESP32 Marauder devboard over USB serial.
|
marauder-validate is an integration harness that exercises the safe read/RX/inspection subset of Marauder wrapper methods against a live ESP32 Marauder devboard over USB serial. |
|
mifaretest
command
mifaretest exercises the realistic Mifare workflow against a tag held to the real Flipper: detect → inspect existing fixtures → dump protocol → save a UID-only file → diff vs an existing file → edit → emulate → cleanup.
|
mifaretest exercises the realistic Mifare workflow against a tag held to the real Flipper: detect → inspect existing fixtures → dump protocol → save a UID-only file → diff vs an existing file → edit → emulate → cleanup. |
|
promptzero
command
|
|
|
pzrunner
command
pzrunner is a non-interactive harness that drives the promptzero Agent end-to-end over a real Flipper.
|
pzrunner is a non-interactive harness that drives the promptzero Agent end-to-end over a real Flipper. |
|
webtest
command
webtest spawns `promptzero --web` against a real Flipper, then drives every HTTP API endpoint and the websocket handshake to confirm the public web surface is wired correctly.
|
webtest spawns `promptzero --web` against a real Flipper, then drives every HTTP API endpoint and the websocket handshake to confirm the public web surface is wired correctly. |
|
internal
|
|
|
adsb
Package adsb decodes Mode S downlink frames captured at 1090 MHz — both short-form (56-bit) surveillance replies and long-form (112-bit) extended squitter / ADS-B frames.
|
Package adsb decodes Mode S downlink frames captured at 1090 MHz — both short-form (56-bit) surveillance replies and long-form (112-bit) extended squitter / ADS-B frames. |
|
ais
Package ais decodes AIS (Automatic Identification System) NMEA 0183 sentences carried over the standard AIS VHF channels (161.975 / 162.025 MHz) — the maritime counterpart of ADS-B, mandatory on commercial vessels >300 GT and on most passenger ships under SOLAS Chapter V.
|
Package ais decodes AIS (Automatic Identification System) NMEA 0183 sentences carried over the standard AIS VHF channels (161.975 / 162.025 MHz) — the maritime counterpart of ADS-B, mandatory on commercial vessels >300 GT and on most passenger ships under SOLAS Chapter V. |
|
amqp091
Package amqp091 decodes AMQP 0-9-1 wire-protocol frames per the AMQP 0-9-1 specification.
|
Package amqp091 decodes AMQP 0-9-1 wire-protocol frames per the AMQP 0-9-1 specification. |
|
applecontinuity
Package applecontinuity decodes Apple Continuity BLE advertisement payloads — the Manufacturer-Specific-Data blob Apple devices broadcast for Handoff, AirDrop, Nearby Info / Action, AirPods proximity pairing, iBeacon, Hey Siri, and the other ad-hoc connectivity primitives that make the Apple ecosystem feel "magical" on a sniffer.
|
Package applecontinuity decodes Apple Continuity BLE advertisement payloads — the Manufacturer-Specific-Data blob Apple devices broadcast for Handoff, AirDrop, Nearby Info / Action, AirPods proximity pairing, iBeacon, Hey Siri, and the other ad-hoc connectivity primitives that make the Apple ecosystem feel "magical" on a sniffer. |
|
aprs
Package aprs decodes APRS (Automatic Packet Reporting System) frames carried over AX.25 — the dominant ham-radio position + telemetry + messaging beacon family transmitted on 144.39 MHz (NA), 144.80 MHz (EU), and a handful of HF bands.
|
Package aprs decodes APRS (Automatic Packet Reporting System) frames carried over AX.25 — the dominant ham-radio position + telemetry + messaging beacon family transmitted on 144.39 MHz (NA), 144.80 MHz (EU), and a handful of HF bands. |
|
arpdecode
Package arpdecode decodes Address Resolution Protocol (ARP) and Reverse ARP (RARP) packets per RFC 826 + RFC 903 + the RFC 5227 IPv4 address-conflict-detection extensions (gratuitous ARP / ARP probe / ARP announcement).
|
Package arpdecode decodes Address Resolution Protocol (ARP) and Reverse ARP (RARP) packets per RFC 826 + RFC 903 + the RFC 5227 IPv4 address-conflict-detection extensions (gratuitous ARP / ARP probe / ARP announcement). |
|
attack
Package attack maps PromptZero tools and workflows to MITRE ATT&CK techniques.
|
Package attack maps PromptZero tools and workflows to MITRE ATT&CK techniques. |
|
bacnet
Package bacnet decodes BACnet/IP (BACnet over UDP, ASHRAE 135 Annex J) frames — the dominant building-automation protocol used in HVAC controllers, lighting panels, energy meters, fire-alarm gateways, elevator dispatch, and BMS (Building Management Systems) front-ends.
|
Package bacnet decodes BACnet/IP (BACnet over UDP, ASHRAE 135 Annex J) frames — the dominant building-automation protocol used in HVAC controllers, lighting panels, energy meters, fire-alarm gateways, elevator dispatch, and BMS (Building Management Systems) front-ends. |
|
badusb
Package badusb parses DuckyScript / BadUSB payload scripts into structured line-by-line views — command + arguments + validation status.
|
Package badusb parses DuckyScript / BadUSB payload scripts into structured line-by-line views — command + arguments + validation status. |
|
bfd
Package bfd decodes BFD Control packets per RFC 5880.
|
Package bfd decodes BFD Control packets per RFC 5880. |
|
bgp
Package bgp decodes BGP-4 messages per RFC 4271 plus the canonical extensions: RFC 4760 (Multiprotocol BGP / MP-BGP), RFC 5492 (Capabilities Optional Parameter), RFC 6793 (4-byte AS Number), and RFC 2918 / 7313 (Route Refresh).
|
Package bgp decodes BGP-4 messages per RFC 4271 plus the canonical extensions: RFC 4760 (Multiprotocol BGP / MP-BGP), RFC 5492 (Capabilities Optional Parameter), RFC 6793 (4-byte AS Number), and RFC 2918 / 7313 (Route Refresh). |
|
ble
Package ble decodes BLE advertisement payloads — currently just Apple Continuity manufacturer-data — into operator-facing structures.
|
Package ble decodes BLE advertisement payloads — currently just Apple Continuity manufacturer-data — into operator-facing structures. |
|
breaker
Package breaker implements a per-tool consecutive-error circuit breaker (roadmap P3-28, second half).
|
Package breaker implements a per-tool consecutive-error circuit breaker (roadmap P3-28, second half). |
|
bruce
Package bruce interfaces with the Bruce pentesting firmware for ESP32-based boards over a USB-serial connection.
|
Package bruce interfaces with the Bruce pentesting firmware for ESP32-based boards over a USB-serial connection. |
|
btclassic
Package btclassic decodes Bluetooth Classic (BR/EDR) metadata fields — primarily the 24-bit Class of Device (CoD) value that every classic Bluetooth device advertises during inquiry.
|
Package btclassic decodes Bluetooth Classic (BR/EDR) metadata fields — primarily the 24-bit Class of Device (CoD) value that every classic Bluetooth device advertises during inquiry. |
|
btuuid
Package btuuid resolves Bluetooth SIG-assigned 16-bit GATT UUIDs (Services, Characteristics, Descriptors) to their canonical names.
|
Package btuuid resolves Bluetooth SIG-assigned 16-bit GATT UUIDs (Services, Characteristics, Descriptors) to their canonical names. |
|
buspirate
Package buspirate is the PromptZero backend for the Bus Pirate 5 universal bus probe (RP2040-based).
|
Package buspirate is the PromptZero backend for the Bus Pirate 5 universal bus probe (RP2040-based). |
|
campaign
Package campaign implements the PromptZero Campaigns feature (roadmap P2-19) — declarative, YAML-authored multi-step engagement specs that compose the existing agent tool surface.
|
Package campaign implements the PromptZero Campaigns feature (roadmap P2-19) — declarative, YAML-authored multi-step engagement specs that compose the existing agent tool surface. |
|
cassandra
Package cassandra decodes Apache Cassandra CQL binary protocol frames.
|
Package cassandra decodes Apache Cassandra CQL binary protocol frames. |
|
cbordecode
Package cbordecode parses CBOR (Concise Binary Object Representation) per RFC 8949.
|
Package cbordecode parses CBOR (Concise Binary Object Representation) per RFC 8949. |
|
cdp
Package cdp decodes Cisco Discovery Protocol packets per the publicly-documented wire format (reverse-engineered and documented in Wireshark dissectors, tcpdump output, and the CDP protocol whitepapers Cisco has historically published).
|
Package cdp decodes Cisco Discovery Protocol packets per the publicly-documented wire format (reverse-engineered and documented in Wireshark dissectors, tcpdump output, and the CDP protocol whitepapers Cisco has historically published). |
|
clisafe
Package clisafe contains helpers shared by every transport that pushes operator-supplied strings through a line-oriented CLI.
|
Package clisafe contains helpers shared by every transport that pushes operator-supplied strings through a line-oriented CLI. |
|
coap
Package coap decodes Constrained Application Protocol (RFC 7252) packets — the application-layer protocol used by constrained IoT devices (6LoWPAN, Thread, OpenThread, Zigbee IP).
|
Package coap decodes Constrained Application Protocol (RFC 7252) packets — the application-layer protocol used by constrained IoT devices (6LoWPAN, Thread, OpenThread, Zigbee IP). |
|
confidence
Package confidence provides pre-dispatch heuristic scoring for tool-use inputs.
|
Package confidence provides pre-dispatch heuristic scoring for tool-use inputs. |
|
consensus
Package consensus implements ensemble voting over multi-model risk verdicts (roadmap P3-33).
|
Package consensus implements ensemble voting over multi-model risk verdicts (roadmap P3-33). |
|
containerbridge
Package containerbridge runs external CLI tools inside Docker containers and surfaces their output as Go values.
|
Package containerbridge runs external CLI tools inside Docker containers and surfaces their output as Go values. |
|
cost
Package cost tracks Anthropic token usage and running dollar cost per PromptZero session, and implements the simple "consecutive errors → offline" heuristic that flips the observability offline banner.
|
Package cost tracks Anthropic token usage and running dollar cost per PromptZero session, and implements the simple "consecutive errors → offline" heuristic that flips the observability offline banner. |
|
crypto1
Package crypto1 is the pure-Go implementation of the Crypto1 stream cipher used by MIFARE Classic and some HID iCLASS legacy systems.
|
Package crypto1 is the pure-Go implementation of the Crypto1 stream cipher used by MIFARE Classic and some HID iCLASS legacy systems. |
|
dccp
Package dccp decodes DCCP (Datagram Congestion Control Protocol) packets per RFC 4340.
|
Package dccp decodes DCCP (Datagram Congestion Control Protocol) packets per RFC 4340. |
|
dcerpc
Package dcerpc decodes DCE/RPC (Distributed Computing Environment / Remote Procedure Call) messages per DCE 1.1 + [MS-RPCE] — the Microsoft RPC framing layer that carries nearly every Windows AD attack chain.
|
Package dcerpc decodes DCE/RPC (Distributed Computing Environment / Remote Procedure Call) messages per DCE 1.1 + [MS-RPCE] — the Microsoft RPC framing layer that carries nearly every Windows AD attack chain. |
|
dcf77
Package dcf77 decodes DCF77 time-signal frames — the long-wave (77.5 kHz) radio broadcast from Mainflingen, Germany, that carries the current Central European time + date.
|
Package dcf77 decodes DCF77 time-signal frames — the long-wave (77.5 kHz) radio broadcast from Mainflingen, Germany, that carries the current Central European time + date. |
|
defense
Package defense provides passive RF / BLE detection helpers used to surface adversarial activity nearby — the blue-team complement to PromptZero's offensive capability set.
|
Package defense provides passive RF / BLE detection helpers used to surface adversarial activity nearby — the blue-team complement to PromptZero's offensive capability set. |
|
desfire
Package desfire decodes Mifare DESFire Application Identifiers (AIDs) — the 3-byte values returned by the DESFire GetApplicationIDs command that identify each application stored on the card.
|
Package desfire decodes Mifare DESFire Application Identifiers (AIDs) — the 3-byte values returned by the DESFire GetApplicationIDs command that identify each application stored on the card. |
|
dhcp
Package dhcp decodes DHCPv4 packets per RFC 2131 (the envelope) + RFC 2132 (the options).
|
Package dhcp decodes DHCPv4 packets per RFC 2131 (the envelope) + RFC 2132 (the options). |
|
dhcpv6
Package dhcpv6 decodes DHCPv6 packets per RFC 8415 (which consolidates RFC 3315 + RFC 3633 prefix delegation + RFC 3646 DNS configuration + RFC 4242 information refresh time + RFC 7083 rapid-commit / unicast updates into one current spec).
|
Package dhcpv6 decodes DHCPv6 packets per RFC 8415 (which consolidates RFC 3315 + RFC 3633 prefix delegation + RFC 3646 DNS configuration + RFC 4242 information refresh time + RFC 7083 rapid-commit / unicast updates into one current spec). |
|
diameter
Package diameter decodes Diameter packets per RFC 6733 (the current Diameter Base Protocol — supersedes RFC 3588).
|
Package diameter decodes Diameter packets per RFC 6733 (the current Diameter Base Protocol — supersedes RFC 3588). |
|
diff
Package diff renders a `git diff --no-prefix`-style unified-diff string from two text inputs.
|
Package diff renders a `git diff --no-prefix`-style unified-diff string from two text inputs. |
|
dnp3
Package dnp3 decodes DNP3 (Distributed Network Protocol 3) frames per IEEE 1815-2012.
|
Package dnp3 decodes DNP3 (Distributed Network Protocol 3) frames per IEEE 1815-2012. |
|
dnsdecode
Package dnsdecode parses DNS messages on the wire — the most-traffic-bearing UDP protocol on the internet and a staple of every blue-team / red-team / network-debugging workflow.
|
Package dnsdecode parses DNS messages on the wire — the most-traffic-bearing UDP protocol on the internet and a staple of every blue-team / red-team / network-debugging workflow. |
|
droneid
Package droneid decodes ASTM F3411-22 (a.k.a.
|
Package droneid decodes ASTM F3411-22 (a.k.a. |
|
dtls
Package dtls decodes Datagram Transport Layer Security records and handshake messages per RFC 6347 (DTLS 1.2) and RFC 9147 (DTLS 1.3 — unified header form is not supported here; we decode the legacy DTLS 1.3 record layer that uses the same 13-byte header as 1.2).
|
Package dtls decodes Datagram Transport Layer Security records and handshake messages per RFC 6347 (DTLS 1.2) and RFC 9147 (DTLS 1.3 — unified header form is not supported here; we decode the legacy DTLS 1.3 record layer that uses the same 13-byte header as 1.2). |
|
eapol
Package eapol decodes EAPOL-Key frames — the WPA / WPA2 / WPA3 4-way handshake frames captured from any 802.1X-bearing medium.
|
Package eapol decodes EAPOL-Key frames — the WPA / WPA2 / WPA3 4-way handshake frames captured from any 802.1X-bearing medium. |
|
eigrp
Package eigrp decodes EIGRP (Enhanced Interior Gateway Routing Protocol) packets per RFC 7868 (informational; Cisco proprietary until 2016).
|
Package eigrp decodes EIGRP (Enhanced Interior Gateway Routing Protocol) packets per RFC 7868 (informational; Cisco proprietary until 2016). |
|
emv
Package emv decodes EMV BER-TLV structures from contactless and contact payment card APDU responses.
|
Package emv decodes EMV BER-TLV structures from contactless and contact payment card APDU responses. |
|
enip
Package enip decodes EtherNet/IP encapsulation packets and the CIP (Common Industrial Protocol) messages they carry — the ODVA factory-automation protocol family used by Allen-Bradley / Rockwell ControlLogix / CompactLogix / MicroLogix PLCs, Omron NJ/NX, Cognex vision systems, and a long tail of CIP-compliant I/O modules and drives.
|
Package enip decodes EtherNet/IP encapsulation packets and the CIP (Common Industrial Protocol) messages they carry — the ODVA factory-automation protocol family used by Allen-Bradley / Rockwell ControlLogix / CompactLogix / MicroLogix PLCs, Omron NJ/NX, Cognex vision systems, and a long tail of CIP-compliant I/O modules and drives. |
|
estransport
Package estransport decodes Elasticsearch internal transport protocol frames.
|
Package estransport decodes Elasticsearch internal transport protocol frames. |
|
eval
Package eval provides the PromptZero golden evaluation harness (roadmap P2-25).
|
Package eval provides the PromptZero golden evaluation harness (roadmap P2-25). |
|
faultier
Package faultier drives a hextreeio Faultier USB voltage-glitcher via its serial bridge interface.
|
Package faultier drives a hextreeio Faultier USB voltage-glitcher via its serial bridge interface. |
|
fileformat
Package fileformat gives the PromptZero agent structural access to the Flipper file formats it already ships with — .sub, .nfc, .ir, .rfid.
|
Package fileformat gives the PromptZero agent structural access to the Flipper file formats it already ships with — .sub, .nfc, .ir, .rfid. |
|
flipper/mock
Package mock provides a pty-backed fake Flipper CLI so serial.go and the command wrappers can be exercised without real hardware.
|
Package mock provides a pty-backed fake Flipper CLI so serial.go and the command wrappers can be exercised without real hardware. |
|
flipper/rpc
Package rpc implements a typed Flipper Zero RPC client over a transport.Transport.
|
Package rpc implements a typed Flipper Zero RPC client over a transport.Transport. |
|
flipper/transport
Package transport defines the byte-channel substrate the Flipper CLI layer operates over.
|
Package transport defines the byte-channel substrate the Flipper CLI layer operates over. |
|
geneve
Package geneve decodes Generic Network Virtualization Encapsulation packets per RFC 8926.
|
Package geneve decodes Generic Network Virtualization Encapsulation packets per RFC 8926. |
|
goose
Package goose decodes IEC 61850-8-1 GOOSE (Generic Object Oriented Substation Events) messages — the time-critical multicast Ethernet protocol that carries protective-relay signals between Intelligent Electronic Devices (IEDs) inside modern digital substations.
|
Package goose decodes IEC 61850-8-1 GOOSE (Generic Object Oriented Substation Events) messages — the time-critical multicast Ethernet protocol that carries protective-relay signals between Intelligent Electronic Devices (IEDs) inside modern digital substations. |
|
gre
Package gre decodes Generic Routing Encapsulation packets per RFC 2784 (base) + RFC 2890 (Key + Sequence Number) + RFC 2637 (PPTP Enhanced GRE, Version=1).
|
Package gre decodes Generic Routing Encapsulation packets per RFC 2784 (base) + RFC 2890 (Key + Sequence Number) + RFC 2637 (PPTP Enhanced GRE, Version=1). |
|
grpcdecode
Package grpcdecode decodes gRPC Length-Prefixed Messages per the gRPC wire-protocol specification.
|
Package grpcdecode decodes gRPC Length-Prefixed Messages per the gRPC wire-protocol specification. |
|
gsmtap
Package gsmtap decodes GSMTAP pseudo-header bytes per the Osmocom GSMTAP specification (osmo-bts / osmo-pcap-server / gsmtap.h reference).
|
Package gsmtap decodes GSMTAP pseudo-header bytes per the Osmocom GSMTAP specification (osmo-bts / osmo-pcap-server / gsmtap.h reference). |
|
gtp
Package gtp decodes GPRS Tunneling Protocol User Plane (GTP-U) packets per 3GPP TS 29.281.
|
Package gtp decodes GPRS Tunneling Protocol User Plane (GTP-U) packets per 3GPP TS 29.281. |
|
hartip
Package hartip decodes HART-IP (Highway Addressable Remote Transducer over IP) messages per the HART Foundation specification (HCF_SPEC-085 + the HART-IP wire format reference).
|
Package hartip decodes HART-IP (Highway Addressable Remote Transducer over IP) messages per the HART Foundation specification (HCF_SPEC-085 + the HART-IP wire format reference). |
|
hpack
Package hpack decodes HPACK-compressed HTTP/2 header blocks per RFC 7541.
|
Package hpack decodes HPACK-compressed HTTP/2 header blocks per RFC 7541. |
|
hsrp
Package hsrp decodes Hot Standby Router Protocol (HSRP) packets per RFC 2281 (HSRPv1) and the Cisco HSRPv2 TLV extensions.
|
Package hsrp decodes Hot Standby Router Protocol (HSRP) packets per RFC 2281 (HSRPv1) and the Cisco HSRPv2 TLV extensions. |
|
http2
Package http2 decodes HTTP/2 frames per RFC 9113.
|
Package http2 decodes HTTP/2 frames per RFC 9113. |
|
httpmsg
Package httpmsg decodes HTTP/1.x messages per RFC 9112 + RFC 9110.
|
Package httpmsg decodes HTTP/1.x messages per RFC 9112 + RFC 9110. |
|
ibutton
Package ibutton decodes Dallas 1-Wire ROM IDs (a.k.a.
|
Package ibutton decodes Dallas 1-Wire ROM IDs (a.k.a. |
|
iclass
Package iclass implements the iCLASS block cipher and the loclass key-recovery attack against HID iCLASS Elite / High Security readers.
|
Package iclass implements the iCLASS block cipher and the loclass key-recovery attack against HID iCLASS Elite / High Security readers. |
|
icmp
Package icmp decodes ICMP (RFC 792) and ICMPv6 (RFC 4443 + 4861 for Neighbor Discovery) packets.
|
Package icmp decodes ICMP (RFC 792) and ICMPv6 (RFC 4443 + 4861 for Neighbor Discovery) packets. |
|
iec104
Package iec104 decodes IEC 60870-5-104 APDUs — the European / Asian utility-SCADA telecontrol protocol that runs over TCP/IP.
|
Package iec104 decodes IEC 60870-5-104 APDUs — the European / Asian utility-SCADA telecontrol protocol that runs over TCP/IP. |
|
ieee80211
Package ieee80211 decodes IEEE 802.11 management frames — the beacon / probe / authentication / association / deauthentication / disassociation frames captured by every WiFi sniffer (Marauder, hcxdumptool, aircrack-ng, Wireshark).
|
Package ieee80211 decodes IEEE 802.11 management frames — the beacon / probe / authentication / association / deauthentication / disassociation frames captured by every WiFi sniffer (Marauder, hcxdumptool, aircrack-ng, Wireshark). |
|
ieee802154
Package ieee802154 decodes IEEE 802.15.4 MAC-layer frames — the wire format underneath Zigbee, Thread, OpenThread, and most other 2.4 GHz IoT mesh stacks.
|
Package ieee802154 decodes IEEE 802.15.4 MAC-layer frames — the wire format underneath Zigbee, Thread, OpenThread, and most other 2.4 GHz IoT mesh stacks. |
|
igmp
Package igmp decodes Internet Group Management Protocol packets per RFC 3376 (IGMPv3) and RFC 2236 (IGMPv2).
|
Package igmp decodes Internet Group Management Protocol packets per RFC 3376 (IGMPv3) and RFC 2236 (IGMPv2). |
|
ike
Package ike decodes IKEv2 (Internet Key Exchange version 2) messages per RFC 7296.
|
Package ike decodes IKEv2 (Internet Key Exchange version 2) messages per RFC 7296. |
|
imap
Package imap decodes IMAP4rev1 (Internet Message Access Protocol v4 revision 1) messages per RFC 3501, plus the RFC 2595 (STARTTLS), RFC 2087 (QUOTA), RFC 2342 (NAMESPACE), and RFC 4978 (COMPRESS) extensions.
|
Package imap decodes IMAP4rev1 (Internet Message Access Protocol v4 revision 1) messages per RFC 3501, plus the RFC 2595 (STARTTLS), RFC 2087 (QUOTA), RFC 2342 (NAMESPACE), and RFC 4978 (COMPRESS) extensions. |
|
ipdecode
Package ipdecode parses raw IP packets (IPv4 + IPv6) plus the most-deployed next-layer headers (TCP, UDP, ICMP, ICMPv6).
|
Package ipdecode parses raw IP packets (IPv4 + IPv6) plus the most-deployed next-layer headers (TCP, UDP, ICMP, ICMPv6). |
|
ipfix
Package ipfix decodes IPFIX (IP Flow Information eXport) messages per RFC 7011.
|
Package ipfix decodes IPFIX (IP Flow Information eXport) messages per RFC 7011. |
|
ipmi
Package ipmi decodes IPMI (Intelligent Platform Management Interface) messages carried over RMCP (Remote Management Control Protocol) on UDP/623.
|
Package ipmi decodes IPMI (Intelligent Platform Management Interface) messages carried over RMCP (Remote Management Control Protocol) on UDP/623. |
|
ipsec
Package ipsec decodes the two IPsec data-plane protocols: ESP (Encapsulating Security Payload) per RFC 4303 and AH (Authentication Header) per RFC 4302.
|
Package ipsec decodes the two IPsec data-plane protocols: ESP (Encapsulating Security Payload) per RFC 4303 and AH (Authentication Header) per RFC 4302. |
|
isis
Package isis decodes IS-IS (Intermediate System to Intermediate System) packets per ISO 10589 and RFC 1195.
|
Package isis decodes IS-IS (Intermediate System to Intermediate System) packets per ISO 10589 and RFC 1195. |
|
iso14443a
Package iso14443a identifies ISO/IEC 14443-3 Type A NFC tags from their anti-collision response (ATQA + SAK + UID, plus optional ATS).
|
Package iso14443a identifies ISO/IEC 14443-3 Type A NFC tags from their anti-collision response (ATQA + SAK + UID, plus optional ATS). |
|
iso7816
Package iso7816 decodes ISO/IEC 7816-3 Answer To Reset (ATR) strings — the response every contact smart card sends when reset.
|
Package iso7816 decodes ISO/IEC 7816-3 Answer To Reset (ATR) strings — the response every contact smart card sends when reset. |
|
j1850
Package j1850 decodes SAE J1850 VPW (Variable Pulse Width) and PWM (Pulse Width Modulation) frames — the legacy OBD-II protocol used by GM and Ford vehicles before they migrated to CAN bus around 2008.
|
Package j1850 decodes SAE J1850 VPW (Variable Pulse Width) and PWM (Pulse Width Modulation) frames — the legacy OBD-II protocol used by GM and Ford vehicles before they migrated to CAN bus around 2008. |
|
jtag
Package jtag decodes JTAG IDCODE values (IEEE 1149.1) and the SWD DPIDR / TARGETID variants used by ARM CoreSight debug interfaces.
|
Package jtag decodes JTAG IDCODE values (IEEE 1149.1) and the SWD DPIDR / TARGETID variants used by ARM CoreSight debug interfaces. |
|
jwtdecode
Package jwtdecode decodes JSON Web Tokens (JWT) — the dominant API auth token format in modern web stacks.
|
Package jwtdecode decodes JSON Web Tokens (JWT) — the dominant API auth token format in modern web stacks. |
|
kafka
Package kafka decodes Apache Kafka wire-protocol request/response messages per the Kafka protocol specification (KIP-35 and the protocol guide).
|
Package kafka decodes Apache Kafka wire-protocol request/response messages per the Kafka protocol specification (KIP-35 and the protocol guide). |
|
keeloq
Package keeloq implements the KeeLoq block cipher and supporting primitives for sub-GHz rolling-code analysis.
|
Package keeloq implements the KeeLoq block cipher and supporting primitives for sub-GHz rolling-code analysis. |
|
kerberos
Package kerberos decodes Kerberos v5 messages per RFC 4120 — the authentication protocol that underpins **every Active Directory deployment** and most enterprise SSO stacks (MIT Kerberos, Heimdal, Microsoft Active Directory, Apple Open Directory, FreeIPA / IdM).
|
Package kerberos decodes Kerberos v5 messages per RFC 4120 — the authentication protocol that underpins **every Active Directory deployment** and most enterprise SSO stacks (MIT Kerberos, Heimdal, Microsoft Active Directory, Apple Open Directory, FreeIPA / IdM). |
|
l2tp
Package l2tp decodes L2TPv3 packets per RFC 3931 (UDP- encapsulated mode on UDP port 1701).
|
Package l2tp decodes L2TPv3 packets per RFC 3931 (UDP- encapsulated mode on UDP port 1701). |
|
lacp
Package lacp decodes Link Aggregation Control Protocol (LACP) PDUs per IEEE 802.1AX-2020 (formerly 802.3ad).
|
Package lacp decodes Link Aggregation Control Protocol (LACP) PDUs per IEEE 802.1AX-2020 (formerly 802.3ad). |
|
ldap
Package ldap decodes Lightweight Directory Access Protocol v3 messages per RFC 4511 — the canonical directory-service protocol used by **every Active Directory deployment** + most enterprise IAM stacks (Microsoft AD LDS, OpenLDAP, 389 Directory Server, FreeIPA / IdM, Apple Open Directory, Apache Directory Server, Oracle Internet Directory, Novell eDirectory).
|
Package ldap decodes Lightweight Directory Access Protocol v3 messages per RFC 4511 — the canonical directory-service protocol used by **every Active Directory deployment** + most enterprise IAM stacks (Microsoft AD LDS, OpenLDAP, 389 Directory Server, FreeIPA / IdM, Apple Open Directory, Apache Directory Server, Oracle Internet Directory, Novell eDirectory). |
|
ldp
Package ldp decodes LDP (Label Distribution Protocol) PDUs per RFC 5036.
|
Package ldp decodes LDP (Label Distribution Protocol) PDUs per RFC 5036. |
|
lldp
Package lldp decodes Link Layer Discovery Protocol payloads per IEEE 802.1AB-2009.
|
Package lldp decodes Link Layer Discovery Protocol payloads per IEEE 802.1AB-2009. |
|
llmnr
Package llmnr decodes LLMNR (Link-Local Multicast Name Resolution) messages per RFC 4795.
|
Package llmnr decodes LLMNR (Link-Local Multicast Name Resolution) messages per RFC 4795. |
|
lorawan
Package lorawan decodes LoRaWAN PHYPayload frames — the MAC-layer packet format used by LoRaWAN 1.0.x and 1.1 networks.
|
Package lorawan decodes LoRaWAN PHYPayload frames — the MAC-layer packet format used by LoRaWAN 1.0.x and 1.1 networks. |
|
marauder/parsers
Package parsers turns Marauder CLI output lines into typed events the web layer can ship as JSON.
|
Package parsers turns Marauder CLI output lines into typed events the web layer can ship as JSON. |
|
mcp
Package mcp exposes PromptZero's tool surface over the Model Context Protocol (stdio transport).
|
Package mcp exposes PromptZero's tool surface over the Model Context Protocol (stdio transport). |
|
mcpfed
Package mcpfed federates external Model Context Protocol (MCP) servers as native PromptZero tools.
|
Package mcpfed federates external Model Context Protocol (MCP) servers as native PromptZero tools. |
|
mdns
Package mdns decodes Multicast DNS (mDNS) messages per RFC 6762 + the DNS-SD (DNS-Based Service Discovery) layer per RFC 6763.
|
Package mdns decodes Multicast DNS (mDNS) messages per RFC 6762 + the DNS-SD (DNS-Based Service Discovery) layer per RFC 6763. |
|
memcached
Package memcached decodes Memcached binary-protocol messages per the Memcached binary protocol specification.
|
Package memcached decodes Memcached binary-protocol messages per the Memcached binary protocol specification. |
|
mifare
Package mifare decodes Mifare Classic 1K / 4K data dumps — manufacturer block (sector 0 block 0), sector trailer (last block of each sector), value blocks (recognized by their value+complement structure), and plain data blocks.
|
Package mifare decodes Mifare Classic 1K / 4K data dumps — manufacturer block (sector 0 block 0), sector trailer (last block of each sector), value blocks (recognized by their value+complement structure), and plain data blocks. |
|
modbus
Package modbus decodes Modbus RTU and Modbus TCP frames per the Modbus Application Protocol Specification v1.1b3 and the Modbus Messaging Implementation Guide v1.0b.
|
Package modbus decodes Modbus RTU and Modbus TCP frames per the Modbus Application Protocol Specification v1.1b3 and the Modbus Messaging Implementation Guide v1.0b. |
|
mode
Package mode defines named operation profiles that constrain which tools the agent will dispatch.
|
Package mode defines named operation profiles that constrain which tools the agent will dispatch. |
|
mongodb
Package mongodb decodes MongoDB wire protocol messages per the MongoDB documentation ("MongoDB Wire Protocol").
|
Package mongodb decodes MongoDB wire protocol messages per the MongoDB documentation ("MongoDB Wire Protocol"). |
|
mpls
Package mpls decodes MPLS label stacks per RFC 3032 (stack encoding) + RFC 5462 (TC field rename from EXP) + the reserved-label catalogue from RFC 4182 / 5586 / 6790 / 7274.
|
Package mpls decodes MPLS label stacks per RFC 3032 (stack encoding) + RFC 5462 (TC field rename from EXP) + the reserved-label catalogue from RFC 4182 / 5586 / 6790 / 7274. |
|
mqtt
Package mqtt decodes MQTT v3.1.1 control packets — the application-layer protocol underneath most IoT smart-home / industrial-sensor / broker setups.
|
Package mqtt decodes MQTT v3.1.1 control packets — the application-layer protocol underneath most IoT smart-home / industrial-sensor / broker setups. |
|
mqttsn
Package mqttsn decodes MQTT-SN (MQTT for Sensor Networks) v1.2 messages per the OASIS MQTT-SN specification.
|
Package mqttsn decodes MQTT-SN (MQTT for Sensor Networks) v1.2 messages per the OASIS MQTT-SN specification. |
|
msdp
Package msdp decodes MSDP (Multicast Source Discovery Protocol) packets per RFC 3618.
|
Package msdp decodes MSDP (Multicast Source Discovery Protocol) packets per RFC 3618. |
|
mysqldb
Package mysqldb decodes MySQL / MariaDB client/server protocol messages per the MySQL documentation (Chapter 4: "Client/Server Protocol").
|
Package mysqldb decodes MySQL / MariaDB client/server protocol messages per the MySQL documentation (Chapter 4: "Client/Server Protocol"). |
|
natpmp
Package natpmp decodes NAT-PMP (NAT Port Mapping Protocol) messages per RFC 6886.
|
Package natpmp decodes NAT-PMP (NAT Port Mapping Protocol) messages per RFC 6886. |
|
nbns
Package nbns decodes NBNS (NetBIOS Name Service) messages per RFC 1001 (NetBIOS service concepts) and RFC 1002 (NetBIOS over TCP/UDP encoding).
|
Package nbns decodes NBNS (NetBIOS Name Service) messages per RFC 1001 (NetBIOS service concepts) and RFC 1002 (NetBIOS over TCP/UDP encoding). |
|
ndef
Package ndef decodes NFC Data Exchange Format messages — the payload format every NDEF-formatted NFC tag stores.
|
Package ndef decodes NFC Data Exchange Format messages — the payload format every NDEF-formatted NFC tag stores. |
|
ndp
Package ndp decodes ICMPv6 NDP (Neighbor Discovery Protocol) messages per RFC 4861 (base NDP) + RFC 4191 (Default Router Preferences + Route Information) + RFC 8106 (RDNSS / DNSSL for SLAAC-only IPv6 hosts).
|
Package ndp decodes ICMPv6 NDP (Neighbor Discovery Protocol) messages per RFC 4861 (base NDP) + RFC 4191 (Default Router Preferences + Route Information) + RFC 8106 (RDNSS / DNSSL for SLAAC-only IPv6 hosts). |
|
netflow
Package netflow decodes NetFlow v5 export packets per Cisco's public NetFlow v5 specification (1996; the dominant flow-export format on enterprise + ISP networks for two decades, still emitted by every Cisco / Juniper / Arista router that runs classic NetFlow).
|
Package netflow decodes NetFlow v5 export packets per Cisco's public NetFlow v5 specification (1996; the dominant flow-export format on enterprise + ISP networks for two decades, still emitted by every Cisco / Juniper / Arista router that runs classic NetFlow). |
|
netflow9
Package netflow9 decodes NetFlow v9 (RFC 3954) packets.
|
Package netflow9 decodes NetFlow v9 (RFC 3954) packets. |
|
nrf24
Package nrf24 decodes Nordic NRF24L01 Enhanced Shockburst (ESB) packets and the Logitech Unifying / Mousejack payload variants that ride on top of them.
|
Package nrf24 decodes Nordic NRF24L01 Enhanced Shockburst (ESB) packets and the Logitech Unifying / Mousejack payload variants that ride on top of them. |
|
ntlm
Package ntlm decodes NTLM (NT LAN Manager) messages per Microsoft Open Protocol Specifications MS-NLMP.
|
Package ntlm decodes NTLM (NT LAN Manager) messages per Microsoft Open Protocol Specifications MS-NLMP. |
|
ntp
Package ntp decodes NTP / SNTP packets per RFC 5905 (v4), RFC 1305 (v3), and RFC 4330 (SNTPv4).
|
Package ntp decodes NTP / SNTP packets per RFC 5905 (v4), RFC 1305 (v3), and RFC 4330 (SNTPv4). |
|
obs
Package obs ("observability") is the cross-cutting layer that wires structured logging, Prometheus metrics, and the /debug snapshot view into the rest of PromptZero.
|
Package obs ("observability") is the cross-cutting layer that wires structured logging, Prometheus metrics, and the /debug snapshot view into the rest of PromptZero. |
|
opcua
Package opcua decodes OPC UA Binary messages per IEC 62541-6 (OPC Unified Architecture, Part 6: Mappings).
|
Package opcua decodes OPC UA Binary messages per IEC 62541-6 (OPC Unified Architecture, Part 6: Mappings). |
|
openflow
Package openflow decodes OpenFlow control-channel messages per the Open Networking Foundation (ONF) specifications — version 1.0 (`of10`), 1.3 (`of13`; the dominant deployed version), and 1.5 (`of15`).
|
Package openflow decodes OpenFlow control-channel messages per the Open Networking Foundation (ONF) specifications — version 1.0 (`of10`), 1.3 (`of13`; the dominant deployed version), and 1.5 (`of15`). |
|
ospf
Package ospf decodes OSPFv2 packets per RFC 2328.
|
Package ospf decodes OSPFv2 packets per RFC 2328. |
|
ospfv3
Package ospfv3 decodes OSPFv3 (RFC 5340) packets.
|
Package ospfv3 decodes OSPFv3 (RFC 5340) packets. |
|
pacs
Package pacs decodes Physical Access Control System (PACS) credential payloads — the upper-layer encoding that sits on top of the Wiegand bit-stream produced by an HID Prox / iCLASS / EM-style reader.
|
Package pacs decodes Physical Access Control System (PACS) credential payloads — the upper-layer encoding that sits on top of the Wiegand bit-stream produced by an HID Prox / iCLASS / EM-style reader. |
|
pcap
Package pcap implements a pure-Go libpcap classic-format writer and reader.
|
Package pcap implements a pure-Go libpcap classic-format writer and reader. |
|
pcapng
Package pcapng decodes the PCAPng (next-generation packet capture, draft-tuexen-opsawg-pcapng) file format.
|
Package pcapng decodes the PCAPng (next-generation packet capture, draft-tuexen-opsawg-pcapng) file format. |
|
pcp
Package pcp decodes PCP (Port Control Protocol) messages per RFC 6887.
|
Package pcp decodes PCP (Port Control Protocol) messages per RFC 6887. |
|
persona
Package persona implements operator-mode profiles for PromptZero.
|
Package persona implements operator-mode profiles for PromptZero. |
|
pim
Package pim decodes Protocol Independent Multicast (PIM) version 2 packets per RFC 7761 (PIM-SM v2; the dominant multicast routing protocol).
|
Package pim decodes Protocol Independent Multicast (PIM) version 2 packets per RFC 7761 (PIM-SM v2; the dominant multicast routing protocol). |
|
pocsag
Package pocsag decodes POCSAG (Post Office Code Standardisation Advisory Group) paging-protocol bit-streams — ITU-R M.584-2 — into structured pages with address, function (numeric / alphanumeric), and decoded message text.
|
Package pocsag decodes POCSAG (Post Office Code Standardisation Advisory Group) paging-protocol bit-streams — ITU-R M.584-2 — into structured pages with address, function (numeric / alphanumeric), and decoded message text. |
|
pop3
Package pop3 decodes POP3 (Post Office Protocol v3) messages per RFC 1939, plus the RFC 2449 (CAPA), RFC 2595 (STLS), and RFC 5034 (AUTH SASL) extensions.
|
Package pop3 decodes POP3 (Post Office Protocol v3) messages per RFC 1939, plus the RFC 2449 (CAPA), RFC 2595 (STLS), and RFC 5034 (AUTH SASL) extensions. |
|
postgres
Package postgres decodes PostgreSQL frontend / backend protocol v3 messages per the PostgreSQL documentation (Part VIII: "Frontend/Backend Protocol").
|
Package postgres decodes PostgreSQL frontend / backend protocol v3 messages per the PostgreSQL documentation (Part VIII: "Frontend/Backend Protocol"). |
|
pppoe
Package pppoe decodes Point-to-Point Protocol over Ethernet packets per RFC 2516 — both the Discovery phase (PADI / PADO / PADR / PADS / PADT) and the Session phase (PPP-in- PPPoE payload).
|
Package pppoe decodes Point-to-Point Protocol over Ethernet packets per RFC 2516 — both the Discovery phase (PADI / PADO / PADR / PADS / PADT) and the Session phase (PPP-in- PPPoE payload). |
|
profinetdcp
Package profinetdcp decodes Profinet DCP (Discovery and Configuration Protocol) frames per IEC 61158-6-10.
|
Package profinetdcp decodes Profinet DCP (Discovery and Configuration Protocol) frames per IEC 61158-6-10. |
|
protobufdecode
Package protobufdecode parses raw Protocol Buffers wire-format bytes without needing the .proto schema — the equivalent of `protoc --decode_raw`.
|
Package protobufdecode parses raw Protocol Buffers wire-format bytes without needing the .proto schema — the equivalent of `protoc --decode_raw`. |
|
ptpv2
Package ptpv2 decodes PTPv2 (Precision Time Protocol version 2) packets per IEEE 1588-2008.
|
Package ptpv2 decodes PTPv2 (Precision Time Protocol version 2) packets per IEEE 1588-2008. |
|
quic
Package quic decodes QUIC long-header packets per RFC 9000.
|
Package quic decodes QUIC long-header packets per RFC 9000. |
|
radius
Package radius decodes RADIUS packets per RFC 2865 (auth) + RFC 2866 (accounting) + supporting RFCs.
|
Package radius decodes RADIUS packets per RFC 2865 (auth) + RFC 2866 (accounting) + supporting RFCs. |
|
rag
Package rag provides lexical retrieval over the bundled PromptZero documentation corpus.
|
Package rag provides lexical retrieval over the bundled PromptZero documentation corpus. |
|
rdpx224
Package rdpx224 decodes the initial-handshake frames of Microsoft RDP (Remote Desktop Protocol) per [MS-RDPBCGR] — specifically the TPKT-wrapped X.224 (COTP) Connection Request / Connection Confirm PDUs plus the embedded RDP_NEG_REQ / RDP_NEG_RSP / RDP_NEG_FAILURE structures.
|
Package rdpx224 decodes the initial-handshake frames of Microsoft RDP (Remote Desktop Protocol) per [MS-RDPBCGR] — specifically the TPKT-wrapped X.224 (COTP) Connection Request / Connection Confirm PDUs plus the embedded RDP_NEG_REQ / RDP_NEG_RSP / RDP_NEG_FAILURE structures. |
|
redis
Package redis decodes Redis RESP (REdis Serialization Protocol) v2 + v3 messages per the Redis documentation.
|
Package redis decodes Redis RESP (REdis Serialization Protocol) v2 + v3 messages per the Redis documentation. |
|
report
Package report renders engagement reports from PromptZero session audit data.
|
Package report renders engagement reports from PromptZero session audit data. |
|
rip
Package rip decodes RIP (Routing Information Protocol) v1 and v2 wire-protocol messages per RFC 1058 (RIPv1) and RFC 2453 (RIPv2).
|
Package rip decodes RIP (Routing Information Protocol) v1 and v2 wire-protocol messages per RFC 1058 (RIPv1) and RFC 2453 (RIPv2). |
|
rsvpte
Package rsvpte decodes RSVP-TE (Resource Reservation Protocol — Traffic Engineering) packets per RFC 3209 (RSVP-TE extensions) and RFC 2205 (base RSVP).
|
Package rsvpte decodes RSVP-TE (Resource Reservation Protocol — Traffic Engineering) packets per RFC 3209 (RSVP-TE extensions) and RFC 2205 (base RSVP). |
|
rtmp
Package rtmp decodes RTMP (Real-Time Messaging Protocol) wire frames.
|
Package rtmp decodes RTMP (Real-Time Messaging Protocol) wire frames. |
|
rtp
Package rtp decodes RTP and RTCP packets per RFC 3550 (Real-time Transport Protocol) and the static payload type assignments of RFC 3551, plus the standard RTCP feedback extensions of RFC 4585 (RTPFB / PSFB) and RFC 3611 (XR).
|
Package rtp decodes RTP and RTCP packets per RFC 3550 (Real-time Transport Protocol) and the static payload type assignments of RFC 3551, plus the standard RTCP feedback extensions of RFC 4585 (RTPFB / PSFB) and RFC 3611 (XR). |
|
rtsp
Package rtsp decodes RTSP (Real-Time Streaming Protocol) messages per RFC 7826 (RTSP 2.0) and the more widely-deployed RFC 2326 (RTSP 1.0).
|
Package rtsp decodes RTSP (Real-Time Streaming Protocol) messages per RFC 7826 (RTSP 2.0) and the more widely-deployed RFC 2326 (RTSP 1.0). |
|
rules
Package rules is PromptZero's reactive rules engine.
|
Package rules is PromptZero's reactive rules engine. |
|
s7comm
Package s7comm decodes classic S7Comm PDUs — the Siemens S7- 300 / S7-400 / S7-1200 / S7-1500 PLC protocol that rides on ISO-on-TCP (RFC 1006, default TCP port 102).
|
Package s7comm decodes classic S7Comm PDUs — the Siemens S7- 300 / S7-400 / S7-1200 / S7-1500 PLC protocol that rides on ISO-on-TCP (RFC 1006, default TCP port 102). |
|
sctp
Package sctp decodes Stream Control Transmission Protocol (SCTP) packets per RFC 4960 (with the AUTH / ASCONF / RE-CONFIG / PAD / FORWARD-TSN chunk types from RFCs 4895 / 5061 / 6525 / 4820 / 3758).
|
Package sctp decodes Stream Control Transmission Protocol (SCTP) packets per RFC 4960 (with the AUTH / ASCONF / RE-CONFIG / PAD / FORWARD-TSN chunk types from RFCs 4895 / 5061 / 6525 / 4820 / 3758). |
|
semcache
Package semcache implements a small, durable, on-disk semantic cache for LLM-generated payloads (roadmap P2-27).
|
Package semcache implements a small, durable, on-disk semantic cache for LLM-generated payloads (roadmap P2-27). |
|
sflow
Package sflow decodes sFlow v5 datagrams per the InMon publicly-published sFlow v5 specification (sflow.org).
|
Package sflow decodes sFlow v5 datagrams per the InMon publicly-published sFlow v5 specification (sflow.org). |
|
sip
Package sip decodes SIP messages per RFC 3261.
|
Package sip decodes SIP messages per RFC 3261. |
|
smb2
Package smb2 decodes SMB2 / SMB3 (Server Message Block v2/v3) messages per [MS-SMB2] — the canonical Windows file-share and lateral-movement protocol.
|
Package smb2 decodes SMB2 / SMB3 (Server Message Block v2/v3) messages per [MS-SMB2] — the canonical Windows file-share and lateral-movement protocol. |
|
smtp
Package smtp decodes SMTP (Simple Mail Transfer Protocol) messages per RFC 5321 — the 40-year-old text-based protocol every mail server speaks.
|
Package smtp decodes SMTP (Simple Mail Transfer Protocol) messages per RFC 5321 — the 40-year-old text-based protocol every mail server speaks. |
|
snapshot
Package snapshot captures pre-write copies of Flipper SD files so /rewind can restore them on demand.
|
Package snapshot captures pre-write copies of Flipper SD files so /rewind can restore them on demand. |
|
snmp
Package snmp decodes SNMP v1, v2c, and v3 packets — the dominant network-management protocol on enterprise networks, found on every router / switch / firewall / printer / UPS / PDU / managed AP / managed VM-host since the late '80s.
|
Package snmp decodes SNMP v1, v2c, and v3 packets — the dominant network-management protocol on enterprise networks, found on every router / switch / firewall / printer / UPS / PDU / managed AP / managed VM-host since the late '80s. |
|
someip
Package someip decodes SOME/IP (Scalable service-Oriented MiddlewarE over IP) messages per the AUTOSAR R23-11 SOME/IP Protocol Specification (PRS_SOMEIPProtocol) and the parallel SOME/IP Service Discovery spec (PRS_SOMEIPServiceDiscoveryProtocol).
|
Package someip decodes SOME/IP (Scalable service-Oriented MiddlewarE over IP) messages per the AUTOSAR R23-11 SOME/IP Protocol Specification (PRS_SOMEIPProtocol) and the parallel SOME/IP Service Discovery spec (PRS_SOMEIPServiceDiscoveryProtocol). |
|
ssdp
Package ssdp decodes SSDP (Simple Service Discovery Protocol) messages per the UPnP Device Architecture 1.1 (UPnP Forum, 2008).
|
Package ssdp decodes SSDP (Simple Service Discovery Protocol) messages per the UPnP Device Architecture 1.1 (UPnP Forum, 2008). |
|
sshdecode
Package sshdecode parses SSH wire-protocol frames per RFC 4253 (SSH Transport Layer Protocol) and RFC 4250-4256.
|
Package sshdecode parses SSH wire-protocol frames per RFC 4253 (SSH Transport Layer Protocol) and RFC 4250-4256. |
|
stp
Package stp decodes Spanning Tree Protocol BPDUs per IEEE 802.1D-2004 (STP / RSTP) and IEEE 802.1Q-2014 §13 (MSTP).
|
Package stp decodes Spanning Tree Protocol BPDUs per IEEE 802.1D-2004 (STP / RSTP) and IEEE 802.1Q-2014 §13 (MSTP). |
|
streaming
Package streaming provides the partial-frame sink used by tools that opt into streaming dispatch (roadmap P3-28 first half).
|
Package streaming provides the partial-frame sink used by tools that opt into streaming dispatch (roadmap P3-28 first half). |
|
stun
Package stun decodes STUN packets per RFC 5389 / 8489 + TURN extensions per RFC 5766 / 8656.
|
Package stun decodes STUN packets per RFC 5389 / 8489 + TURN extensions per RFC 5766 / 8656. |
|
subghz
Package subghz provides pure-Go classifiers for common Sub-GHz radio protocols captured by the Flipper Zero.
|
Package subghz provides pure-Go classifiers for common Sub-GHz radio protocols captured by the Flipper Zero. |
|
subghz/protocols
Package protocols implements pure-Go decoders for the top-20 Sub-GHz remote control protocols captured by the Flipper Zero.
|
Package protocols implements pure-Go decoders for the top-20 Sub-GHz remote control protocols captured by the Flipper Zero. |
|
syslog
Package syslog decodes syslog messages in both the modern RFC 5424 (IETF) format and the legacy RFC 3164 (BSD) format.
|
Package syslog decodes syslog messages in both the modern RFC 5424 (IETF) format and the legacy RFC 3164 (BSD) format. |
|
tacacs
Package tacacs decodes TACACS+ packets per RFC 8907 (which finally documented the Cisco-proprietary protocol after decades of use in production).
|
Package tacacs decodes TACACS+ packets per RFC 8907 (which finally documented the Cisco-proprietary protocol after decades of use in production). |
|
targetmem
Package targetmem stores per-target facts across PromptZero sessions.
|
Package targetmem stores per-target facts across PromptZero sessions. |
|
tds
Package tds decodes TDS (Tabular Data Stream) messages per Microsoft Open Specifications [MS-TDS] — the Microsoft SQL Server protocol.
|
Package tds decodes TDS (Tabular Data Stream) messages per Microsoft Open Specifications [MS-TDS] — the Microsoft SQL Server protocol. |
|
testmocks
Package testmocks centralises the shared mock harness used across PromptZero's test surfaces — flipper-agent tests, end-to-end REPL tests, workflow tests.
|
Package testmocks centralises the shared mock harness used across PromptZero's test surfaces — flipper-agent tests, end-to-end REPL tests, workflow tests. |
|
tftp
Package tftp decodes TFTP (Trivial File Transfer Protocol) packets per RFC 1350, with the Option Extension family from RFC 2347 (envelope) + RFC 2348 (blksize) + RFC 2349 (timeout + tsize) + RFC 7440 (windowsize).
|
Package tftp decodes TFTP (Trivial File Transfer Protocol) packets per RFC 1350, with the Option Extension family from RFC 2347 (envelope) + RFC 2348 (blksize) + RFC 2349 (timeout + tsize) + RFC 7440 (windowsize). |
|
tlsdecode
Package tlsdecode decodes the cleartext portion of a TLS handshake — the ClientHello and ServerHello records that every TLS connection emits in the clear before encryption is negotiated.
|
Package tlsdecode decodes the cleartext portion of a TLS handshake — the ClientHello and ServerHello records that every TLS connection emits in the clear before encryption is negotiated. |
|
toolctx
Package toolctx serves static per-tool cheat sheets the agent appends to tool descriptions at catalog registration time.
|
Package toolctx serves static per-tool cheat sheets the agent appends to tool descriptions at catalog registration time. |
|
tools
Package tools — argument-extraction helpers.
|
Package tools — argument-extraction helpers. |
|
trainset
Package trainset exports the audit log as a fine-tuning dataset.
|
Package trainset exports the audit log as a fine-tuning dataset. |
|
usbhid
Package usbhid decodes USB HID Keyboard Boot Protocol reports — the 8-byte input reports that every BadUSB-class device (Hak5 Rubber Ducky, Bash Bunny, OMG Cable, Adafruit Trinket BadUSB, the Bruce ESP32 BadUSB add-on) generates to inject keystrokes into a victim host.
|
Package usbhid decodes USB HID Keyboard Boot Protocol reports — the 8-byte input reports that every BadUSB-class device (Hak5 Rubber Ducky, Bash Bunny, OMG Cable, Adafruit Trinket BadUSB, the Bruce ESP32 BadUSB add-on) generates to inject keystrokes into a victim host. |
|
validator
Package validator scans BadUSB/DuckyScript payloads for patterns that the operator would want to see before the Flipper types them on a real target.
|
Package validator scans BadUSB/DuckyScript payloads for patterns that the operator would want to see before the Flipper types them on a real target. |
|
version
Package version carries build-time metadata embedded via -ldflags.
|
Package version carries build-time metadata embedded via -ldflags. |
|
vlan
Package vlan decodes IEEE 802.1Q (C-tag) and 802.1ad (S-tag, QinQ) VLAN tags per IEEE 802.1Q-2018.
|
Package vlan decodes IEEE 802.1Q (C-tag) and 802.1ad (S-tag, QinQ) VLAN tags per IEEE 802.1Q-2018. |
|
vncrfb
Package vncrfb decodes VNC RFB (Remote Framebuffer) Protocol handshake messages per RFC 6143 plus the RealVNC / TightVNC / VeNCrypt / Apple ARD extensions.
|
Package vncrfb decodes VNC RFB (Remote Framebuffer) Protocol handshake messages per RFC 6143 plus the RealVNC / TightVNC / VeNCrypt / Apple ARD extensions. |
|
vrrp
Package vrrp decodes Virtual Router Redundancy Protocol (VRRP) packets per RFC 5798 (v3, IPv4 + IPv6) and the older RFC 3768 (v2, IPv4-only, still widely deployed).
|
Package vrrp decodes Virtual Router Redundancy Protocol (VRRP) packets per RFC 5798 (v3, IPv4 + IPv6) and the older RFC 3768 (v2, IPv4-only, still widely deployed). |
|
vxlan
Package vxlan decodes Virtual Extensible LAN packets per RFC 7348, plus per-vendor variants: Cisco's Group-Based Policy (VXLAN-GBP, draft-smith-vxlan-group-policy) and the Generic Protocol Extension (VXLAN-GPE, draft-ietf-nvo3- vxlan-gpe).
|
Package vxlan decodes Virtual Extensible LAN packets per RFC 7348, plus per-vendor variants: Cisco's Group-Based Policy (VXLAN-GBP, draft-smith-vxlan-group-policy) and the Generic Protocol Extension (VXLAN-GPE, draft-ietf-nvo3- vxlan-gpe). |
|
watch
Package watch implements the --watch filesystem-trigger mode.
|
Package watch implements the --watch filesystem-trigger mode. |
|
web
Marauder synth-panel WebSocket layer.
|
Marauder synth-panel WebSocket layer. |
|
webhook
Package webhook dispatches PromptZero lifecycle events as outbound HTTP POSTs.
|
Package webhook dispatches PromptZero lifecycle events as outbound HTTP POSTs. |
|
wireguard
Package wireguard decodes WireGuard UDP packets per the official protocol specification at https://www.wireguard.com/protocol/.
|
Package wireguard decodes WireGuard UDP packets per the official protocol specification at https://www.wireguard.com/protocol/. |
|
wordlists
Package wordlists embeds PromptZero's built-in wordlists and exposes them as MCP resources via promptzero://wordlists/<name> URIs.
|
Package wordlists embeds PromptZero's built-in wordlists and exposes them as MCP resources via promptzero://wordlists/<name> URIs. |
|
workflows
Package workflows implements composite pentest flows that orchestrate several Flipper primitives + LLM reasoning behind a single LLM-callable tool.
|
Package workflows implements composite pentest flows that orchestrate several Flipper primitives + LLM reasoning behind a single LLM-callable tool. |
|
wsframe
Package wsframe decodes WebSocket frames per RFC 6455.
|
Package wsframe decodes WebSocket frames per RFC 6455. |
|
x509decode
Package x509decode parses X.509 certificates into a structured view — the natural complement to tls_handshake_decode (whose Certificate handshake-message body is surfaced as raw hex).
|
Package x509decode parses X.509 certificates into a structured view — the natural complement to tls_handshake_decode (whose Certificate handshake-message body is surfaced as raw hex). |
|
xmpp
Package xmpp decodes XMPP (Extensible Messaging and Presence Protocol) wire-protocol stanzas per RFC 6120 (core) and RFC 6121 (IM).
|
Package xmpp decodes XMPP (Extensible Messaging and Presence Protocol) wire-protocol stanzas per RFC 6120 (core) and RFC 6121 (IM). |
|
zigbee
Package zigbee decodes Zigbee Network Layer (NWK) frames — the layer that sits on top of IEEE 802.15.4 MAC frames in the Zigbee stack.
|
Package zigbee decodes Zigbee Network Layer (NWK) frames — the layer that sits on top of IEEE 802.15.4 MAC frames in the Zigbee stack. |
|
zmtp
Package zmtp decodes ZMTP (ZeroMQ Message Transport Protocol) wire frames — the transport layer for every ZeroMQ socket.
|
Package zmtp decodes ZMTP (ZeroMQ Message Transport Protocol) wire frames — the transport layer for every ZeroMQ socket. |
|
zwave
Package zwave decodes classic Z-Wave MAC-layer frames per the Sigma Designs / Silicon Labs public specification (SDS-12852, Z-Wave Public API + Z-Wave Plus / 700/800-series protocol reference).
|
Package zwave decodes classic Z-Wave MAC-layer frames per the Sigma Designs / Silicon Labs public specification (SDS-12852, Z-Wave Public API + Z-Wave Plus / 700/800-series protocol reference). |
|
test
|
|
|
adversarial
Package adversarial holds the cross-package adversarial test suite (roadmap P3-30).
|
Package adversarial holds the cross-package adversarial test suite (roadmap P3-30). |
Click to show internal directories.
Click to hide internal directories.