Directories
¶
| Path | Synopsis |
|---|---|
|
cmd
|
|
|
_devvalidate
command
Command _devvalidate is a read-only, LLM-free validation harness for a physically-connected Flipper Zero.
|
Command _devvalidate is a read-only, LLM-free validation harness for a physically-connected Flipper Zero. |
|
_marvalidate
command
Command _marvalidate is a read-only / benign validation harness for a physically-connected ESP32 Marauder devboard.
|
Command _marvalidate is a read-only / benign validation harness for a physically-connected ESP32 Marauder devboard. |
|
cliprobe
command
cliprobe: minimal pty driver that sends ONE prompt and dumps every byte the CLI emits for 60s.
|
cliprobe: minimal pty driver that sends ONE prompt and dumps every byte the CLI emits for 60s. |
|
clitest
command
clitest spawns `promptzero` in REPL mode under a pty (because the REPL refuses to enter raw mode without a TTY) and drives a few non-LLM slash commands to verify the CLI plumbing works end-to-end: banner prints, /help renders, /quit exits cleanly.
|
clitest spawns `promptzero` in REPL mode under a pty (because the REPL refuses to enter raw mode without a TTY) and drives a few non-LLM slash commands to verify the CLI plumbing works end-to-end: banner prints, /help renders, /quit exits cleanly. |
|
cliyolo
command
cliyolo drives the promptzero REPL through a pty with a curated set of natural-language prompts to exercise every non-destructive Flipper subsystem.
|
cliyolo drives the promptzero REPL through a pty with a curated set of natural-language prompts to exercise every non-destructive Flipper subsystem. |
|
coverage-diff
command
cmd/coverage-diff scrapes the awesome-flipperzero upstream lists for tool/verb names and cross-references them against PromptZero's registered tool registry (internal/tools).
|
cmd/coverage-diff scrapes the awesome-flipperzero upstream lists for tool/verb names and cross-references them against PromptZero's registered tool registry (internal/tools). |
|
flipper-usecases
command
Command flipper-usecases runs realistic operator tasks against a live Flipper Zero and reports pass/fail + concise summaries.
|
Command flipper-usecases runs realistic operator tasks against a live Flipper Zero and reports pass/fail + concise summaries. |
|
flipper-validate
command
flipper-validate is an integration harness that exercises Flipper wrapper methods against a live device over serial.
|
flipper-validate is an integration harness that exercises Flipper wrapper methods against a live device over serial. |
|
hwtest
command
hwtest is a developer-only smoke harness that drives a real Flipper Zero (and optional Marauder) over MCP.
|
hwtest is a developer-only smoke harness that drives a real Flipper Zero (and optional Marauder) over MCP. |
|
marauder-validate
command
marauder-validate is an integration harness that exercises the safe read/RX/inspection subset of Marauder wrapper methods against a live ESP32 Marauder devboard over USB serial.
|
marauder-validate is an integration harness that exercises the safe read/RX/inspection subset of Marauder wrapper methods against a live ESP32 Marauder devboard over USB serial. |
|
mifaretest
command
mifaretest exercises the realistic Mifare workflow against a tag held to the real Flipper: detect → inspect existing fixtures → dump protocol → save a UID-only file → diff vs an existing file → edit → emulate → cleanup.
|
mifaretest exercises the realistic Mifare workflow against a tag held to the real Flipper: detect → inspect existing fixtures → dump protocol → save a UID-only file → diff vs an existing file → edit → emulate → cleanup. |
|
promptzero
command
|
|
|
pzrunner
command
pzrunner is a non-interactive harness that drives the promptzero Agent end-to-end over a real Flipper.
|
pzrunner is a non-interactive harness that drives the promptzero Agent end-to-end over a real Flipper. |
|
webtest
command
webtest spawns `promptzero --web` against a real Flipper, then drives every HTTP API endpoint and the websocket handshake to confirm the public web surface is wired correctly.
|
webtest spawns `promptzero --web` against a real Flipper, then drives every HTTP API endpoint and the websocket handshake to confirm the public web surface is wired correctly. |
|
internal
|
|
|
adsb
Package adsb decodes Mode S downlink frames captured at 1090 MHz — both short-form (56-bit) surveillance replies and long-form (112-bit) extended squitter / ADS-B frames.
|
Package adsb decodes Mode S downlink frames captured at 1090 MHz — both short-form (56-bit) surveillance replies and long-form (112-bit) extended squitter / ADS-B frames. |
|
ais
Package ais decodes AIS (Automatic Identification System) NMEA 0183 sentences carried over the standard AIS VHF channels (161.975 / 162.025 MHz) — the maritime counterpart of ADS-B, mandatory on commercial vessels >300 GT and on most passenger ships under SOLAS Chapter V.
|
Package ais decodes AIS (Automatic Identification System) NMEA 0183 sentences carried over the standard AIS VHF channels (161.975 / 162.025 MHz) — the maritime counterpart of ADS-B, mandatory on commercial vessels >300 GT and on most passenger ships under SOLAS Chapter V. |
|
altbeacon
Package altbeacon decodes and builds AltBeacon BLE advertisements — the open, vendor-neutral beacon standard (github.com/AltBeacon/spec), the counterpart to Apple iBeacon and Google Eddystone.
|
Package altbeacon decodes and builds AltBeacon BLE advertisements — the open, vendor-neutral beacon standard (github.com/AltBeacon/spec), the counterpart to Apple iBeacon and Google Eddystone. |
|
amqp091
Package amqp091 decodes AMQP 0-9-1 wire-protocol frames per the AMQP 0-9-1 specification.
|
Package amqp091 decodes AMQP 0-9-1 wire-protocol frames per the AMQP 0-9-1 specification. |
|
aoe
Package aoe decodes ATA over Ethernet (AoE, EtherType 0x88A2) — the CORAID protocol that exposes raw ATA disk commands directly over an Ethernet segment.
|
Package aoe decodes ATA over Ethernet (AoE, EtherType 0x88A2) — the CORAID protocol that exposes raw ATA disk commands directly over an Ethernet segment. |
|
applecontinuity
Package applecontinuity decodes Apple Continuity BLE advertisement payloads — the Manufacturer-Specific-Data blob Apple devices broadcast for Handoff, AirDrop, Nearby Info / Action, AirPods proximity pairing, iBeacon, Hey Siri, and the other ad-hoc connectivity primitives that make the Apple ecosystem feel "magical" on a sniffer.
|
Package applecontinuity decodes Apple Continuity BLE advertisement payloads — the Manufacturer-Specific-Data blob Apple devices broadcast for Handoff, AirDrop, Nearby Info / Action, AirPods proximity pairing, iBeacon, Hey Siri, and the other ad-hoc connectivity primitives that make the Apple ecosystem feel "magical" on a sniffer. |
|
aprs
Package aprs decodes APRS (Automatic Packet Reporting System) frames carried over AX.25 — the dominant ham-radio position + telemetry + messaging beacon family transmitted on 144.39 MHz (NA), 144.80 MHz (EU), and a handful of HF bands.
|
Package aprs decodes APRS (Automatic Packet Reporting System) frames carried over AX.25 — the dominant ham-radio position + telemetry + messaging beacon family transmitted on 144.39 MHz (NA), 144.80 MHz (EU), and a handful of HF bands. |
|
arpdecode
Package arpdecode decodes Address Resolution Protocol (ARP) and Reverse ARP (RARP) packets per RFC 826 + RFC 903 + the RFC 5227 IPv4 address-conflict-detection extensions (gratuitous ARP / ARP probe / ARP announcement).
|
Package arpdecode decodes Address Resolution Protocol (ARP) and Reverse ARP (RARP) packets per RFC 826 + RFC 903 + the RFC 5227 IPv4 address-conflict-detection extensions (gratuitous ARP / ARP probe / ARP announcement). |
|
att
Package att decodes the Bluetooth Attribute Protocol (ATT, Core spec Vol 3 Part F) — the request/response protocol behind GATT, carried on L2CAP CID 0x0004.
|
Package att decodes the Bluetooth Attribute Protocol (ATT, Core spec Vol 3 Part F) — the request/response protocol behind GATT, carried on L2CAP CID 0x0004. |
|
attack
Package attack maps PromptZero tools and workflows to MITRE ATT&CK techniques.
|
Package attack maps PromptZero tools and workflows to MITRE ATT&CK techniques. |
|
awskey
Package awskey decodes an AWS access key ID (AKIA…/ASIA…/AROA… — the 20-char unique IDs AWS issues for keys, roles, users, and policies) into the **AWS account ID** bit-packed inside it and the **credential type**.
|
Package awskey decodes an AWS access key ID (AKIA…/ASIA…/AROA… — the 20-char unique IDs AWS issues for keys, roles, users, and policies) into the **AWS account ID** bit-packed inside it and the **credential type**. |
|
azuresas
Package azuresas decodes an Azure Storage Shared Access Signature (SAS) token — the `?sv=…&sp=…&se=…&sig=…` query string that grants delegated access to Azure Blob / Queue / Table / File storage — into its **blast radius**: the SAS type, the granted permissions (expanded to human operations), the validity window (start / expiry), the scope (service / resource type / resource), the allowed IP range and protocol, and any stored-access-policy reference.
|
Package azuresas decodes an Azure Storage Shared Access Signature (SAS) token — the `?sv=…&sp=…&se=…&sig=…` query string that grants delegated access to Azure Blob / Queue / Table / File storage — into its **blast radius**: the SAS type, the granted permissions (expanded to human operations), the validity window (start / expiry), the scope (service / resource type / resource), the allowed IP range and protocol, and any stored-access-policy reference. |
|
bacnet
Package bacnet decodes BACnet/IP (BACnet over UDP, ASHRAE 135 Annex J) frames — the dominant building-automation protocol used in HVAC controllers, lighting panels, energy meters, fire-alarm gateways, elevator dispatch, and BMS (Building Management Systems) front-ends.
|
Package bacnet decodes BACnet/IP (BACnet over UDP, ASHRAE 135 Annex J) frames — the dominant building-automation protocol used in HVAC controllers, lighting panels, energy meters, fire-alarm gateways, elevator dispatch, and BMS (Building Management Systems) front-ends. |
|
badusb
Package badusb parses DuckyScript / BadUSB payload scripts into structured line-by-line views — command + arguments + validation status.
|
Package badusb parses DuckyScript / BadUSB payload scripts into structured line-by-line views — command + arguments + validation status. |
|
base58check
Package base58check decodes a Base58Check string — the encoding Bitcoin (and many forks / chains) use for WIF private keys, legacy addresses, and BIP-32 extended keys — into its version, payload, and checksum validity, and identifies the artifact type.
|
Package base58check decodes a Base58Check string — the encoding Bitcoin (and many forks / chains) use for WIF private keys, legacy addresses, and BIP-32 extended keys — into its version, payload, and checksum validity, and identifies the artifact type. |
|
bcbp
Package bcbp decodes an IATA Bar Coded Boarding Pass (Resolution 792) — the text string encoded in the PDF417 / Aztec / QR barcode on a boarding pass.
|
Package bcbp decodes an IATA Bar Coded Boarding Pass (Resolution 792) — the text string encoded in the PDF417 / Aztec / QR barcode on a boarding pass. |
|
bech32
Package bech32 decodes a Bech32 / Bech32m string — the encoding modern Bitcoin uses for SegWit addresses (bc1…/tb1…), and which Nostr (npub/nsec/note), Lightning (lnbc…), and Cosmos-family chains also use — into its human-readable prefix (HRP), data payload, and checksum variant, and interprets SegWit addresses (witness version + program + type).
|
Package bech32 decodes a Bech32 / Bech32m string — the encoding modern Bitcoin uses for SegWit addresses (bc1…/tb1…), and which Nostr (npub/nsec/note), Lightning (lnbc…), and Cosmos-family chains also use — into its human-readable prefix (HRP), data payload, and checksum variant, and interprets SegWit addresses (witness version + program + type). |
|
bfd
Package bfd decodes BFD Control packets per RFC 5880.
|
Package bfd decodes BFD Control packets per RFC 5880. |
|
bgp
Package bgp decodes BGP-4 messages per RFC 4271 plus the canonical extensions: RFC 4760 (Multiprotocol BGP / MP-BGP), RFC 5492 (Capabilities Optional Parameter), RFC 6793 (4-byte AS Number), and RFC 2918 / 7313 (Route Refresh).
|
Package bgp decodes BGP-4 messages per RFC 4271 plus the canonical extensions: RFC 4760 (Multiprotocol BGP / MP-BGP), RFC 5492 (Capabilities Optional Parameter), RFC 6793 (4-byte AS Number), and RFC 2918 / 7313 (Route Refresh). |
|
bip39
Package bip39 validates and decodes a BIP-39 mnemonic — the 12/15/18/21/24-word "seed phrase" used by virtually every cryptocurrency wallet (Bitcoin, Ethereum, hardware wallets) — into its entropy, checksum validity, word indices, and the derived BIP-39 seed.
|
Package bip39 validates and decodes a BIP-39 mnemonic — the 12/15/18/21/24-word "seed phrase" used by virtually every cryptocurrency wallet (Bitcoin, Ethereum, hardware wallets) — into its entropy, checksum validity, word indices, and the derived BIP-39 seed. |
|
ble
Package ble decodes BLE advertisement payloads — currently just Apple Continuity manufacturer-data — into operator-facing structures.
|
Package ble decodes BLE advertisement payloads — currently just Apple Continuity manufacturer-data — into operator-facing structures. |
|
bleadv
Package bleadv decodes a Bluetooth advertising / scan-response payload — the GAP "AD structure" list (Bluetooth Core Specification, Vol 3 Part C §11, and the Core Specification Supplement / Assigned Numbers).
|
Package bleadv decodes a Bluetooth advertising / scan-response payload — the GAP "AD structure" list (Bluetooth Core Specification, Vol 3 Part C §11, and the Core Specification Supplement / Assigned Numbers). |
|
breaker
Package breaker implements a per-tool consecutive-error circuit breaker (roadmap P3-28, second half).
|
Package breaker implements a per-tool consecutive-error circuit breaker (roadmap P3-28, second half). |
|
bruce
Package bruce interfaces with the Bruce pentesting firmware for ESP32-based boards over a USB-serial connection.
|
Package bruce interfaces with the Bruce pentesting firmware for ESP32-based boards over a USB-serial connection. |
|
bson
Package bson decodes a BSON document (the binary serialization MongoDB stores and that `mongodump` writes to `.bson` files) into a structured tree.
|
Package bson decodes a BSON document (the binary serialization MongoDB stores and that `mongodump` writes to `.bson` files) into a structured tree. |
|
btclassic
Package btclassic decodes Bluetooth Classic (BR/EDR) metadata fields — primarily the 24-bit Class of Device (CoD) value that every classic Bluetooth device advertises during inquiry.
|
Package btclassic decodes Bluetooth Classic (BR/EDR) metadata fields — primarily the 24-bit Class of Device (CoD) value that every classic Bluetooth device advertises during inquiry. |
|
btoob
Package btoob decodes Bluetooth Out-Of-Band (OOB) pairing records — the "tap-to-pair" payload carried by an NFC handover tag and the Bluetooth Secure Simple Pairing OOB data block.
|
Package btoob decodes Bluetooth Out-Of-Band (OOB) pairing records — the "tap-to-pair" payload carried by an NFC handover tag and the Bluetooth Secure Simple Pairing OOB data block. |
|
btuuid
Package btuuid resolves Bluetooth SIG-assigned 16-bit GATT UUIDs (Services, Characteristics, Descriptors) to their canonical names.
|
Package btuuid resolves Bluetooth SIG-assigned 16-bit GATT UUIDs (Services, Characteristics, Descriptors) to their canonical names. |
|
buspirate
Package buspirate is the PromptZero backend for the Bus Pirate 5 universal bus probe (RP2040-based).
|
Package buspirate is the PromptZero backend for the Bus Pirate 5 universal bus probe (RP2040-based). |
|
campaign
Package campaign implements the PromptZero Campaigns feature (roadmap P2-19) — declarative, YAML-authored multi-step engagement specs that compose the existing agent tool surface.
|
Package campaign implements the PromptZero Campaigns feature (roadmap P2-19) — declarative, YAML-authored multi-step engagement specs that compose the existing agent tool surface. |
|
canfd
Package canfd decodes a captured CAN / CAN-FD frame in the SocketCAN candump text representation into its structured fields — the format-independent signal an automotive pentester reads off a bus capture without the bus attached.
|
Package canfd decodes a captured CAN / CAN-FD frame in the SocketCAN candump text representation into its structured fields — the format-independent signal an automotive pentester reads off a bus capture without the bus attached. |
|
carp
Package carp decodes the Common Address Redundancy Protocol — the open first-hop-redundancy protocol (FHRP) used by OpenBSD, FreeBSD and pfSense / OPNsense for gateway / firewall high availability.
|
Package carp decodes the Common Address Redundancy Protocol — the open first-hop-redundancy protocol (FHRP) used by OpenBSD, FreeBSD and pfSense / OPNsense for gateway / firewall high availability. |
|
cassandra
Package cassandra decodes Apache Cassandra CQL binary protocol frames.
|
Package cassandra decodes Apache Cassandra CQL binary protocol frames. |
|
cbordecode
Package cbordecode parses CBOR (Concise Binary Object Representation) per RFC 8949.
|
Package cbordecode parses CBOR (Concise Binary Object Representation) per RFC 8949. |
|
ccache
Package ccache parses an MIT Kerberos credential cache (the binary FILE: ccache format, version 0x0504) into its default principal and stored credentials — the client / server principals, ticket flags, validity times, session key, and the embedded ticket bytes.
|
Package ccache parses an MIT Kerberos credential cache (the binary FILE: ccache format, version 0x0504) into its default principal and stored credentials — the client / server principals, ticket flags, validity times, session key, and the embedded ticket bytes. |
|
ccp
Package ccp decodes CCP — the CAN Calibration Protocol (ASAM) — the CAN-native predecessor of XCP that an ECU calibration tool uses to read and write an ECU's memory: connect to a station, characterise (DAQ) measurement, download calibration data, and flash (PROGRAM).
|
Package ccp decodes CCP — the CAN Calibration Protocol (ASAM) — the CAN-native predecessor of XCP that an ECU calibration tool uses to read and write an ECU's memory: connect to a station, characterise (DAQ) measurement, download calibration data, and flash (PROGRAM). |
|
cdp
Package cdp decodes Cisco Discovery Protocol packets per the publicly-documented wire format (reverse-engineered and documented in Wireshark dissectors, tcpdump output, and the CDP protocol whitepapers Cisco has historically published).
|
Package cdp decodes Cisco Discovery Protocol packets per the publicly-documented wire format (reverse-engineered and documented in Wireshark dissectors, tcpdump output, and the CDP protocol whitepapers Cisco has historically published). |
|
checksum
Package checksum computes and identifies the common NON-CRC frame checksums — plain modular sums, XOR/LRC, the Modbus two's-complement LRC, and the Fletcher checksums.
|
Package checksum computes and identifies the common NON-CRC frame checksums — plain modular sums, XOR/LRC, the Modbus two's-complement LRC, and the Fletcher checksums. |
|
ciscopw
Package ciscopw decodes Cisco IOS "type 7" passwords — the weak, reversible obfuscation produced by `service password-encryption`, ubiquitous in router and switch configuration loot.
|
Package ciscopw decodes Cisco IOS "type 7" passwords — the weak, reversible obfuscation produced by `service password-encryption`, ubiquitous in router and switch configuration loot. |
|
clisafe
Package clisafe contains helpers shared by every transport that pushes operator-supplied strings through a line-oriented CLI.
|
Package clisafe contains helpers shared by every transport that pushes operator-supplied strings through a line-oriented CLI. |
|
coap
Package coap decodes Constrained Application Protocol (RFC 7252) packets — the application-layer protocol used by constrained IoT devices (6LoWPAN, Thread, OpenThread, Zigbee IP).
|
Package coap decodes Constrained Application Protocol (RFC 7252) packets — the application-layer protocol used by constrained IoT devices (6LoWPAN, Thread, OpenThread, Zigbee IP). |
|
confidence
Package confidence provides pre-dispatch heuristic scoring for tool-use inputs.
|
Package confidence provides pre-dispatch heuristic scoring for tool-use inputs. |
|
consensus
Package consensus implements ensemble voting over multi-model risk verdicts (roadmap P3-33).
|
Package consensus implements ensemble voting over multi-model risk verdicts (roadmap P3-33). |
|
containerbridge
Package containerbridge runs external CLI tools inside Docker containers and surfaces their output as Go values.
|
Package containerbridge runs external CLI tools inside Docker containers and surfaces their output as Go values. |
|
cost
Package cost tracks Anthropic token usage and running dollar cost per PromptZero session, and implements the simple "consecutive errors → offline" heuristic that flips the observability offline banner.
|
Package cost tracks Anthropic token usage and running dollar cost per PromptZero session, and implements the simple "consecutive errors → offline" heuristic that flips the observability offline banner. |
|
crc
Package crc computes and identifies cyclic redundancy checks against the standard CRC catalogue (the parameters Greg Cook's reveng catalogue publishes).
|
Package crc computes and identifies cyclic redundancy checks against the standard CRC catalogue (the parameters Greg Cook's reveng catalogue publishes). |
|
crypto1
Package crypto1 is the pure-Go implementation of the Crypto1 stream cipher used by MIFARE Classic and some HID iCLASS legacy systems.
|
Package crypto1 is the pure-Go implementation of the Crypto1 stream cipher used by MIFARE Classic and some HID iCLASS legacy systems. |
|
cyfral
Package cyfral decodes a Cyfral iButton frame — the contact-key format used by Cyfral intercom systems (common across the former-CIS / Eastern-European residential market).
|
Package cyfral decodes a Cyfral iButton frame — the contact-key format used by Cyfral intercom systems (common across the former-CIS / Eastern-European residential market). |
|
dcc2
Package dcc2 implements Domain Cached Credentials v2 (DCC2 / MS-Cache v2 / mscash2, hashcat mode 2100): the format Windows (Vista / Server 2008+) uses to cache domain logons locally, dumped from a compromised workstation's SECURITY registry hive (HKLM\SECURITY\Cache, e.g.
|
Package dcc2 implements Domain Cached Credentials v2 (DCC2 / MS-Cache v2 / mscash2, hashcat mode 2100): the format Windows (Vista / Server 2008+) uses to cache domain logons locally, dumped from a compromised workstation's SECURITY registry hive (HKLM\SECURITY\Cache, e.g. |
|
dccp
Package dccp decodes DCCP (Datagram Congestion Control Protocol) packets per RFC 4340.
|
Package dccp decodes DCCP (Datagram Congestion Control Protocol) packets per RFC 4340. |
|
dcerpc
Package dcerpc decodes DCE/RPC (Distributed Computing Environment / Remote Procedure Call) messages per DCE 1.1 + [MS-RPCE] — the Microsoft RPC framing layer that carries nearly every Windows AD attack chain.
|
Package dcerpc decodes DCE/RPC (Distributed Computing Environment / Remote Procedure Call) messages per DCE 1.1 + [MS-RPCE] — the Microsoft RPC framing layer that carries nearly every Windows AD attack chain. |
|
dcf77
Package dcf77 decodes DCF77 time-signal frames — the long-wave (77.5 kHz) radio broadcast from Mainflingen, Germany, that carries the current Central European time + date.
|
Package dcf77 decodes DCF77 time-signal frames — the long-wave (77.5 kHz) radio broadcast from Mainflingen, Germany, that carries the current Central European time + date. |
|
debruijn
Package debruijn generates binary de Bruijn sequences B(2,n) — the optimal bit stream for brute-forcing fixed-code (non-rolling) receivers.
|
Package debruijn generates binary de Bruijn sequences B(2,n) — the optimal bit stream for brute-forcing fixed-code (non-rolling) receivers. |
|
defense
Package defense provides passive RF / BLE detection helpers used to surface adversarial activity nearby — the blue-team complement to PromptZero's offensive capability set.
|
Package defense provides passive RF / BLE detection helpers used to surface adversarial activity nearby — the blue-team complement to PromptZero's offensive capability set. |
|
desfire
Package desfire decodes Mifare DESFire Application Identifiers (AIDs) — the 3-byte values returned by the DESFire GetApplicationIDs command that identify each application stored on the card.
|
Package desfire decodes Mifare DESFire Application Identifiers (AIDs) — the 3-byte values returned by the DESFire GetApplicationIDs command that identify each application stored on the card. |
|
dhcp
Package dhcp decodes DHCPv4 packets per RFC 2131 (the envelope) + RFC 2132 (the options).
|
Package dhcp decodes DHCPv4 packets per RFC 2131 (the envelope) + RFC 2132 (the options). |
|
dhcpv6
Package dhcpv6 decodes DHCPv6 packets per RFC 8415 (which consolidates RFC 3315 + RFC 3633 prefix delegation + RFC 3646 DNS configuration + RFC 4242 information refresh time + RFC 7083 rapid-commit / unicast updates into one current spec).
|
Package dhcpv6 decodes DHCPv6 packets per RFC 8415 (which consolidates RFC 3315 + RFC 3633 prefix delegation + RFC 3646 DNS configuration + RFC 4242 information refresh time + RFC 7083 rapid-commit / unicast updates into one current spec). |
|
diameter
Package diameter decodes Diameter packets per RFC 6733 (the current Diameter Base Protocol — supersedes RFC 3588).
|
Package diameter decodes Diameter packets per RFC 6733 (the current Diameter Base Protocol — supersedes RFC 3588). |
|
diff
Package diff renders a `git diff --no-prefix`-style unified-diff string from two text inputs.
|
Package diff renders a `git diff --no-prefix`-style unified-diff string from two text inputs. |
|
dnp3
Package dnp3 decodes DNP3 (Distributed Network Protocol 3) frames per IEEE 1815-2012.
|
Package dnp3 decodes DNP3 (Distributed Network Protocol 3) frames per IEEE 1815-2012. |
|
dnsdecode
Package dnsdecode parses DNS messages on the wire — the most-traffic-bearing UDP protocol on the internet and a staple of every blue-team / red-team / network-debugging workflow.
|
Package dnsdecode parses DNS messages on the wire — the most-traffic-bearing UDP protocol on the internet and a staple of every blue-team / red-team / network-debugging workflow. |
|
doip
Package doip decodes DoIP — Diagnostics over Internet Protocol (ISO 13400) — the Ethernet/IP transport that carries vehicle diagnostics (UDS) in modern cars, replacing the OBD-II-over-CAN link.
|
Package doip decodes DoIP — Diagnostics over Internet Protocol (ISO 13400) — the Ethernet/IP transport that carries vehicle diagnostics (UDS) in modern cars, replacing the OBD-II-over-CAN link. |
|
droneid
Package droneid decodes ASTM F3411-22 (a.k.a.
|
Package droneid decodes ASTM F3411-22 (a.k.a. |
|
dsmr
Package dsmr decodes a DSMR / P1 smart-meter telegram — the ASCII data stream a Dutch/Belgian (and increasingly EU) smart electricity/gas meter pushes out of its P1 customer port every second.
|
Package dsmr decodes a DSMR / P1 smart-meter telegram — the ASCII data stream a Dutch/Belgian (and increasingly EU) smart electricity/gas meter pushes out of its P1 customer port every second. |
|
dtls
Package dtls decodes Datagram Transport Layer Security records and handshake messages per RFC 6347 (DTLS 1.2) and RFC 9147 (DTLS 1.3 — unified header form is not supported here; we decode the legacy DTLS 1.3 record layer that uses the same 13-byte header as 1.2).
|
Package dtls decodes Datagram Transport Layer Security records and handshake messages per RFC 6347 (DTLS 1.2) and RFC 9147 (DTLS 1.3 — unified header form is not supported here; we decode the legacy DTLS 1.3 record layer that uses the same 13-byte header as 1.2). |
|
dtp
Package dtp decodes Cisco's Dynamic Trunking Protocol — the Layer-2 protocol a Cisco switch port uses to negotiate whether a link becomes an 802.1Q/ISL trunk.
|
Package dtp decodes Cisco's Dynamic Trunking Protocol — the Layer-2 protocol a Cisco switch port uses to negotiate whether a link becomes an 802.1Q/ISL trunk. |
|
eapol
Package eapol decodes EAPOL-Key frames — the WPA / WPA2 / WPA3 4-way handshake frames captured from any 802.1X-bearing medium.
|
Package eapol decodes EAPOL-Key frames — the WPA / WPA2 / WPA3 4-way handshake frames captured from any 802.1X-bearing medium. |
|
eas
Package eas decodes EAS / SAME (Specific Area Message Encoding) headers — the AFSK digital header that prefixes every Emergency Alert System and NOAA Weather Radio alert (the ZCZC… burst at 520.83 baud on 162 MHz / broadcast EAS).
|
Package eas decodes EAS / SAME (Specific Area Message Encoding) headers — the AFSK digital header that prefixes every Emergency Alert System and NOAA Weather Radio alert (the ZCZC… burst at 520.83 baud on 162 MHz / broadcast EAS). |
|
eigrp
Package eigrp decodes EIGRP (Enhanced Interior Gateway Routing Protocol) packets per RFC 7868 (informational; Cisco proprietary until 2016).
|
Package eigrp decodes EIGRP (Enhanced Interior Gateway Routing Protocol) packets per RFC 7868 (informational; Cisco proprietary until 2016). |
|
emv
Package emv decodes EMV BER-TLV structures from contactless and contact payment card APDU responses.
|
Package emv decodes EMV BER-TLV structures from contactless and contact payment card APDU responses. |
|
enip
Package enip decodes EtherNet/IP encapsulation packets and the CIP (Common Industrial Protocol) messages they carry — the ODVA factory-automation protocol family used by Allen-Bradley / Rockwell ControlLogix / CompactLogix / MicroLogix PLCs, Omron NJ/NX, Cognex vision systems, and a long tail of CIP-compliant I/O modules and drives.
|
Package enip decodes EtherNet/IP encapsulation packets and the CIP (Common Industrial Protocol) messages they carry — the ODVA factory-automation protocol family used by Allen-Bradley / Rockwell ControlLogix / CompactLogix / MicroLogix PLCs, Omron NJ/NX, Cognex vision systems, and a long tail of CIP-compliant I/O modules and drives. |
|
enocean
Package enocean decodes EnOcean ESP3 packets and the ERP1 radio telegrams they carry — the self-powered 868 / 902 / 315 MHz building- automation protocol behind batteryless light switches, occupancy / window-contact / temperature sensors and actuators.
|
Package enocean decodes EnOcean ESP3 packets and the ERP1 radio telegrams they carry — the self-powered 868 / 902 / 315 MHz building- automation protocol behind batteryless light switches, occupancy / window-contact / temperature sensors and actuators. |
|
epc
Package epc decodes GS1 Electronic Product Code (EPC) binary identifiers — the data on UHF RAIN RFID (EPC Gen2 / ISO 18000-63) tags used pervasively in retail item-level tagging and supply-chain logistics.
|
Package epc decodes GS1 Electronic Product Code (EPC) binary identifiers — the data on UHF RAIN RFID (EPC Gen2 / ISO 18000-63) tags used pervasively in retail item-level tagging and supply-chain logistics. |
|
erspan
Package erspan decodes the ERSPAN (Encapsulated Remote SPAN) header — Cisco's protocol for carrying a port-mirror (SPAN) session across a routed network inside a GRE tunnel.
|
Package erspan decodes the ERSPAN (Encapsulated Remote SPAN) header — Cisco's protocol for carrying a port-mirror (SPAN) session across a routed network inside a GRE tunnel. |
|
esmc
Package esmc decodes the ESMC — Ethernet Synchronization Messaging Channel (ITU-T G.8264) — the control channel of Synchronous Ethernet (SyncE).
|
Package esmc decodes the ESMC — Ethernet Synchronization Messaging Channel (ITU-T G.8264) — the control channel of Synchronous Ethernet (SyncE). |
|
estransport
Package estransport decodes Elasticsearch internal transport protocol frames.
|
Package estransport decodes Elasticsearch internal transport protocol frames. |
|
ethercat
Package ethercat decodes EtherCAT (Ethernet for Control Automation Technology, IEC 61158) frames — the real-time industrial Ethernet fieldbus dominating factory automation, motion control, and robotics (Beckhoff TwinCAT, and the many EtherCAT-slave drives, I/O terminals, and servo controllers built on the ET1100/ET1200 ESC ASICs).
|
Package ethercat decodes EtherCAT (Ethernet for Control Automation Technology, IEC 61158) frames — the real-time industrial Ethernet fieldbus dominating factory automation, motion control, and robotics (Beckhoff TwinCAT, and the many EtherCAT-slave drives, I/O terminals, and servo controllers built on the ET1100/ET1200 ESC ASICs). |
|
etherip
Package etherip decodes EtherIP (RFC 3378) — the protocol that tunnels a whole Ethernet frame inside an IP packet (IP protocol 97).
|
Package etherip decodes EtherIP (RFC 3378) — the protocol that tunnels a whole Ethernet frame inside an IP packet (IP protocol 97). |
|
ethkeystore
Package ethkeystore decrypts an Ethereum V3 keystore — the encrypted JSON wallet file Geth, MyEtherWallet, MetaMask exports, and most Ethereum tooling produce — recovering the 32-byte private key with the operator's passphrase.
|
Package ethkeystore decrypts an Ethereum V3 keystore — the encrypted JSON wallet file Geth, MyEtherWallet, MetaMask exports, and most Ethereum tooling produce — recovering the 32-byte private key with the operator's passphrase. |
|
eval
Package eval provides the PromptZero golden evaluation harness (roadmap P2-25).
|
Package eval provides the PromptZero golden evaluation harness (roadmap P2-25). |
|
faultier
Package faultier drives a hextreeio Faultier USB voltage-glitcher via its serial bridge interface.
|
Package faultier drives a hextreeio Faultier USB voltage-glitcher via its serial bridge interface. |
|
fdxb
Package fdxb decodes the ISO 11784/11785 FDX-B data block — the 134.2 kHz LF transponder format used by animal / pet microchips (and many "biothermo" and asset transponders).
|
Package fdxb decodes the ISO 11784/11785 FDX-B data block — the 134.2 kHz LF transponder format used by animal / pet microchips (and many "biothermo" and asset transponders). |
|
felica
Package felica decodes FeliCa (Sony, JIS X 6319-4) — NFC-F / NFC Forum Type 3 — command and response frames.
|
Package felica decodes FeliCa (Sony, JIS X 6319-4) — NFC-F / NFC Forum Type 3 — command and response frames. |
|
fileformat
Package fileformat gives the PromptZero agent structural access to the Flipper file formats it already ships with — .sub, .nfc, .ir, .rfid.
|
Package fileformat gives the PromptZero agent structural access to the Flipper file formats it already ships with — .sub, .nfc, .ir, .rfid. |
|
flasksession
Package flasksession decodes, verifies and forges Flask session cookies (the itsdangerous URLSafeTimedSerializer format).
|
Package flasksession decodes, verifies and forges Flask session cookies (the itsdangerous URLSafeTimedSerializer format). |
|
flipper/mock
Package mock provides a pty-backed fake Flipper CLI so serial.go and the command wrappers can be exercised without real hardware.
|
Package mock provides a pty-backed fake Flipper CLI so serial.go and the command wrappers can be exercised without real hardware. |
|
flipper/rpc
Package rpc implements a typed Flipper Zero RPC client over a transport.Transport.
|
Package rpc implements a typed Flipper Zero RPC client over a transport.Transport. |
|
flipper/transport
Package transport defines the byte-channel substrate the Flipper CLI layer operates over.
|
Package transport defines the byte-channel substrate the Flipper CLI layer operates over. |
|
geneve
Package geneve decodes Generic Network Virtualization Encapsulation packets per RFC 8926.
|
Package geneve decodes Generic Network Virtualization Encapsulation packets per RFC 8926. |
|
geohash
Package geohash converts between geographic coordinates and geohash strings — the compact base-32 geocode (e.g.
|
Package geohash converts between geographic coordinates and geohash strings — the compact base-32 geocode (e.g. |
|
githubtoken
Package githubtoken identifies and validates a GitHub authentication token — the prefixed, checksummed formats GitHub adopted in April 2021 (ghp_, gho_, ghu_, ghs_, ghr_, github_pat_).
|
Package githubtoken identifies and validates a GitHub authentication token — the prefixed, checksummed formats GitHub adopted in April 2021 (ghp_, gho_, ghu_, ghs_, ghr_, github_pat_). |
|
goose
Package goose decodes IEC 61850-8-1 GOOSE (Generic Object Oriented Substation Events) messages — the time-critical multicast Ethernet protocol that carries protective-relay signals between Intelligent Electronic Devices (IEDs) inside modern digital substations.
|
Package goose decodes IEC 61850-8-1 GOOSE (Generic Object Oriented Substation Events) messages — the time-critical multicast Ethernet protocol that carries protective-relay signals between Intelligent Electronic Devices (IEDs) inside modern digital substations. |
|
gre
Package gre decodes Generic Routing Encapsulation packets per RFC 2784 (base) + RFC 2890 (Key + Sequence Number) + RFC 2637 (PPTP Enhanced GRE, Version=1).
|
Package gre decodes Generic Routing Encapsulation packets per RFC 2784 (base) + RFC 2890 (Key + Sequence Number) + RFC 2637 (PPTP Enhanced GRE, Version=1). |
|
grpcdecode
Package grpcdecode decodes gRPC Length-Prefixed Messages per the gRPC wire-protocol specification.
|
Package grpcdecode decodes gRPC Length-Prefixed Messages per the gRPC wire-protocol specification. |
|
gsmtap
Package gsmtap decodes GSMTAP pseudo-header bytes per the Osmocom GSMTAP specification (osmo-bts / osmo-pcap-server / gsmtap.h reference).
|
Package gsmtap decodes GSMTAP pseudo-header bytes per the Osmocom GSMTAP specification (osmo-bts / osmo-pcap-server / gsmtap.h reference). |
|
gtp
Package gtp decodes GPRS Tunneling Protocol User Plane (GTP-U) packets per 3GPP TS 29.281.
|
Package gtp decodes GPRS Tunneling Protocol User Plane (GTP-U) packets per 3GPP TS 29.281. |
|
gtpv2
Package gtpv2 decodes GTPv2-C — the GTP version-2 control plane (3GPP TS 29.274) that signals EPS bearer / session management across the LTE and 5G-NSA core (the S11 MME↔SGW, S5/S8 SGW↔PGW and S10/S16 interfaces, UDP port 2123).
|
Package gtpv2 decodes GTPv2-C — the GTP version-2 control plane (3GPP TS 29.274) that signals EPS bearer / session management across the LTE and 5G-NSA core (the S11 MME↔SGW, S5/S8 SGW↔PGW and S10/S16 interfaces, UDP port 2123). |
|
gxrp
Package gxrp decodes GARP (Generic Attribute Registration Protocol, IEEE 802.1D-2004 §12.10) and its two applications, GVRP (GARP VLAN Registration Protocol) and GMRP (GARP Multicast Registration Protocol).
|
Package gxrp decodes GARP (Generic Attribute Registration Protocol, IEEE 802.1D-2004 §12.10) and its two applications, GVRP (GARP VLAN Registration Protocol) and GMRP (GARP Multicast Registration Protocol). |
|
hartip
Package hartip decodes HART-IP (Highway Addressable Remote Transducer over IP) messages per the HART Foundation specification (HCF_SPEC-085 + the HART-IP wire format reference).
|
Package hartip decodes HART-IP (Highway Addressable Remote Transducer over IP) messages per the HART Foundation specification (HCF_SPEC-085 + the HART-IP wire format reference). |
|
hashcat
Package hashcat builds hashcat-crackable hash lines natively, in pure Go.
|
Package hashcat builds hashcat-crackable hash lines natively, in pure Go. |
|
hci
Package hci decodes Bluetooth HCI (Host Controller Interface) packets — the transport between a Bluetooth host stack and its controller, and exactly what a btsnoop / hcidump capture contains.
|
Package hci decodes Bluetooth HCI (Host Controller Interface) packets — the transport between a Bluetooth host stack and its controller, and exactly what a btsnoop / hcidump capture contains. |
|
hicp
Package hicp decodes HICP (Host IP Configuration Protocol, UDP 3250) — the HMS Anybus protocol for discovering and (re)configuring industrial Ethernet gateway modules.
|
Package hicp decodes HICP (Host IP Configuration Protocol, UDP 3250) — the HMS Anybus protocol for discovering and (re)configuring industrial Ethernet gateway modules. |
|
hidreport
Package hidreport decodes a USB HID Report Descriptor — the item-based structure (USB HID 1.11 §6.2.2) a HID device returns to declare *what it is*: its usage (keyboard / mouse / gamepad / vendor-defined), its collections, and the size/shape of its input, output and feature reports.
|
Package hidreport decodes a USB HID Report Descriptor — the item-based structure (USB HID 1.11 §6.2.2) a HID device returns to declare *what it is*: its usage (keyboard / mouse / gamepad / vendor-defined), its collections, and the size/shape of its input, output and feature reports. |
|
hmacutil
Package hmacutil computes and verifies HMAC-SHA1/SHA256/SHA512 message authentication codes.
|
Package hmacutil computes and verifies HMAC-SHA1/SHA256/SHA512 message authentication codes. |
|
homeplugav
Package homeplugav decodes the management-message envelope of HomePlug AV / IEEE 1901 powerline networking (the MAC Management Entry, EtherType 0x88E1) — the control plane of powerline (PLC) adapters.
|
Package homeplugav decodes the management-message envelope of HomePlug AV / IEEE 1901 powerline networking (the MAC Management Entry, EtherType 0x88E1) — the control plane of powerline (PLC) adapters. |
|
homepluggp
Package homepluggp decodes HomePlug Green PHY SLAC management messages — the Signal Level Attenuation Characterization protocol that pairs an electric vehicle to a charging station over the CCS / ISO 15118 (DIN 70121) Combined Charging System pilot line.
|
Package homepluggp decodes HomePlug Green PHY SLAC management messages — the Signal Level Attenuation Characterization protocol that pairs an electric vehicle to a charging station over the CCS / ISO 15118 (DIN 70121) Combined Charging System pilot line. |
|
hpack
Package hpack decodes HPACK-compressed HTTP/2 header blocks per RFC 7541.
|
Package hpack decodes HPACK-compressed HTTP/2 header blocks per RFC 7541. |
|
hsrp
Package hsrp decodes Hot Standby Router Protocol (HSRP) packets per RFC 2281 (HSRPv1) and the Cisco HSRPv2 TLV extensions.
|
Package hsrp decodes Hot Standby Router Protocol (HSRP) packets per RFC 2281 (HSRPv1) and the Cisco HSRPv2 TLV extensions. |
|
http2
Package http2 decodes HTTP/2 frames per RFC 9113.
|
Package http2 decodes HTTP/2 frames per RFC 9113. |
|
httpmsg
Package httpmsg decodes HTTP/1.x messages per RFC 9112 + RFC 9110.
|
Package httpmsg decodes HTTP/1.x messages per RFC 9112 + RFC 9110. |
|
ibutton
Package ibutton decodes Dallas 1-Wire ROM IDs (a.k.a.
|
Package ibutton decodes Dallas 1-Wire ROM IDs (a.k.a. |
|
iccid
Code generated from Google libphonenumber (the `phonenumbers` library) E.164 calling-code → region map and pycountry's ISO-3166 names.
|
Code generated from Google libphonenumber (the `phonenumbers` library) E.164 calling-code → region map and pycountry's ISO-3166 names. |
|
iclass
Package iclass implements the iCLASS block cipher and the loclass key-recovery attack against HID iCLASS Elite / High Security readers.
|
Package iclass implements the iCLASS block cipher and the loclass key-recovery attack against HID iCLASS Elite / High Security readers. |
|
icmp
Package icmp decodes ICMP (RFC 792) and ICMPv6 (RFC 4443 + 4861 for Neighbor Discovery) packets.
|
Package icmp decodes ICMP (RFC 792) and ICMPv6 (RFC 4443 + 4861 for Neighbor Discovery) packets. |
|
icmpext
Package icmpext decodes the ICMP multipart message extension structure (RFC 4884) and, within it, the MPLS Label Stack object (RFC 4950).
|
Package icmpext decodes the ICMP multipart message extension structure (RFC 4884) and, within it, the MPLS Label Stack object (RFC 4950). |
|
iec104
Package iec104 decodes IEC 60870-5-104 APDUs — the European / Asian utility-SCADA telecontrol protocol that runs over TCP/IP.
|
Package iec104 decodes IEC 60870-5-104 APDUs — the European / Asian utility-SCADA telecontrol protocol that runs over TCP/IP. |
|
ieee80211
Package ieee80211 decodes IEEE 802.11 management frames — the beacon / probe / authentication / association / deauthentication / disassociation frames captured by every WiFi sniffer (Marauder, hcxdumptool, aircrack-ng, Wireshark).
|
Package ieee80211 decodes IEEE 802.11 management frames — the beacon / probe / authentication / association / deauthentication / disassociation frames captured by every WiFi sniffer (Marauder, hcxdumptool, aircrack-ng, Wireshark). |
|
ieee802154
Package ieee802154 decodes IEEE 802.15.4 MAC-layer frames — the wire format underneath Zigbee, Thread, OpenThread, and most other 2.4 GHz IoT mesh stacks.
|
Package ieee802154 decodes IEEE 802.15.4 MAC-layer frames — the wire format underneath Zigbee, Thread, OpenThread, and most other 2.4 GHz IoT mesh stacks. |
|
igmp
Package igmp decodes Internet Group Management Protocol packets per RFC 3376 (IGMPv3) and RFC 2236 (IGMPv2).
|
Package igmp decodes Internet Group Management Protocol packets per RFC 3376 (IGMPv3) and RFC 2236 (IGMPv2). |
|
igmpv3
Package igmpv3 decodes IGMPv3 (RFC 3376) — the IPv4 multicast group membership protocol, version 3.
|
Package igmpv3 decodes IGMPv3 (RFC 3376) — the IPv4 multicast group membership protocol, version 3. |
|
ike
Package ike decodes IKEv2 (Internet Key Exchange version 2) messages per RFC 7296.
|
Package ike decodes IKEv2 (Internet Key Exchange version 2) messages per RFC 7296. |
|
imap
Package imap decodes IMAP4rev1 (Internet Message Access Protocol v4 revision 1) messages per RFC 3501, plus the RFC 2595 (STARTTLS), RFC 2087 (QUOTA), RFC 2342 (NAMESPACE), and RFC 4978 (COMPRESS) extensions.
|
Package imap decodes IMAP4rev1 (Internet Message Access Protocol v4 revision 1) messages per RFC 3501, plus the RFC 2595 (STARTTLS), RFC 2087 (QUOTA), RFC 2342 (NAMESPACE), and RFC 4978 (COMPRESS) extensions. |
|
imei
Package imei decodes and validates a GSM device identity — the 15-digit IMEI (with its Luhn check digit) and the 16-digit IMEISV (software-version variant).
|
Package imei decodes and validates a GSM device identity — the 15-digit IMEI (with its Luhn check digit) and the 16-digit IMEISV (software-version variant). |
|
imsi
Package imsi decodes an International Mobile Subscriber Identity — the up-to-15-digit identifier stored on a SIM/USIM that uniquely names a cellular subscriber, disclosed in plaintext in a GSM/LTE Identity Response (the message an IMSI-catcher / cell-site simulator forces a handset to send).
|
Package imsi decodes an International Mobile Subscriber Identity — the up-to-15-digit identifier stored on a SIM/USIM that uniquely names a cellular subscriber, disclosed in plaintext in a GSM/LTE Identity Response (the message an IMSI-catcher / cell-site simulator forces a handset to send). |
|
ioprox
Package ioprox decodes the IO Prox (Kantech XSF) 125 kHz LF access-control data block — the credential format used by Kantech ioProx readers, widely deployed across North American commercial / institutional access control.
|
Package ioprox decodes the IO Prox (Kantech XSF) 125 kHz LF access-control data block — the credential format used by Kantech ioProx readers, widely deployed across North American commercial / institutional access control. |
|
ipdecode
Package ipdecode parses raw IP packets (IPv4 + IPv6) plus the most-deployed next-layer headers (TCP, UDP, ICMP, ICMPv6).
|
Package ipdecode parses raw IP packets (IPv4 + IPv6) plus the most-deployed next-layer headers (TCP, UDP, ICMP, ICMPv6). |
|
ipfix
Package ipfix decodes IPFIX (IP Flow Information eXport) messages per RFC 7011.
|
Package ipfix decodes IPFIX (IP Flow Information eXport) messages per RFC 7011. |
|
ipmi
Package ipmi decodes IPMI (Intelligent Platform Management Interface) messages carried over RMCP (Remote Management Control Protocol) on UDP/623.
|
Package ipmi decodes IPMI (Intelligent Platform Management Interface) messages carried over RMCP (Remote Management Control Protocol) on UDP/623. |
|
ipsec
Package ipsec decodes the two IPsec data-plane protocols: ESP (Encapsulating Security Payload) per RFC 4303 and AH (Authentication Header) per RFC 4302.
|
Package ipsec decodes the two IPsec data-plane protocols: ESP (Encapsulating Security Payload) per RFC 4303 and AH (Authentication Header) per RFC 4302. |
|
ir
Package ir decodes raw infrared remote-control timing captures into the protocol + address/command — the IR analogue of the Sub-GHz protocol decoders, and the complement to the file-level ir_decode_file (which only reads a .ir file's already-parsed entries).
|
Package ir decodes raw infrared remote-control timing captures into the protocol + address/command — the IR analogue of the Sub-GHz protocol decoders, and the complement to the file-level ir_decode_file (which only reads a .ir file's already-parsed entries). |
|
isis
Package isis decodes IS-IS (Intermediate System to Intermediate System) packets per ISO 10589 and RFC 1195.
|
Package isis decodes IS-IS (Intermediate System to Intermediate System) packets per ISO 10589 and RFC 1195. |
|
iso14443a
Package iso14443a identifies ISO/IEC 14443-3 Type A NFC tags from their anti-collision response (ATQA + SAK + UID, plus optional ATS).
|
Package iso14443a identifies ISO/IEC 14443-3 Type A NFC tags from their anti-collision response (ATQA + SAK + UID, plus optional ATS). |
|
iso14443b
Package iso14443b decodes an ISO/IEC 14443 Type B ATQB (the PICC's answer to REQB/WUPB) — the second contact-less proximity standard alongside Type A (this project's internal/iso14443a).
|
Package iso14443b decodes an ISO/IEC 14443 Type B ATQB (the PICC's answer to REQB/WUPB) — the second contact-less proximity standard alongside Type A (this project's internal/iso14443a). |
|
iso15693
Package iso15693 decodes the identity fields of an ISO/IEC 15693 vicinity card (HF 13.56 MHz) — the UID and, optionally, the AFI application-family byte.
|
Package iso15693 decodes the identity fields of an ISO/IEC 15693 vicinity card (HF 13.56 MHz) — the UID and, optionally, the AFI application-family byte. |
|
iso7816
Package iso7816 decodes ISO/IEC 7816-3 Answer To Reset (ATR) strings — the response every contact smart card sends when reset.
|
Package iso7816 decodes ISO/IEC 7816-3 Answer To Reset (ATR) strings — the response every contact smart card sends when reset. |
|
isotp
Package isotp decodes ISO-TP (ISO 15765-2) transport frames and reassembles the multi-frame messages that carry UDS / OBD-II over CAN — the transport layer that sits between a raw CAN frame (canfd) and the diagnostic application PDU (uds / obd2).
|
Package isotp decodes ISO-TP (ISO 15765-2) transport frames and reassembles the multi-frame messages that carry UDS / OBD-II over CAN — the transport layer that sits between a raw CAN frame (canfd) and the diagnostic application PDU (uds / obd2). |
|
j1850
Package j1850 decodes SAE J1850 VPW (Variable Pulse Width) and PWM (Pulse Width Modulation) frames — the legacy OBD-II protocol used by GM and Ford vehicles before they migrated to CAN bus around 2008.
|
Package j1850 decodes SAE J1850 VPW (Variable Pulse Width) and PWM (Pulse Width Modulation) frames — the legacy OBD-II protocol used by GM and Ford vehicles before they migrated to CAN bus around 2008. |
|
jablotron
Package jablotron decodes the Jablotron 125 kHz LF access-control data block — the credential format used by Jablotron readers/fobs, widely deployed across Czech / Slovak / wider-EU access control and intercom systems.
|
Package jablotron decodes the Jablotron 125 kHz LF access-control data block — the credential format used by Jablotron readers/fobs, widely deployed across Czech / Slovak / wider-EU access control and intercom systems. |
|
jtag
Package jtag decodes JTAG IDCODE values (IEEE 1149.1) and the SWD DPIDR / TARGETID variants used by ARM CoreSight debug interfaces.
|
Package jtag decodes JTAG IDCODE values (IEEE 1149.1) and the SWD DPIDR / TARGETID variants used by ARM CoreSight debug interfaces. |
|
jwtdecode
Package jwtdecode decodes JSON Web Tokens (JWT) — the dominant API auth token format in modern web stacks.
|
Package jwtdecode decodes JSON Web Tokens (JWT) — the dominant API auth token format in modern web stacks. |
|
jwtsig
Package jwtsig verifies the HMAC signature of a JWS (JWT) against a candidate secret — the verification step jwt_decode deliberately leaves out.
|
Package jwtsig verifies the HMAC signature of a JWS (JWT) against a candidate secret — the verification step jwt_decode deliberately leaves out. |
|
kafka
Package kafka decodes Apache Kafka wire-protocol request/response messages per the Kafka protocol specification (KIP-35 and the protocol guide).
|
Package kafka decodes Apache Kafka wire-protocol request/response messages per the Kafka protocol specification (KIP-35 and the protocol guide). |
|
keeloq
Package keeloq implements the KeeLoq block cipher and supporting primitives for sub-GHz rolling-code analysis.
|
Package keeloq implements the KeeLoq block cipher and supporting primitives for sub-GHz rolling-code analysis. |
|
kerberos
Package kerberos decodes Kerberos v5 messages per RFC 4120 — the authentication protocol that underpins **every Active Directory deployment** and most enterprise SSO stacks (MIT Kerberos, Heimdal, Microsoft Active Directory, Apple Open Directory, FreeIPA / IdM).
|
Package kerberos decodes Kerberos v5 messages per RFC 4120 — the authentication protocol that underpins **every Active Directory deployment** and most enterprise SSO stacks (MIT Kerberos, Heimdal, Microsoft Active Directory, Apple Open Directory, FreeIPA / IdM). |
|
keytab
Package keytab parses an MIT Kerberos keytab file (the binary `.keytab` format, version 0x0502) into its entries — service / account principals, key-version numbers, encryption types, and the raw key bytes.
|
Package keytab parses an MIT Kerberos keytab file (the binary `.keytab` format, version 0x0502) into its entries — service / account principals, key-version numbers, encryption types, and the raw key bytes. |
|
knxnetip
Package knxnetip decodes KNXnet/IP frames — the IP-transport dialect of KNX, the dominant European building-automation bus (lighting, HVAC, blinds/shutters, access control, energy metering, room controllers).
|
Package knxnetip decodes KNXnet/IP frames — the IP-transport dialect of KNX, the dominant European building-automation bus (lighting, HVAC, blinds/shutters, access control, energy metering, room controllers). |
|
krbroast
Package krbroast assembles the hashcat crack line for the two dominant offline Kerberos credential attacks, from a captured KDC response:
|
Package krbroast assembles the hashcat crack line for the two dominant offline Kerberos credential attacks, from a captured KDC response: |
|
ksuid
Package ksuid decodes a KSUID (K-Sortable Unique IDentifier — the segmentio/ksuid format) into its embedded creation timestamp and random payload.
|
Package ksuid decodes a KSUID (K-Sortable Unique IDentifier — the segmentio/ksuid format) into its embedded creation timestamp and random payload. |
|
kwp
Package kwp decodes KWP2000 (Keyword Protocol 2000, ISO 14230-3) diagnostic messages — the predecessor to UDS still spoken by many pre-CAN / early-CAN ECUs and ELM327 adapters.
|
Package kwp decodes KWP2000 (Keyword Protocol 2000, ISO 14230-3) diagnostic messages — the predecessor to UDS still spoken by many pre-CAN / early-CAN ECUs and ELM327 adapters. |
|
l2cap
Package l2cap decodes Bluetooth L2CAP (Logical Link Control and Adaptation Protocol) — the channel-multiplexing layer that rides inside HCI ACL data and carries the higher Bluetooth protocols.
|
Package l2cap decodes Bluetooth L2CAP (Logical Link Control and Adaptation Protocol) — the channel-multiplexing layer that rides inside HCI ACL data and carries the higher Bluetooth protocols. |
|
l2tp
Package l2tp decodes L2TPv3 packets per RFC 3931 (UDP- encapsulated mode on UDP port 1701).
|
Package l2tp decodes L2TPv3 packets per RFC 3931 (UDP- encapsulated mode on UDP port 1701). |
|
lacp
Package lacp decodes Link Aggregation Control Protocol (LACP) PDUs per IEEE 802.1AX-2020 (formerly 802.3ad).
|
Package lacp decodes Link Aggregation Control Protocol (LACP) PDUs per IEEE 802.1AX-2020 (formerly 802.3ad). |
|
ldap
Package ldap decodes Lightweight Directory Access Protocol v3 messages per RFC 4511 — the canonical directory-service protocol used by **every Active Directory deployment** + most enterprise IAM stacks (Microsoft AD LDS, OpenLDAP, 389 Directory Server, FreeIPA / IdM, Apple Open Directory, Apache Directory Server, Oracle Internet Directory, Novell eDirectory).
|
Package ldap decodes Lightweight Directory Access Protocol v3 messages per RFC 4511 — the canonical directory-service protocol used by **every Active Directory deployment** + most enterprise IAM stacks (Microsoft AD LDS, OpenLDAP, 389 Directory Server, FreeIPA / IdM, Apple Open Directory, Apache Directory Server, Oracle Internet Directory, Novell eDirectory). |
|
ldappw
Package ldappw implements the RFC 2307 LDAP userPassword storage schemes used by OpenLDAP slapd, 389 Directory Server, Dovecot, and Atlassian Crowd: the {SHA}/{SSHA} family plus {MD5}/{SMD5} and the OpenLDAP pw-sha2 / Dovecot SHA-2 extensions ({SHA256}/{SSHA256}/{SHA384}/{SSHA384}/{SHA512}/{SSHA512}).
|
Package ldappw implements the RFC 2307 LDAP userPassword storage schemes used by OpenLDAP slapd, 389 Directory Server, Dovecot, and Atlassian Crowd: the {SHA}/{SSHA} family plus {MD5}/{SMD5} and the OpenLDAP pw-sha2 / Dovecot SHA-2 extensions ({SHA256}/{SSHA256}/{SHA384}/{SSHA384}/{SHA512}/{SSHA512}). |
|
ldp
Package ldp decodes LDP (Label Distribution Protocol) PDUs per RFC 5036.
|
Package ldp decodes LDP (Label Distribution Protocol) PDUs per RFC 5036. |
|
lin
Package lin decodes a LIN (Local Interconnect Network) bus frame — the low-cost single-wire automotive sub-bus that hangs off CAN for body electronics: door / mirror / seat modules, climate flaps, wiper and rain/light sensors, switch panels.
|
Package lin decodes a LIN (Local Interconnect Network) bus frame — the low-cost single-wire automotive sub-bus that hangs off CAN for body electronics: door / mirror / seat modules, climate flaps, wiper and rain/light sensors, switch panels. |
|
linecode
Package linecode decodes raw line-code bitstreams into the data bits they carry.
|
Package linecode decodes raw line-code bitstreams into the data bits they carry. |
|
lldp
Package lldp decodes Link Layer Discovery Protocol payloads per IEEE 802.1AB-2009.
|
Package lldp decodes Link Layer Discovery Protocol payloads per IEEE 802.1AB-2009. |
|
llmnr
Package llmnr decodes LLMNR (Link-Local Multicast Name Resolution) messages per RFC 4795.
|
Package llmnr decodes LLMNR (Link-Local Multicast Name Resolution) messages per RFC 4795. |
|
lorawan
Package lorawan decodes LoRaWAN PHYPayload frames — the MAC-layer packet format used by LoRaWAN 1.0.x and 1.1 networks.
|
Package lorawan decodes LoRaWAN PHYPayload frames — the MAC-layer packet format used by LoRaWAN 1.0.x and 1.1 networks. |
|
macaddr
Package macaddr classifies an IEEE 802 MAC address (EUI-48) from its two administration bits — the I/G bit (individual vs group/multicast) and the U/L bit (universally vs locally administered).
|
Package macaddr classifies an IEEE 802 MAC address (EUI-48) from its two administration bits — the I/G bit (individual vs group/multicast) and the U/L bit (universally vs locally administered). |
|
maccontrol
Package maccontrol decodes IEEE 802.3 MAC Control frames (EtherType 0x8808) — the Ethernet flow-control and EPON access-control sublayer.
|
Package maccontrol decodes IEEE 802.3 MAC Control frames (EtherType 0x8808) — the Ethernet flow-control and EPON access-control sublayer. |
|
macsec
Package macsec decodes the IEEE 802.1AE (MACsec) Security TAG — the per-frame header that prefixes a MACsec-protected Ethernet frame (EtherType 0x88E5).
|
Package macsec decodes the IEEE 802.1AE (MACsec) Security TAG — the per-frame header that prefixes a MACsec-protected Ethernet frame (EtherType 0x88E5). |
|
maidenhead
Package maidenhead converts between geographic coordinates and Maidenhead grid locators (a.k.a.
|
Package maidenhead converts between geographic coordinates and Maidenhead grid locators (a.k.a. |
|
marauder/parsers
Package parsers turns Marauder CLI output lines into typed events the web layer can ship as JSON.
|
Package parsers turns Marauder CLI output lines into typed events the web layer can ship as JSON. |
|
mbus
Package mbus decodes M-Bus (Meter-Bus, EN 13757-2 link layer + EN 13757-3 application layer) frames — the European smart-metering protocol for electricity, gas, water, heat, and warm-water meters.
|
Package mbus decodes M-Bus (Meter-Bus, EN 13757-2 link layer + EN 13757-3 application layer) frames — the European smart-metering protocol for electricity, gas, water, heat, and warm-water meters. |
|
mcp
Package mcp exposes PromptZero's tool surface over the Model Context Protocol (stdio transport).
|
Package mcp exposes PromptZero's tool surface over the Model Context Protocol (stdio transport). |
|
mcpfed
Package mcpfed federates external Model Context Protocol (MCP) servers as native PromptZero tools.
|
Package mcpfed federates external Model Context Protocol (MCP) servers as native PromptZero tools. |
|
mdns
Package mdns decodes Multicast DNS (mDNS) messages per RFC 6762 + the DNS-SD (DNS-Based Service Discovery) layer per RFC 6763.
|
Package mdns decodes Multicast DNS (mDNS) messages per RFC 6762 + the DNS-SD (DNS-Based Service Discovery) layer per RFC 6763. |
|
memcached
Package memcached decodes Memcached binary-protocol messages per the Memcached binary protocol specification.
|
Package memcached decodes Memcached binary-protocol messages per the Memcached binary protocol specification. |
|
meshtastic
Package meshtastic decodes the Meshtastic LoRa-mesh radio packet header — the 16-byte plaintext header that prefixes every Meshtastic packet on the 868/915 MHz LoRa channel, before the AES-encrypted payload.
|
Package meshtastic decodes the Meshtastic LoRa-mesh radio packet header — the 16-byte plaintext header that prefixes every Meshtastic packet on the 868/915 MHz LoRa channel, before the AES-encrypted payload. |
|
metakom
Package metakom decodes a Metakom iButton key — the 4-byte (32-bit) contact key format used by Metakom intercom systems (common across the former-CIS / Eastern-European residential market).
|
Package metakom decodes a Metakom iButton key — the 4-byte (32-bit) contact key format used by Metakom intercom systems (common across the former-CIS / Eastern-European residential market). |
|
mifare
Package mifare decodes Mifare Classic 1K / 4K data dumps — manufacturer block (sector 0 block 0), sector trailer (last block of each sector), value blocks (recognized by their value+complement structure), and plain data blocks.
|
Package mifare decodes Mifare Classic 1K / 4K data dumps — manufacturer block (sector 0 block 0), sector trailer (last block of each sector), value blocks (recognized by their value+complement structure), and plain data blocks. |
|
mld
Package mld decodes MLD — Multicast Listener Discovery — the IPv6 multicast-group membership protocol carried in ICMPv6: MLDv1 (RFC 2710) and MLDv2 (RFC 3810).
|
Package mld decodes MLD — Multicast Listener Discovery — the IPv6 multicast-group membership protocol carried in ICMPv6: MLDv1 (RFC 2710) and MLDv2 (RFC 3810). |
|
modbus
Package modbus decodes Modbus RTU and Modbus TCP frames per the Modbus Application Protocol Specification v1.1b3 and the Modbus Messaging Implementation Guide v1.0b.
|
Package modbus decodes Modbus RTU and Modbus TCP frames per the Modbus Application Protocol Specification v1.1b3 and the Modbus Messaging Implementation Guide v1.0b. |
|
mode
Package mode defines named operation profiles that constrain which tools the agent will dispatch.
|
Package mode defines named operation profiles that constrain which tools the agent will dispatch. |
|
mongodb
Package mongodb decodes MongoDB wire protocol messages per the MongoDB documentation ("MongoDB Wire Protocol").
|
Package mongodb decodes MongoDB wire protocol messages per the MongoDB documentation ("MongoDB Wire Protocol"). |
|
mount
Package mount decodes the ONC RPC NFS MOUNT protocol v3 (RFC 1813, program 100005) — the service that hands a client the root file handle for an NFS export.
|
Package mount decodes the ONC RPC NFS MOUNT protocol v3 (RFC 1813, program 100005) — the service that hands a client the root file handle for an NFS export. |
|
mpls
Package mpls decodes MPLS label stacks per RFC 3032 (stack encoding) + RFC 5462 (TC field rename from EXP) + the reserved-label catalogue from RFC 4182 / 5586 / 6790 / 7274.
|
Package mpls decodes MPLS label stacks per RFC 3032 (stack encoding) + RFC 5462 (TC field rename from EXP) + the reserved-label catalogue from RFC 4182 / 5586 / 6790 / 7274. |
|
mqtt
Package mqtt decodes MQTT v3.1.1 control packets — the application-layer protocol underneath most IoT smart-home / industrial-sensor / broker setups.
|
Package mqtt decodes MQTT v3.1.1 control packets — the application-layer protocol underneath most IoT smart-home / industrial-sensor / broker setups. |
|
mqttsn
Package mqttsn decodes MQTT-SN (MQTT for Sensor Networks) v1.2 messages per the OASIS MQTT-SN specification.
|
Package mqttsn decodes MQTT-SN (MQTT for Sensor Networks) v1.2 messages per the OASIS MQTT-SN specification. |
|
mrz
Package mrz decodes the Machine Readable Zone of a passport, ID card or visa — the `<`-padded OCR-B lines at the bottom of an ICAO 9303 travel document.
|
Package mrz decodes the Machine Readable Zone of a passport, ID card or visa — the `<`-padded OCR-B lines at the bottom of an ICAO 9303 travel document. |
|
msdp
Package msdp decodes MSDP (Multicast Source Discovery Protocol) packets per RFC 3618.
|
Package msdp decodes MSDP (Multicast Source Discovery Protocol) packets per RFC 3618. |
|
msgpack
Package msgpack decodes a MessagePack-encoded value to a structured tree — the compact binary serialization (https://msgpack.org) used by Redis internals, msgpack-RPC, many web/API backends, mobile sync protocols, and game-server traffic.
|
Package msgpack decodes a MessagePack-encoded value to a structured tree — the compact binary serialization (https://msgpack.org) used by Redis internals, msgpack-RPC, many web/API backends, mobile sync protocols, and game-server traffic. |
|
mysqldb
Package mysqldb decodes MySQL / MariaDB client/server protocol messages per the MySQL documentation (Chapter 4: "Client/Server Protocol").
|
Package mysqldb decodes MySQL / MariaDB client/server protocol messages per the MySQL documentation (Chapter 4: "Client/Server Protocol"). |
|
mysqlpw
Package mysqlpw implements the MySQL / MariaDB mysql_native_password hash (the "4.1+" PASSWORD() format, hashcat mode 300): the value stored in mysql.user.authentication_string / Password.
|
Package mysqlpw implements the MySQL / MariaDB mysql_native_password hash (the "4.1+" PASSWORD() format, hashcat mode 300): the value stored in mysql.user.authentication_string / Password. |
|
natpmp
Package natpmp decodes NAT-PMP (NAT Port Mapping Protocol) messages per RFC 6886.
|
Package natpmp decodes NAT-PMP (NAT Port Mapping Protocol) messages per RFC 6886. |
|
nbns
Package nbns decodes NBNS (NetBIOS Name Service) messages per RFC 1001 (NetBIOS service concepts) and RFC 1002 (NetBIOS over TCP/UDP encoding).
|
Package nbns decodes NBNS (NetBIOS Name Service) messages per RFC 1001 (NetBIOS service concepts) and RFC 1002 (NetBIOS over TCP/UDP encoding). |
|
ndef
Package ndef decodes NFC Data Exchange Format messages — the payload format every NDEF-formatted NFC tag stores.
|
Package ndef decodes NFC Data Exchange Format messages — the payload format every NDEF-formatted NFC tag stores. |
|
ndp
Package ndp decodes ICMPv6 NDP (Neighbor Discovery Protocol) messages per RFC 4861 (base NDP) + RFC 4191 (Default Router Preferences + Route Information) + RFC 8106 (RDNSS / DNSSL for SLAAC-only IPv6 hosts).
|
Package ndp decodes ICMPv6 NDP (Neighbor Discovery Protocol) messages per RFC 4861 (base NDP) + RFC 4191 (Default Router Preferences + Route Information) + RFC 8106 (RDNSS / DNSSL for SLAAC-only IPv6 hosts). |
|
netflow
Package netflow decodes NetFlow v5 export packets per Cisco's public NetFlow v5 specification (1996; the dominant flow-export format on enterprise + ISP networks for two decades, still emitted by every Cisco / Juniper / Arista router that runs classic NetFlow).
|
Package netflow decodes NetFlow v5 export packets per Cisco's public NetFlow v5 specification (1996; the dominant flow-export format on enterprise + ISP networks for two decades, still emitted by every Cisco / Juniper / Arista router that runs classic NetFlow). |
|
netflow9
Package netflow9 decodes NetFlow v9 (RFC 3954) packets.
|
Package netflow9 decodes NetFlow v9 (RFC 3954) packets. |
|
netntlm
Package netntlm assembles the hashcat crack line for a captured NTLM challenge-response authentication — the loot of an SMB-relay / Responder / NTLM-over-HTTP capture.
|
Package netntlm assembles the hashcat crack line for a captured NTLM challenge-response authentication — the loot of an SMB-relay / Responder / NTLM-over-HTTP capture. |
|
nfs
Package nfs decodes ONC RPC NFS v3 (RFC 1813, program 100003) call messages — the file-access layer that completes the project's NFS reconnaissance chain after internal/portmap (rpcbind, locate the service) and internal/mount (get the export root file handle).
|
Package nfs decodes ONC RPC NFS v3 (RFC 1813, program 100003) call messages — the file-access layer that completes the project's NFS reconnaissance chain after internal/portmap (rpcbind, locate the service) and internal/mount (get the export root file handle). |
|
nlm
Package nlm decodes the ONC RPC NFS Lock Manager protocol v4 (NLM, program 100021) — the byte-range / advisory locking sidecar of NFS, run by rpc.lockd.
|
Package nlm decodes the ONC RPC NFS Lock Manager protocol v4 (NLM, program 100021) — the byte-range / advisory locking sidecar of NFS, run by rpc.lockd. |
|
nmea
Package nmea decodes NMEA 0183 sentences — the line-based ASCII output of virtually every GPS/GNSS receiver, including the GPS modules used with the Flipper Zero and the ESP32 Marauder devboard.
|
Package nmea decodes NMEA 0183 sentences — the line-based ASCII output of virtually every GPS/GNSS receiver, including the GPS modules used with the Flipper Zero and the ESP32 Marauder devboard. |
|
noralsy
Package noralsy decodes the Noralsy 125 kHz LF access-control data block — the credential format used by Noralsy readers/fobs, common in French (and wider European) residential access control and intercom systems.
|
Package noralsy decodes the Noralsy 125 kHz LF access-control data block — the credential format used by Noralsy readers/fobs, common in French (and wider European) residential access control and intercom systems. |
|
nrf24
Package nrf24 decodes Nordic NRF24L01 Enhanced Shockburst (ESB) packets and the Logitech Unifying / Mousejack payload variants that ride on top of them.
|
Package nrf24 decodes Nordic NRF24L01 Enhanced Shockburst (ESB) packets and the Logitech Unifying / Mousejack payload variants that ride on top of them. |
|
nsh
Package nsh decodes the Network Service Header (NSH, RFC 8300) — the Service Function Chaining (SFC) encapsulation that steers a packet through an ordered chain of service functions (firewalls, DPI, NAT, load-balancers) in SDN / NFV / cloud fabrics.
|
Package nsh decodes the Network Service Header (NSH, RFC 8300) — the Service Function Chaining (SFC) encapsulation that steers a packet through an ordered chain of service functions (firewalls, DPI, NAT, load-balancers) in SDN / NFV / cloud fabrics. |
|
ntag
Package ntag decodes the NTAG21x (NTAG213/215/216) configuration pages — the registers that control an NFC Type-2 tag's password protection, lock state, NFC counter, and UID/counter ASCII-mirror feature.
|
Package ntag decodes the NTAG21x (NTAG213/215/216) configuration pages — the registers that control an NFC Type-2 tag's password protection, lock state, NFC counter, and UID/counter ASCII-mirror feature. |
|
nthash
Package nthash computes the Windows NT hash (NTLM) of a password: the MD4 digest of the password encoded as little-endian UTF-16.
|
Package nthash computes the Windows NT hash (NTLM) of a password: the MD4 digest of the password encoded as little-endian UTF-16. |
|
ntlm
Package ntlm decodes NTLM (NT LAN Manager) messages per Microsoft Open Protocol Specifications MS-NLMP.
|
Package ntlm decodes NTLM (NT LAN Manager) messages per Microsoft Open Protocol Specifications MS-NLMP. |
|
ntp
Package ntp decodes NTP / SNTP packets per RFC 5905 (v4), RFC 1305 (v3), and RFC 4330 (SNTPv4).
|
Package ntp decodes NTP / SNTP packets per RFC 5905 (v4), RFC 1305 (v3), and RFC 4330 (SNTPv4). |
|
oam
Package oam decodes Ethernet OAM / Connectivity Fault Management (CFM) frames — IEEE 802.1ag / ITU-T Y.1731, EtherType 0x8902.
|
Package oam decodes Ethernet OAM / Connectivity Fault Management (CFM) frames — IEEE 802.1ag / ITU-T Y.1731, EtherType 0x8902. |
|
obd2
Package obd2 decodes OBD-II / SAE J1979 Mode-01 ("show current data") responses into engineering values — turning the raw measurement bytes of a diagnostic response into RPM, speed, coolant temperature, MAF, etc.
|
Package obd2 decodes OBD-II / SAE J1979 Mode-01 ("show current data") responses into engineering values — turning the raw measurement bytes of a diagnostic response into RPM, speed, coolant temperature, MAF, etc. |
|
objectid
Package objectid decodes a MongoDB ObjectId into its embedded fields — most usefully its **creation timestamp**.
|
Package objectid decodes a MongoDB ObjectId into its embedded fields — most usefully its **creation timestamp**. |
|
obs
Package obs ("observability") is the cross-cutting layer that wires structured logging, Prometheus metrics, and the /debug snapshot view into the rest of PromptZero.
|
Package obs ("observability") is the cross-cutting layer that wires structured logging, Prometheus metrics, and the /debug snapshot view into the rest of PromptZero. |
|
oncrpc
Package oncrpc parses the ONC RPC (Sun RPC, RFC 5531) message header shared by the project's RPC-protocol decoders — internal/portmap (rpcbind), internal/mount (NFS MOUNT) and internal/nfs (NFS v3).
|
Package oncrpc parses the ONC RPC (Sun RPC, RFC 5531) message header shared by the project's RPC-protocol decoders — internal/portmap (rpcbind), internal/mount (NFS MOUNT) and internal/nfs (NFS v3). |
|
opcua
Package opcua decodes OPC UA Binary messages per IEC 62541-6 (OPC Unified Architecture, Part 6: Mappings).
|
Package opcua decodes OPC UA Binary messages per IEC 62541-6 (OPC Unified Architecture, Part 6: Mappings). |
|
openflow
Package openflow decodes OpenFlow control-channel messages per the Open Networking Foundation (ONF) specifications — version 1.0 (`of10`), 1.3 (`of13`; the dominant deployed version), and 1.5 (`of15`).
|
Package openflow decodes OpenFlow control-channel messages per the Open Networking Foundation (ONF) specifications — version 1.0 (`of10`), 1.3 (`of13`; the dominant deployed version), and 1.5 (`of15`). |
|
osdp
Package osdp decodes OSDP (Open Supervised Device Protocol) packets — the SIA / IEC 60839-11-5 serial protocol that modern physical-access- control readers speak to their controllers (the secure successor to Wiegand).
|
Package osdp decodes OSDP (Open Supervised Device Protocol) packets — the SIA / IEC 60839-11-5 serial protocol that modern physical-access- control readers speak to their controllers (the secure successor to Wiegand). |
|
ospf
Package ospf decodes OSPFv2 packets per RFC 2328.
|
Package ospf decodes OSPFv2 packets per RFC 2328. |
|
ospfv3
Package ospfv3 decodes OSPFv3 (RFC 5340) packets.
|
Package ospfv3 decodes OSPFv3 (RFC 5340) packets. |
|
otp
Package otp computes RFC 4226 HOTP and RFC 6238 TOTP one-time passwords.
|
Package otp computes RFC 4226 HOTP and RFC 6238 TOTP one-time passwords. |
|
otpmigration
Package otpmigration decodes the Google Authenticator "Export accounts" payload — the otpauth-migration://offline?data=… URI (and the bare base64 behind it) — into the list of 2FA accounts it carries: issuer, account name, secret, algorithm, digit count, OTP type, and HOTP counter.
|
Package otpmigration decodes the Google Authenticator "Export accounts" payload — the otpauth-migration://offline?data=… URI (and the bare base64 behind it) — into the list of 2FA accounts it carries: issuer, account name, secret, algorithm, digit count, OTP type, and HOTP counter. |
|
pacs
Package pacs decodes Physical Access Control System (PACS) credential payloads — the upper-layer encoding that sits on top of the Wiegand bit-stream produced by an HID Prox / iCLASS / EM-style reader.
|
Package pacs decodes Physical Access Control System (PACS) credential payloads — the upper-layer encoding that sits on top of the Wiegand bit-stream produced by an HID Prox / iCLASS / EM-style reader. |
|
paseto
Package paseto decodes (and, for the Ed25519 public variants, verifies) PASETO tokens — "Platform-Agnostic Security Tokens", the modern signed/encrypted token format positioned as the safer alternative to JWT (no algorithm confusion, versioned crypto).
|
Package paseto decodes (and, for the Ed25519 public variants, verifies) PASETO tokens — "Platform-Agnostic Security Tokens", the modern signed/encrypted token format positioned as the safer alternative to JWT (no algorithm confusion, versioned crypto). |
|
pcap
Package pcap implements a pure-Go libpcap classic-format writer and reader.
|
Package pcap implements a pure-Go libpcap classic-format writer and reader. |
|
pcapng
Package pcapng decodes the PCAPng (next-generation packet capture, draft-tuexen-opsawg-pcapng) file format.
|
Package pcapng decodes the PCAPng (next-generation packet capture, draft-tuexen-opsawg-pcapng) file format. |
|
pcp
Package pcp decodes PCP (Port Control Protocol) messages per RFC 6887.
|
Package pcp decodes PCP (Port Control Protocol) messages per RFC 6887. |
|
pemkey
Package pemkey parses a PEM private key file (the openssl-style "-----BEGIN [RSA|EC|ENCRYPTED] PRIVATE KEY-----" / PKCS#1 / SEC1 / PKCS#8 formats) for triage.
|
Package pemkey parses a PEM private key file (the openssl-style "-----BEGIN [RSA|EC|ENCRYPTED] PRIVATE KEY-----" / PKCS#1 / SEC1 / PKCS#8 formats) for triage. |
|
persona
Package persona implements operator-mode profiles for PromptZero.
|
Package persona implements operator-mode profiles for PromptZero. |
|
pfcp
Package pfcp decodes the Packet Forwarding Control Protocol (3GPP TS 29.244) — the control protocol of the N4 interface (5G SMF↔UPF) and the 4G Sxa/Sxb/Sxc CUPS interfaces, by which the control plane programs the user-plane function's packet-forwarding rules (PDRs / FARs / QERs / URRs) over UDP 8805.
|
Package pfcp decodes the Packet Forwarding Control Protocol (3GPP TS 29.244) — the control protocol of the N4 interface (5G SMF↔UPF) and the 4G Sxa/Sxb/Sxc CUPS interfaces, by which the control plane programs the user-plane function's packet-forwarding rules (PDRs / FARs / QERs / URRs) over UDP 8805. |
|
pgpassword
Package pgpassword implements the PostgreSQL "md5" password verifier (hashcat mode 12): the value stored in pg_authid.rolpassword (pg_shadow.passwd) when a role uses md5 authentication.
|
Package pgpassword implements the PostgreSQL "md5" password verifier (hashcat mode 12): the value stored in pg_authid.rolpassword (pg_shadow.passwd) when a role uses md5 authentication. |
|
pgppacket
Package pgppacket decodes the OpenPGP (RFC 4880 / RFC 9580) packet stream of a PGP key or message — public/secret keys, user IDs, signatures, and the encrypted/compressed/literal data packets — into a structured per-packet view: tag, length, and for key packets the version, algorithm, creation time, **fingerprint, and 64-bit key ID**.
|
Package pgppacket decodes the OpenPGP (RFC 4880 / RFC 9580) packet stream of a PGP key or message — public/secret keys, user IDs, signatures, and the encrypted/compressed/literal data packets — into a structured per-packet view: tag, length, and for key packets the version, algorithm, creation time, **fingerprint, and 64-bit key ID**. |
|
pgscram
Package pgscram implements the PostgreSQL SCRAM-SHA-256 stored verifier (RFC 5802 / RFC 7677 + PostgreSQL's pg_authid encoding, hashcat mode 28600): the value stored in pg_authid.rolpassword for a role using scram-sha-256 authentication, the default since PostgreSQL 10 (2017) and the successor to the older md5 verifier (see internal/pgpassword).
|
Package pgscram implements the PostgreSQL SCRAM-SHA-256 stored verifier (RFC 5802 / RFC 7677 + PostgreSQL's pg_authid encoding, hashcat mode 28600): the value stored in pg_authid.rolpassword for a role using scram-sha-256 authentication, the default since PostgreSQL 10 (2017) and the successor to the older md5 verifier (see internal/pgpassword). |
|
phpass
Package phpass verifies and computes "portable PHP" password hashes — the phpass scheme used by WordPress ($P$…) and phpBB3 ($H$…).
|
Package phpass verifies and computes "portable PHP" password hashes — the phpass scheme used by WordPress ($P$…) and phpBB3 ($H$…). |
|
pim
Package pim decodes Protocol Independent Multicast (PIM) version 2 packets per RFC 7761 (PIM-SM v2; the dominant multicast routing protocol).
|
Package pim decodes Protocol Independent Multicast (PIM) version 2 packets per RFC 7761 (PIM-SM v2; the dominant multicast routing protocol). |
|
pmbus
Package pmbus decodes PMBus — the Power Management Bus, an SMBus/I2C command set (PMBus spec) that PSUs, voltage regulators (VRMs), battery chargers and hot-swap controllers expose to set and read their power rails.
|
Package pmbus decodes PMBus — the Power Management Bus, an SMBus/I2C command set (PMBus spec) that PSUs, voltage regulators (VRMs), battery chargers and hot-swap controllers expose to set and read their power rails. |
|
pocsag
Package pocsag decodes POCSAG (Post Office Code Standardisation Advisory Group) paging-protocol bit-streams — ITU-R M.584-2 — into structured pages with address, function (numeric / alphanumeric), and decoded message text.
|
Package pocsag decodes POCSAG (Post Office Code Standardisation Advisory Group) paging-protocol bit-streams — ITU-R M.584-2 — into structured pages with address, function (numeric / alphanumeric), and decoded message text. |
|
pop3
Package pop3 decodes POP3 (Post Office Protocol v3) messages per RFC 1939, plus the RFC 2449 (CAPA), RFC 2595 (STLS), and RFC 5034 (AUTH SASL) extensions.
|
Package pop3 decodes POP3 (Post Office Protocol v3) messages per RFC 1939, plus the RFC 2449 (CAPA), RFC 2595 (STLS), and RFC 5034 (AUTH SASL) extensions. |
|
portmap
Package portmap decodes ONC RPC (RFC 5531) portmapper / rpcbind v2 messages (program 100000, UDP/TCP 111) — the classic Sun-RPC service directory.
|
Package portmap decodes ONC RPC (RFC 5531) portmapper / rpcbind v2 messages (program 100000, UDP/TCP 111) — the classic Sun-RPC service directory. |
|
postgres
Package postgres decodes PostgreSQL frontend / backend protocol v3 messages per the PostgreSQL documentation (Part VIII: "Frontend/Backend Protocol").
|
Package postgres decodes PostgreSQL frontend / backend protocol v3 messages per the PostgreSQL documentation (Part VIII: "Frontend/Backend Protocol"). |
|
pppoe
Package pppoe decodes Point-to-Point Protocol over Ethernet packets per RFC 2516 — both the Discovery phase (PADI / PADO / PADR / PADS / PADT) and the Session phase (PPP-in- PPPoE payload).
|
Package pppoe decodes Point-to-Point Protocol over Ethernet packets per RFC 2516 — both the Discovery phase (PADI / PADO / PADR / PADS / PADT) and the Session phase (PPP-in- PPPoE payload). |
|
presco
Package presco decodes the Presco 125 kHz LF access-control data block — the credential format used by Presco readers (gate / garage / building access).
|
Package presco decodes the Presco 125 kHz LF access-control data block — the credential format used by Presco readers (gate / garage / building access). |
|
profinetdcp
Package profinetdcp decodes Profinet DCP (Discovery and Configuration Protocol) frames per IEC 61158-6-10.
|
Package profinetdcp decodes Profinet DCP (Discovery and Configuration Protocol) frames per IEC 61158-6-10. |
|
protobufdecode
Package protobufdecode parses raw Protocol Buffers wire-format bytes without needing the .proto schema — the equivalent of `protoc --decode_raw`.
|
Package protobufdecode parses raw Protocol Buffers wire-format bytes without needing the .proto schema — the equivalent of `protoc --decode_raw`. |
|
ptpv2
Package ptpv2 decodes PTPv2 (Precision Time Protocol version 2) packets per IEEE 1588-2008.
|
Package ptpv2 decodes PTPv2 (Precision Time Protocol version 2) packets per IEEE 1588-2008. |
|
puttykey
Package puttykey parses a PuTTY private key file (the ".ppk" / "PuTTY-User-Key-File-N" format) for triage.
|
Package puttykey parses a PuTTY private key file (the ".ppk" / "PuTTY-User-Key-File-N" format) for triage. |
|
quic
Package quic decodes QUIC long-header packets per RFC 9000.
|
Package quic decodes QUIC long-header packets per RFC 9000. |
|
radius
Package radius decodes RADIUS packets per RFC 2865 (auth) + RFC 2866 (accounting) + supporting RFCs.
|
Package radius decodes RADIUS packets per RFC 2865 (auth) + RFC 2866 (accounting) + supporting RFCs. |
|
rag
Package rag provides lexical retrieval over the bundled PromptZero documentation corpus.
|
Package rag provides lexical retrieval over the bundled PromptZero documentation corpus. |
|
rdpx224
Package rdpx224 decodes the initial-handshake frames of Microsoft RDP (Remote Desktop Protocol) per [MS-RDPBCGR] — specifically the TPKT-wrapped X.224 (COTP) Connection Request / Connection Confirm PDUs plus the embedded RDP_NEG_REQ / RDP_NEG_RSP / RDP_NEG_FAILURE structures.
|
Package rdpx224 decodes the initial-handshake frames of Microsoft RDP (Remote Desktop Protocol) per [MS-RDPBCGR] — specifically the TPKT-wrapped X.224 (COTP) Connection Request / Connection Confirm PDUs plus the embedded RDP_NEG_REQ / RDP_NEG_RSP / RDP_NEG_FAILURE structures. |
|
rds
Package rds decodes RDS / RBDS (Radio Data System) groups — the digital sub-carrier (57 kHz) on FM broadcast that carries the station's Programme Service name, RadioText, programme type, traffic flags and (for North American RBDS) the call sign.
|
Package rds decodes RDS / RBDS (Radio Data System) groups — the digital sub-carrier (57 kHz) on FM broadcast that carries the station's Programme Service name, RadioText, programme type, traffic flags and (for North American RBDS) the call sign. |
|
redis
Package redis decodes Redis RESP (REdis Serialization Protocol) v2 + v3 messages per the Redis documentation.
|
Package redis decodes Redis RESP (REdis Serialization Protocol) v2 + v3 messages per the Redis documentation. |
|
report
Package report renders engagement reports from PromptZero session audit data.
|
Package report renders engagement reports from PromptZero session audit data. |
|
rip
Package rip decodes RIP (Routing Information Protocol) v1 and v2 wire-protocol messages per RFC 1058 (RIPv1) and RFC 2453 (RIPv2).
|
Package rip decodes RIP (Routing Information Protocol) v1 and v2 wire-protocol messages per RFC 1058 (RIPv1) and RFC 2453 (RIPv2). |
|
ripng
Package ripng decodes RIPng (RFC 2080) — the IPv6 distance-vector routing protocol (UDP 521).
|
Package ripng decodes RIPng (RFC 2080) — the IPv6 distance-vector routing protocol (UDP 521). |
|
roce
Package roce decodes the InfiniBand Base Transport Header (BTH) of RoCE — RDMA over Converged Ethernet — the datacenter Remote Direct Memory Access fabric.
|
Package roce decodes the InfiniBand Base Transport Header (BTH) of RoCE — RDMA over Converged Ethernet — the datacenter Remote Direct Memory Access fabric. |
|
rpl
Package rpl decodes the RPL (Routing Protocol for Low-Power and Lossy Networks, RFC 6550) control messages — the IPv6 routing protocol that builds the mesh ("DODAG") of a 6LoWPAN / IEEE 802.15.4 IoT network.
|
Package rpl decodes the RPL (Routing Protocol for Low-Power and Lossy Networks, RFC 6550) control messages — the IPv6 routing protocol that builds the mesh ("DODAG") of a 6LoWPAN / IEEE 802.15.4 IoT network. |
|
rsn
Package rsn decodes the IEEE 802.11 RSN (Robust Security Network) Information Element — the WPA2/WPA3 element in beacons, probe responses and association requests — into named cipher and AKM suites, the management-frame-protection (PMF) state, and a derived security posture.
|
Package rsn decodes the IEEE 802.11 RSN (Robust Security Network) Information Element — the WPA2/WPA3 element in beacons, probe responses and association requests — into named cipher and AKM suites, the management-frame-protection (PMF) state, and a derived security posture. |
|
rsvpte
Package rsvpte decodes RSVP-TE (Resource Reservation Protocol — Traffic Engineering) packets per RFC 3209 (RSVP-TE extensions) and RFC 2205 (base RSVP).
|
Package rsvpte decodes RSVP-TE (Resource Reservation Protocol — Traffic Engineering) packets per RFC 3209 (RSVP-TE extensions) and RFC 2205 (base RSVP). |
|
rtcm
Package rtcm decodes the RTCM 3.x differential-GNSS message framing — the protocol a GNSS base station broadcasts (over radio, NTRIP or a serial link) to feed real-time corrections to rovers.
|
Package rtcm decodes the RTCM 3.x differential-GNSS message framing — the protocol a GNSS base station broadcasts (over radio, NTRIP or a serial link) to feed real-time corrections to rovers. |
|
rtmp
Package rtmp decodes RTMP (Real-Time Messaging Protocol) wire frames.
|
Package rtmp decodes RTMP (Real-Time Messaging Protocol) wire frames. |
|
rtp
Package rtp decodes RTP and RTCP packets per RFC 3550 (Real-time Transport Protocol) and the static payload type assignments of RFC 3551, plus the standard RTCP feedback extensions of RFC 4585 (RTPFB / PSFB) and RFC 3611 (XR).
|
Package rtp decodes RTP and RTCP packets per RFC 3550 (Real-time Transport Protocol) and the static payload type assignments of RFC 3551, plus the standard RTCP feedback extensions of RFC 4585 (RTPFB / PSFB) and RFC 3611 (XR). |
|
rtps
Package rtps decodes the RTPS (Real-Time Publish-Subscribe) wire protocol — the on-the-wire protocol of OMG DDS, the publish/subscribe middleware that runs **ROS 2 robotics, autonomous vehicles, naval combat systems and industrial control**.
|
Package rtps decodes the RTPS (Real-Time Publish-Subscribe) wire protocol — the on-the-wire protocol of OMG DDS, the publish/subscribe middleware that runs **ROS 2 robotics, autonomous vehicles, naval combat systems and industrial control**. |
|
rtsp
Package rtsp decodes RTSP (Real-Time Streaming Protocol) messages per RFC 7826 (RTSP 2.0) and the more widely-deployed RFC 2326 (RTSP 1.0).
|
Package rtsp decodes RTSP (Real-Time Streaming Protocol) messages per RFC 7826 (RTSP 2.0) and the more widely-deployed RFC 2326 (RTSP 1.0). |
|
rules
Package rules is PromptZero's reactive rules engine.
|
Package rules is PromptZero's reactive rules engine. |
|
s7comm
Package s7comm decodes classic S7Comm PDUs — the Siemens S7- 300 / S7-400 / S7-1200 / S7-1500 PLC protocol that rides on ISO-on-TCP (RFC 1006, default TCP port 102).
|
Package s7comm decodes classic S7Comm PDUs — the Siemens S7- 300 / S7-400 / S7-1200 / S7-1500 PLC protocol that rides on ISO-on-TCP (RFC 1006, default TCP port 102). |
|
saml
Package saml decodes a SAML 2.0 message (a SAMLRequest / SAMLResponse value captured from an SSO flow) into its XML and the high-signal fields a pentester triages: the message type, Issuer, Destination, NameID, the assertion Conditions / AudienceRestriction, and — crucially — whether the message is signed (the golden-SAML / unsigned-assertion attack surface).
|
Package saml decodes a SAML 2.0 message (a SAMLRequest / SAMLResponse value captured from an SSO flow) into its XML and the high-signal fields a pentester triages: the message type, Issuer, Destination, NameID, the assertion Conditions / AudienceRestriction, and — crucially — whether the message is signed (the golden-SAML / unsigned-assertion attack surface). |
|
sctp
Package sctp decodes Stream Control Transmission Protocol (SCTP) packets per RFC 4960 (with the AUTH / ASCONF / RE-CONFIG / PAD / FORWARD-TSN chunk types from RFCs 4895 / 5061 / 6525 / 4820 / 3758).
|
Package sctp decodes Stream Control Transmission Protocol (SCTP) packets per RFC 4960 (with the AUTH / ASCONF / RE-CONFIG / PAD / FORWARD-TSN chunk types from RFCs 4895 / 5061 / 6525 / 4820 / 3758). |
|
semcache
Package semcache implements a small, durable, on-disk semantic cache for LLM-generated payloads (roadmap P2-27).
|
Package semcache implements a small, durable, on-disk semantic cache for LLM-generated payloads (roadmap P2-27). |
|
sflow
Package sflow decodes sFlow v5 datagrams per the InMon publicly-published sFlow v5 specification (sflow.org).
|
Package sflow decodes sFlow v5 datagrams per the InMon publicly-published sFlow v5 specification (sflow.org). |
|
sip
Package sip decodes SIP messages per RFC 3261.
|
Package sip decodes SIP messages per RFC 3261. |
|
skinny
Package skinny decodes the Skinny Client Control Protocol (SCCP) — the Cisco-proprietary signalling protocol between a Cisco IP phone and a CallManager / CUCM (TCP 2000).
|
Package skinny decodes the Skinny Client Control Protocol (SCCP) — the Cisco-proprietary signalling protocol between a Cisco IP phone and a CallManager / CUCM (TCP 2000). |
|
smb2
Package smb2 decodes SMB2 / SMB3 (Server Message Block v2/v3) messages per [MS-SMB2] — the canonical Windows file-share and lateral-movement protocol.
|
Package smb2 decodes SMB2 / SMB3 (Server Message Block v2/v3) messages per [MS-SMB2] — the canonical Windows file-share and lateral-movement protocol. |
|
smp
Package smp decodes the Bluetooth LE Security Manager Protocol (SMP, Core spec Vol 3 Part H) — the pairing-and-key-distribution layer carried on L2CAP CID 0x0006.
|
Package smp decodes the Bluetooth LE Security Manager Protocol (SMP, Core spec Vol 3 Part H) — the pairing-and-key-distribution layer carried on L2CAP CID 0x0006. |
|
smtp
Package smtp decodes SMTP (Simple Mail Transfer Protocol) messages per RFC 5321 — the 40-year-old text-based protocol every mail server speaks.
|
Package smtp decodes SMTP (Simple Mail Transfer Protocol) messages per RFC 5321 — the 40-year-old text-based protocol every mail server speaks. |
|
snapshot
Package snapshot captures pre-write copies of Flipper SD files so /rewind can restore them on demand.
|
Package snapshot captures pre-write copies of Flipper SD files so /rewind can restore them on demand. |
|
snmp
Package snmp decodes SNMP v1, v2c, and v3 packets — the dominant network-management protocol on enterprise networks, found on every router / switch / firewall / printer / UPS / PDU / managed AP / managed VM-host since the late '80s.
|
Package snmp decodes SNMP v1, v2c, and v3 packets — the dominant network-management protocol on enterprise networks, found on every router / switch / firewall / printer / UPS / PDU / managed AP / managed VM-host since the late '80s. |
|
snowflake
Package snowflake decodes a Snowflake ID — the 64-bit identifier used by Discord, Twitter/X, Instagram and others — into its embedded creation timestamp.
|
Package snowflake decodes a Snowflake ID — the 64-bit identifier used by Discord, Twitter/X, Instagram and others — into its embedded creation timestamp. |
|
socks
Package socks decodes the SOCKS proxy protocol (SOCKS4 / SOCKS4a / SOCKS5, RFC 1928) — the proxy / pivot / exfil channel.
|
Package socks decodes the SOCKS proxy protocol (SOCKS4 / SOCKS4a / SOCKS5, RFC 1928) — the proxy / pivot / exfil channel. |
|
someip
Package someip decodes SOME/IP (Scalable service-Oriented MiddlewarE over IP) messages per the AUTOSAR R23-11 SOME/IP Protocol Specification (PRS_SOMEIPProtocol) and the parallel SOME/IP Service Discovery spec (PRS_SOMEIPServiceDiscoveryProtocol).
|
Package someip decodes SOME/IP (Scalable service-Oriented MiddlewarE over IP) messages per the AUTOSAR R23-11 SOME/IP Protocol Specification (PRS_SOMEIPProtocol) and the parallel SOME/IP Service Discovery spec (PRS_SOMEIPServiceDiscoveryProtocol). |
|
spiflash
Package spiflash decodes SPI NOR flash transactions — the command set and the JEDEC RDID identification of the serial flash chips that hold firmware on embedded devices, routers, IoT gear and the Flipper's own targets.
|
Package spiflash decodes SPI NOR flash transactions — the command set and the JEDEC RDID identification of the serial flash chips that hold firmware on embedded devices, routers, IoT gear and the Flipper's own targets. |
|
ssdp
Package ssdp decodes SSDP (Simple Service Discovery Protocol) messages per the UPnP Device Architecture 1.1 (UPnP Forum, 2008).
|
Package ssdp decodes SSDP (Simple Service Discovery Protocol) messages per the UPnP Device Architecture 1.1 (UPnP Forum, 2008). |
|
sshdecode
Package sshdecode parses SSH wire-protocol frames per RFC 4253 (SSH Transport Layer Protocol) and RFC 4250-4256.
|
Package sshdecode parses SSH wire-protocol frames per RFC 4253 (SSH Transport Layer Protocol) and RFC 4250-4256. |
|
sshkey
Package sshkey parses an OpenSSH private key file (the "-----BEGIN OPENSSH PRIVATE KEY-----" / openssh-key-v1 format) for triage.
|
Package sshkey parses an OpenSSH private key file (the "-----BEGIN OPENSSH PRIVATE KEY-----" / openssh-key-v1 format) for triage. |
|
stp
Package stp decodes Spanning Tree Protocol BPDUs per IEEE 802.1D-2004 (STP / RSTP) and IEEE 802.1Q-2014 §13 (MSTP).
|
Package stp decodes Spanning Tree Protocol BPDUs per IEEE 802.1D-2004 (STP / RSTP) and IEEE 802.1Q-2014 §13 (MSTP). |
|
streaming
Package streaming provides the partial-frame sink used by tools that opt into streaming dispatch (roadmap P3-28 first half).
|
Package streaming provides the partial-frame sink used by tools that opt into streaming dispatch (roadmap P3-28 first half). |
|
stun
Package stun decodes STUN packets per RFC 5389 / 8489 + TURN extensions per RFC 5766 / 8656.
|
Package stun decodes STUN packets per RFC 5389 / 8489 + TURN extensions per RFC 5766 / 8656. |
|
subghz
Package subghz provides pure-Go classifiers for common Sub-GHz radio protocols captured by the Flipper Zero.
|
Package subghz provides pure-Go classifiers for common Sub-GHz radio protocols captured by the Flipper Zero. |
|
subghz/protocols
Package protocols implements pure-Go decoders for the top-20 Sub-GHz remote control protocols captured by the Flipper Zero.
|
Package protocols implements pure-Go decoders for the top-20 Sub-GHz remote control protocols captured by the Flipper Zero. |
|
sv
Package sv decodes IEC 61850-9-2 (and 9-2LE) Sampled Values (SV / SMV) — the substation-automation multicast that streams digitised current and voltage samples from a merging unit (the device that samples the instrument transformers on the primary plant) to the protection and measurement IEDs.
|
Package sv decodes IEC 61850-9-2 (and 9-2LE) Sampled Values (SV / SMV) — the substation-automation multicast that streams digitised current and voltage samples from a merging unit (the device that samples the instrument transformers on the primary plant) to the protection and measurement IEDs. |
|
syslog
Package syslog decodes syslog messages in both the modern RFC 5424 (IETF) format and the legacy RFC 3164 (BSD) format.
|
Package syslog decodes syslog messages in both the modern RFC 5424 (IETF) format and the legacy RFC 3164 (BSD) format. |
|
t2t
Package t2t decodes the NFC Forum Type 2 Tag structure — the page layout shared by NXP NTAG21x and MIFARE Ultralight, by far the most common NFC tags (transit, access fobs, amiibo, marketing tags).
|
Package t2t decodes the NFC Forum Type 2 Tag structure — the page layout shared by NXP NTAG21x and MIFARE Ultralight, by far the most common NFC tags (transit, access fobs, amiibo, marketing tags). |
|
t55xx
Package t55xx decodes the T5577 / T55x7 (Atmel/Microchip ATA5577) configuration register — block 0 of page 0, the 32-bit word that controls how an LF 125 kHz tag modulates and clocks its data.
|
Package t55xx decodes the T5577 / T55x7 (Atmel/Microchip ATA5577) configuration register — block 0 of page 0, the 32-bit word that controls how an LF 125 kHz tag modulates and clocks its data. |
|
tacacs
Package tacacs decodes TACACS+ packets per RFC 8907 (which finally documented the Cisco-proprietary protocol after decades of use in production).
|
Package tacacs decodes TACACS+ packets per RFC 8907 (which finally documented the Cisco-proprietary protocol after decades of use in production). |
|
targetmem
Package targetmem stores per-target facts across PromptZero sessions.
|
Package targetmem stores per-target facts across PromptZero sessions. |
|
tcl
Package tcl decodes the ISO/IEC 14443-4 block transmission protocol (T=CL) — the half-duplex block layer that carries APDUs between a contactless reader (PCD) and a Type-4 proximity card (PICC) after activation.
|
Package tcl decodes the ISO/IEC 14443-4 block transmission protocol (T=CL) — the half-duplex block layer that carries APDUs between a contactless reader (PCD) and a Type-4 proximity card (PICC) after activation. |
|
tds
Package tds decodes TDS (Tabular Data Stream) messages per Microsoft Open Specifications [MS-TDS] — the Microsoft SQL Server protocol.
|
Package tds decodes TDS (Tabular Data Stream) messages per Microsoft Open Specifications [MS-TDS] — the Microsoft SQL Server protocol. |
|
testmocks
Package testmocks centralises the shared mock harness used across PromptZero's test surfaces — flipper-agent tests, end-to-end REPL tests, workflow tests.
|
Package testmocks centralises the shared mock harness used across PromptZero's test surfaces — flipper-agent tests, end-to-end REPL tests, workflow tests. |
|
tftp
Package tftp decodes TFTP (Trivial File Transfer Protocol) packets per RFC 1350, with the Option Extension family from RFC 2347 (envelope) + RFC 2348 (blksize) + RFC 2349 (timeout + tsize) + RFC 7440 (windowsize).
|
Package tftp decodes TFTP (Trivial File Transfer Protocol) packets per RFC 1350, with the Option Extension family from RFC 2347 (envelope) + RFC 2348 (blksize) + RFC 2349 (timeout + tsize) + RFC 7440 (windowsize). |
|
tlsdecode
Package tlsdecode decodes the cleartext portion of a TLS handshake — the ClientHello and ServerHello records that every TLS connection emits in the clear before encryption is negotiated.
|
Package tlsdecode decodes the cleartext portion of a TLS handshake — the ClientHello and ServerHello records that every TLS connection emits in the clear before encryption is negotiated. |
|
toolctx
Package toolctx serves static per-tool cheat sheets the agent appends to tool descriptions at catalog registration time.
|
Package toolctx serves static per-tool cheat sheets the agent appends to tool descriptions at catalog registration time. |
|
tools
Package tools — argument-extraction helpers.
|
Package tools — argument-extraction helpers. |
|
tpms
Package tpms decodes TPMS (Tire Pressure Monitoring System) Sub-GHz bit-streams into the format-independent fields a pentester can trust: the Manchester line-decoded payload bytes, the 32-bit sensor ID, and CRC-8 validity.
|
Package tpms decodes TPMS (Tire Pressure Monitoring System) Sub-GHz bit-streams into the format-independent fields a pentester can trust: the Manchester line-decoded payload bytes, the 32-bit sensor ID, and CRC-8 validity. |
|
trainset
Package trainset exports the audit log as a fine-tuning dataset.
|
Package trainset exports the audit log as a fine-tuning dataset. |
|
tzsp
Package tzsp decodes the TaZmen Sniffer Protocol (TZSP) — the UDP encapsulation (default port 0x9090 / 37008) that MikroTik RouterOS, Aruba and other gear use to **stream sniffed wireless frames to a remote analyser**.
|
Package tzsp decodes the TaZmen Sniffer Protocol (TZSP) — the UDP encapsulation (default port 0x9090 / 37008) that MikroTik RouterOS, Aruba and other gear use to **stream sniffed wireless frames to a remote analyser**. |
|
ubx
Package ubx decodes the u-blox UBX binary protocol — the native binary message format that u-blox GNSS receivers speak as the compact alternative to NMEA 0183 text.
|
Package ubx decodes the u-blox UBX binary protocol — the native binary message format that u-blox GNSS receivers speak as the compact alternative to NMEA 0183 text. |
|
uds
Package uds decodes UDS (Unified Diagnostic Services, ISO 14229-1) application-layer messages — the protocol behind modern ECU diagnostics and attacks (session control, security access, routine control, memory read/write, firmware transfer).
|
Package uds decodes UDS (Unified Diagnostic Services, ISO 14229-1) application-layer messages — the protocol behind modern ECU diagnostics and attacks (session control, security access, routine control, memory read/write, firmware transfer). |
|
ulid
Package ulid decodes a ULID (Universally Unique Lexicographically Sortable Identifier) into its embedded creation timestamp and randomness.
|
Package ulid decodes a ULID (Universally Unique Lexicographically Sortable Identifier) into its embedded creation timestamp and randomness. |
|
unixcrypt
Package unixcrypt implements the MD5-based crypt(3) password hashes: the FreeBSD/Linux md5crypt ($1$) and the Apache apr1 ($apr1$) variant.
|
Package unixcrypt implements the MD5-based crypt(3) password hashes: the FreeBSD/Linux md5crypt ($1$) and the Apache apr1 ($apr1$) variant. |
|
usbdesc
Package usbdesc decodes USB descriptors — the self-describing data structures a USB device returns during enumeration (the device, configuration, interface, endpoint, HID and string descriptors of USB 2.0 / 3.x).
|
Package usbdesc decodes USB descriptors — the self-describing data structures a USB device returns during enumeration (the device, configuration, interface, endpoint, HID and string descriptors of USB 2.0 / 3.x). |
|
usbhid
Package usbhid decodes USB HID Keyboard Boot Protocol reports — the 8-byte input reports that every BadUSB-class device (Hak5 Rubber Ducky, Bash Bunny, OMG Cable, Adafruit Trinket BadUSB, the Bruce ESP32 BadUSB add-on) generates to inject keystrokes into a victim host.
|
Package usbhid decodes USB HID Keyboard Boot Protocol reports — the 8-byte input reports that every BadUSB-class device (Hak5 Rubber Ducky, Bash Bunny, OMG Cable, Adafruit Trinket BadUSB, the Bruce ESP32 BadUSB add-on) generates to inject keystrokes into a victim host. |
|
usbpd
Package usbpd decodes USB Power Delivery (USB-PD) messages — the protocol spoken over the USB-C CC line to negotiate power (and to tunnel alternate modes and vendor-defined messages).
|
Package usbpd decodes USB Power Delivery (USB-PD) messages — the protocol spoken over the USB-C CC line to negotiate power (and to tunnel alternate modes and vendor-defined messages). |
|
uuidinfo
Package uuidinfo decodes a UUID/GUID into its structure and — crucially for recon — any information it leaks.
|
Package uuidinfo decodes a UUID/GUID into its structure and — crucially for recon — any information it leaks. |
|
validator
Package validator scans BadUSB/DuckyScript payloads for patterns that the operator would want to see before the Flipper types them on a real target.
|
Package validator scans BadUSB/DuckyScript payloads for patterns that the operator would want to see before the Flipper types them on a real target. |
|
version
Package version carries build-time metadata embedded via -ldflags.
|
Package version carries build-time metadata embedded via -ldflags. |
|
viking
Package viking decodes the Viking 125 kHz LF access-control data block — the credential format used by Viking / "Viking Acs" readers and fobs.
|
Package viking decodes the Viking 125 kHz LF access-control data block — the credential format used by Viking / "Viking Acs" readers and fobs. |
|
vin
Package vin decodes and validates a 17-character Vehicle Identification Number (ISO 3779 / ISO 3780).
|
Package vin decodes and validates a 17-character Vehicle Identification Number (ISO 3779 / ISO 3780). |
|
vlan
Package vlan decodes IEEE 802.1Q (C-tag) and 802.1ad (S-tag, QinQ) VLAN tags per IEEE 802.1Q-2018.
|
Package vlan decodes IEEE 802.1Q (C-tag) and 802.1ad (S-tag, QinQ) VLAN tags per IEEE 802.1Q-2018. |
|
vncrfb
Package vncrfb decodes VNC RFB (Remote Framebuffer) Protocol handshake messages per RFC 6143 plus the RealVNC / TightVNC / VeNCrypt / Apple ARD extensions.
|
Package vncrfb decodes VNC RFB (Remote Framebuffer) Protocol handshake messages per RFC 6143 plus the RealVNC / TightVNC / VeNCrypt / Apple ARD extensions. |
|
vqp
Package vqp decodes the Cisco VLAN Query Protocol (VQP) — the wire protocol of VMPS (VLAN Membership Policy Server), by which a switch asks a server "what VLAN should this source MAC be put on?" and the server answers with a VLAN name (UDP 1589).
|
Package vqp decodes the Cisco VLAN Query Protocol (VQP) — the wire protocol of VMPS (VLAN Membership Policy Server), by which a switch asks a server "what VLAN should this source MAC be put on?" and the server answers with a VLAN name (UDP 1589). |
|
vrrp
Package vrrp decodes Virtual Router Redundancy Protocol (VRRP) packets per RFC 5798 (v3, IPv4 + IPv6) and the older RFC 3768 (v2, IPv4-only, still widely deployed).
|
Package vrrp decodes Virtual Router Redundancy Protocol (VRRP) packets per RFC 5798 (v3, IPv4 + IPv6) and the older RFC 3768 (v2, IPv4-only, still widely deployed). |
|
vtp
Package vtp decodes Cisco's VLAN Trunking Protocol — the L2 protocol that synchronises the VLAN database across the switches of a VTP domain.
|
Package vtp decodes Cisco's VLAN Trunking Protocol — the L2 protocol that synchronises the VLAN database across the switches of a VTP domain. |
|
vxlan
Package vxlan decodes Virtual Extensible LAN packets per RFC 7348, plus per-vendor variants: Cisco's Group-Based Policy (VXLAN-GBP, draft-smith-vxlan-group-policy) and the Generic Protocol Extension (VXLAN-GPE, draft-ietf-nvo3- vxlan-gpe).
|
Package vxlan decodes Virtual Extensible LAN packets per RFC 7348, plus per-vendor variants: Cisco's Group-Based Policy (VXLAN-GBP, draft-smith-vxlan-group-policy) and the Generic Protocol Extension (VXLAN-GPE, draft-ietf-nvo3- vxlan-gpe). |
|
watch
Package watch implements the --watch filesystem-trigger mode.
|
Package watch implements the --watch filesystem-trigger mode. |
|
weather
Package weather decodes 433 MHz weather-station sensor frames (the LaCrosse / Acurite families the Flipper "Weather Station" FAP and rtl_433 cover) from a pre-demodulated 40-bit frame into the interpreted reading — sensor ID, temperature, humidity, battery — for the formats whose checksum validates.
|
Package weather decodes 433 MHz weather-station sensor frames (the LaCrosse / Acurite families the Flipper "Weather Station" FAP and rtl_433 cover) from a pre-demodulated 40-bit frame into the interpreted reading — sensor ID, temperature, humidity, battery — for the formats whose checksum validates. |
|
web
Marauder synth-panel WebSocket layer.
|
Marauder synth-panel WebSocket layer. |
|
webhook
Package webhook dispatches PromptZero lifecycle events as outbound HTTP POSTs.
|
Package webhook dispatches PromptZero lifecycle events as outbound HTTP POSTs. |
|
webpass
Package webpass verifies and computes the PBKDF2 password hashes used by the two dominant Python web frameworks: Django (pbkdf2_sha256$…) and Werkzeug / Flask (pbkdf2:sha256:…).
|
Package webpass verifies and computes the PBKDF2 password hashes used by the two dominant Python web frameworks: Django (pbkdf2_sha256$…) and Werkzeug / Flask (pbkdf2:sha256:…). |
|
wifidefense
Package wifidefense provides defensive, blue-team analysers over sequences of already-decoded 802.11 frames.
|
Package wifidefense provides defensive, blue-team analysers over sequences of already-decoded 802.11 frames. |
|
wireguard
Package wireguard decodes WireGuard UDP packets per the official protocol specification at https://www.wireguard.com/protocol/.
|
Package wireguard decodes WireGuard UDP packets per the official protocol specification at https://www.wireguard.com/protocol/. |
|
wmbus
Package wmbus decodes the Wireless M-Bus (wM-Bus, EN 13757-4) radio link layer — the 868 MHz over-the-air framing that smart water / heat / gas / electricity meters broadcast and that a Flipper Sub-GHz (or SDR) capture lifts off the air.
|
Package wmbus decodes the Wireless M-Bus (wM-Bus, EN 13757-4) radio link layer — the 868 MHz over-the-air framing that smart water / heat / gas / electricity meters broadcast and that a Flipper Sub-GHz (or SDR) capture lifts off the air. |
|
wordlists
Package wordlists embeds PromptZero's built-in wordlists and exposes them as MCP resources via promptzero://wordlists/<name> URIs.
|
Package wordlists embeds PromptZero's built-in wordlists and exposes them as MCP resources via promptzero://wordlists/<name> URIs. |
|
workflows
Package workflows implements composite pentest flows that orchestrate several Flipper primitives + LLM reasoning behind a single LLM-callable tool.
|
Package workflows implements composite pentest flows that orchestrate several Flipper primitives + LLM reasoning behind a single LLM-callable tool. |
|
wpa
Package wpa derives the WPA/WPA2-PSK Pairwise Master Key (PMK) from a passphrase and SSID.
|
Package wpa derives the WPA/WPA2-PSK Pairwise Master Key (PMK) from a passphrase and SSID. |
|
wps
Package wps decodes the Wi-Fi Simple Configuration (WPS) data elements carried in the WPS vendor-specific Information Element of 802.11 beacons and probe responses (Microsoft OUI 00:50:F2, vendor type 0x04).
|
Package wps decodes the Wi-Fi Simple Configuration (WPS) data elements carried in the WPS vendor-specific Information Element of 802.11 beacons and probe responses (Microsoft OUI 00:50:F2, vendor type 0x04). |
|
wsc
Package wsc decodes Wi-Fi Simple Config (WSC / WPS) credential blobs — the TLV structure carried as the `application/vnd.wfa.wsc` MIME type.
|
Package wsc decodes Wi-Fi Simple Config (WSC / WPS) credential blobs — the TLV structure carried as the `application/vnd.wfa.wsc` MIME type. |
|
wsframe
Package wsframe decodes WebSocket frames per RFC 6455.
|
Package wsframe decodes WebSocket frames per RFC 6455. |
|
x509decode
Package x509decode parses X.509 certificates into a structured view — the natural complement to tls_handshake_decode (whose Certificate handshake-message body is surfaced as raw hex).
|
Package x509decode parses X.509 certificates into a structured view — the natural complement to tls_handshake_decode (whose Certificate handshake-message body is surfaced as raw hex). |
|
xcp
Package xcp decodes XCP — the ASAM MCD-1 XCP Universal Measurement and Calibration Protocol — the master/slave protocol an ECU calibration tool uses to read and write an ECU's memory: measurement (DAQ/STIM), calibration (download), and flash programming (PROGRAM).
|
Package xcp decodes XCP — the ASAM MCD-1 XCP Universal Measurement and Calibration Protocol — the master/slave protocol an ECU calibration tool uses to read and write an ECU's memory: measurement (DAQ/STIM), calibration (download), and flash programming (PROGRAM). |
|
xmpp
Package xmpp decodes XMPP (Extensible Messaging and Presence Protocol) wire-protocol stanzas per RFC 6120 (core) and RFC 6121 (IM).
|
Package xmpp decodes XMPP (Extensible Messaging and Presence Protocol) wire-protocol stanzas per RFC 6120 (core) and RFC 6121 (IM). |
|
zigbee
Package zigbee decodes Zigbee Network Layer (NWK) frames — the layer that sits on top of IEEE 802.15.4 MAC frames in the Zigbee stack.
|
Package zigbee decodes Zigbee Network Layer (NWK) frames — the layer that sits on top of IEEE 802.15.4 MAC frames in the Zigbee stack. |
|
zmtp
Package zmtp decodes ZMTP (ZeroMQ Message Transport Protocol) wire frames — the transport layer for every ZeroMQ socket.
|
Package zmtp decodes ZMTP (ZeroMQ Message Transport Protocol) wire frames — the transport layer for every ZeroMQ socket. |
|
zwave
Package zwave decodes classic Z-Wave MAC-layer frames per the Sigma Designs / Silicon Labs public specification (SDS-12852, Z-Wave Public API + Z-Wave Plus / 700/800-series protocol reference).
|
Package zwave decodes classic Z-Wave MAC-layer frames per the Sigma Designs / Silicon Labs public specification (SDS-12852, Z-Wave Public API + Z-Wave Plus / 700/800-series protocol reference). |
|
test
|
|
|
adversarial
Package adversarial holds the cross-package adversarial test suite (roadmap P3-30).
|
Package adversarial holds the cross-package adversarial test suite (roadmap P3-30). |
Click to show internal directories.
Click to hide internal directories.