Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
BaconSampler — Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast. | Kitploit
Tools/GitHubGitHub/logisek/baconsampler
Packet Sniffing & AnalysisReconnaissanceForensicsInformation GatheringNetwork SecurityThreat IntelligenceIntrusion DetectionDNS AnalysisLog Analysis
GitHublogisek/baconsampler

BaconSampler

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

20178 months agoReviewed by Kitploit
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Bacon Sampler

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

Outbound Connections (Windows + libpcap)

Bacon Sampler is a lightweight outbound-connection catcher that sniffs the sizzle of your network traffic and flags suspicious "beacon-like" behavior - those periodic, low-and-slow callbacks that malware loves to phone home with.

It passively monitors outbound connections and DNS lookups, then highlights patterns like steady intervals, repeated destinations, weird jitter, and consistent byte sizes, basically anything that looks less like normal browsing and more like a bot checking in for instructions.

Think of it as a Beacon Scanner, but tastier: if something keeps coming back at the same time every time... we're sampling the bacon.

Features

  • Pcap capture with optional netstat PID correlation
  • Reverse DNS and GeoIP (offline database or free online lookup)
  • Filters for protocol, remote port ranges, and IP CIDRs
  • Group summaries (by remote IP, process, or country) with optional top N
  • Beacon-like activity detection (low-and-slow callbacks)
  • Pattern detection for suspicious connection + DNS query behavior
  • CSV/JSON exports with derived summary files
  • Optional HTML report with all tables

Prerequisites

  • Windows 11
  • Python 3.10+
  • Npcap (recommended) with "Install Npcap in WinPcap API-compatible Mode"
  • GeoIP database for offline IP country lookup:
    • MaxMind GeoLite2 Country (.mmdb) or DB-IP Lite (.mmdb)
    • IP2Location LITE (.BIN)
  • Run PowerShell as Administrator for full visibility

Install

pip install -r requirements.txt

Download a GeoIP database and note the path:

  • GeoLite2 or DB-IP Lite (.mmdb)
  • IP2Location LITE (.BIN)

If you prefer a free online lookup, you can skip this and use --geoip-online.

Usage

Usage examples (common combinations)

List interfaces:

python capture_outbound.py --list-interfaces

Pick an interface by index:

python capture_outbound.py --interface 0

Use multiple interfaces (repeatable):

python capture_outbound.py --interface "Ethernet" --interface "Wi-Fi"

Or with comma-separated names:

python capture_outbound.py --interfaces "Ethernet,Wi-Fi"

Pcap-only capture (A) with offline GeoIP:

python capture_outbound.py --mode pcap --duration 20 --interface "Ethernet" --geoip-db "C:\Path\GeoLite2-Country.mmdb"

Pcap + netstat correlation (B) with offline GeoIP:

python capture_outbound.py --mode pcap_plus_netstat --duration 20 --interface "Ethernet" --geoip-db "C:\Path\GeoLite2-Country.mmdb"

Pcap + netstat union (A+B):

python capture_outbound.py --mode both --duration 20 --interface "Ethernet" --geoip-db "C:\Path\GeoLite2-Country.mmdb"

Online GeoIP (free, rate-limited, cached to disk):

python capture_outbound.py --mode pcap --duration 20 --interface "Ethernet" --geoip-online ipapi

Online GeoIP with IPinfo token:

$env:IPINFO_TOKEN="your_token_here"
python capture_outbound.py --mode pcap --duration 20 --interface "Ethernet" --geoip-online ipinfo

Or pass the token explicitly:

python capture_outbound.py --mode pcap --duration 20 --interface "Ethernet" --geoip-online ipinfo --geoip-online-token "your_token_here"

Tune online GeoIP timeout and retries:

python capture_outbound.py --mode pcap --duration 20 --interface "Ethernet" --geoip-online ipapi --geoip-timeout 2.5 --geoip-retries 1

Disable reverse DNS (faster runs):

python capture_outbound.py --mode pcap --duration 20 --interface "Ethernet" --no-dns

Tune DNS timeout:

python capture_outbound.py --mode pcap --duration 20 --interface "Ethernet" --dns-timeout 0.5

Limit capture by packet count:

python capture_outbound.py --mode pcap --duration 60 --packet-limit 5000

Filter by protocol, remote port, and IP CIDR:

python capture_outbound.py --filter-protocol tcp --filter-port 80,443,1000-2000 --allow-ip 1.2.3.0/24 --deny-ip 1.2.3.4/32

Group summaries and top N:

python capture_outbound.py --group-by remote_ip,process --top 10

Track total bytes per connection:

python capture_outbound.py --mode pcap --duration 20 --interface "Ethernet" --track-bytes

Disable progress output:

python capture_outbound.py --no-progress

Disable console output:

python capture_outbound.py --no-console

Usage examples (advanced combinations)

Pcap + netstat union (A+B) + Online GeoIP + Write a pcap + CSV + HTML:

python capture_outbound.py --mode both --duration 20 --interface "Ethernet,Wi-Fi" --geoip-online ipapi --pcap-out "C:\Path\capture.pcap" --csv "C:\Path\outbound.csv" --html "C:\Path\outbound.html"

Pcap-only + output folder + custom CSV/JSON names:

python capture_outbound.py --mode pcap --duration 20 --interface "Ethernet" --output-dir "C:\Path\Reports" --csv "C:\Path\Reports\outbound.csv" --json "C:\Path\Reports\outbound.json"

Beacon-like activity detection (low-and-slow callbacks):

python capture_outbound.py --duration 300 --beacon-min-duration 120 --beacon-min-interval 60 --beacon-max-interval 1800 --beacon-max-jitter 10 --beacon-min-packets 6 --beacon-max-rate 0.05

Pattern detection (steady intervals, jitter, repeated destinations, consistent sizes):

python capture_outbound.py --duration 300 --track-bytes --pattern-high-jitter 120 --pattern-repeat-destination 4 --pattern-max-byte-jitter 64 --dns-pattern-min-queries 4

Tight beacon + pattern thresholds with filtering:

python capture_outbound.py --duration 600 --filter-protocol tcp --filter-port 443 --track-bytes --beacon-min-duration 180 --beacon-min-interval 90 --beacon-max-interval 900 --beacon-max-jitter 5 --beacon-min-packets 8 --pattern-high-jitter 60 --pattern-repeat-destination 5 --pattern-max-byte-jitter 32

DNS-focused capture (fast DNS lookup + DNS patterns):

python capture_outbound.py --duration 180 --dns-timeout 0.25 --dns-pattern-min-queries 5 --pattern-repeat-destination 3

Outputs

  • Console table by default
  • CSV: outbound_connections.csv
  • JSON: outbound_connections.json
  • HTML: --html "report.html"
  • Beacon findings: *_beacon_findings.csv / *_beacon_findings.json
  • Connection patterns: *_connection_patterns.csv / *_connection_patterns.json
  • DNS patterns: *_dns_patterns.csv / *_dns_patterns.json
  • Unique connections: *_unique_connections.csv / *_unique_connections.json
  • Unique processes: *_unique_processes.csv / *_unique_processes.json
  • Group summaries: *_group_remote_ip*.csv/json, *_group_process*.csv/json, *_group_country*.csv/json

Custom CSV/JSON output paths:

python capture_outbound.py --mode pcap --duration 20 --interface "Ethernet" --csv "C:\Path\outbound.csv" --json "C:\Path\outbound.json"

Send all outputs to a folder:

python capture_outbound.py --mode pcap --duration 20 --output-dir "C:\Path\Reports"

Write HTML output:

python capture_outbound.py --html "outbound.html"

Write a pcap file:

python capture_outbound.py --mode pcap --duration 20 --interface "Ethernet" --pcap-out "capture.pcap"

Command-line options

Download Tool