Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/rafael-santiago/pig
IDS/IPS EvasionNetwork SecurityPenetration Testing
GitHubrafael-santiago/pig

pig

A Linux packet crafting tool.

View Repository
47941145 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Pig

Pig (which can be understood as Packet intruder generator) is a Linux packet crafting tool. You can use Pig to test your IDS/IPS among other stuff.

Pig brings a bunch of well-known attack signatures ready to be used and you can expand this collection with more specific things according to your requirements.

Until now it is possible to create IPv4 signatures with transport layer based on TCP, UDP and ICMP. You can also create signatures based on ARP protocol, besides building up the packet since its Ethernet frame.

If you arrived here by my 2600 article from the SPRING 2016 issue keep reading the following documentation sections because this little Pig has been evolving since then.

How to clone this repo?

It is pretty simple:

[email protected]:~/src# git clone https://github.com/rafael-santiago/pig pig
[email protected]:~/src# cd pig
[email protected]:~/src/pig# git submodule update --init

How to build it?

You need to use the Hefesto to build pig. After following the steps to put Hefesto working on your system. Move to the pig sub-directory named as src and run the following command:

[email protected]:~/src/pig/src# hefesto

After this command you should find the pig binary under the path src/bin. You can use the binary relatively from src/bin or install it.

If for some reason you are having build troubles you should try to read some remarks present in BUILD.md.

How to install it?

For installing you need to be inside the src sub-directory and call:

[email protected]:~/src/pig/src# hefesto --install

For uninstalling, being inside the src sub-directory you should call:

[email protected]:~/src/pig/src# hefesto --uninstall

The pigsty files

Pigsty files are plain text files where you can define a set of packet signatures. There is a specific syntax to be followed. Look out an example of a pigsty file:

[ signature   =      "Hello",
  ip.version  =            4,
  ip.ihl      =            5,
  ip.tos      =            0,
  ip.src      = 192.30.70.10,
  ip.dst      =  192.30.70.3,
  ip.protocol =           17,
  udp.dst     =         1008,
  udp.src     =        32000,
  udp.payload =    "Hello!!" ]

Basically, all signature data must goes between square brackets: [ ... ].

Inside this area the piece of information is supplied by the scheme field = data.

If you have some experience with Computer Networks is sure that the majority of fields listed on Table 1 have strong meaning for you. You must use these fields to create your further signatures.

Table 1: The pig signature fields.

Download Tool