Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
Dshell — Dshell es un marco de análisis forense de redes. | Kitploit
Herramientas/GitHubGitHub/usarmyresearchlab/dshell
Sniffing y Análisis de PaquetesForensia de RedAnálisis ForenseForensia DigitalAnálisis de DNSAnálisis de Registros
GitHubusarmyresearchlab/dshell

Dshell

Dshell es un marco de análisis forense de redes.

Ver Repositorio
5.5k1.1k65hace 2 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

Dshell

Un marco extensible de análisis forense de redes. Permite el desarrollo rápido de plugins para apoyar la disección de capturas de paquetes de red.

Características clave:

  • Análisis profundo de paquetes usando plugins especializados
  • Reensamblaje robusto de flujos
  • Soporte para IPv4 e IPv6
  • Múltiples formatos de salida seleccionables por el usuario y la capacidad de crear manejadores de salida personalizados
  • Plugins encadenables
  • Opción de procesamiento paralelo para dividir el manejo de la fuente de datos en procesos Python separados
  • Habilita el desarrollo de paquetes de plugins externos para compartir e instalar nuevos plugins desarrollados externamente sin superponerse con los directorios principales de plugins de Dshell

Guías

  • Dshell User Guide
    • Una guía de instalación así como de análisis básico y avanzado con ejemplos
    • Ayuda a usuarios finales nuevos y experimentados a usar y entender el marco decoder-shell (Dshell)
  • Dshell Developer Guide
    • Una guía para el desarrollo de plugins con ejemplos básicos, así como definiciones de funciones y clases principales, y una visión general del flujo de datos
    • Ayuda a los usuarios finales a desarrollar nuevos plugins personalizados de Dshell así como modificar plugins existentes

Requisitos

  • Linux (desarrollado en Ubuntu 20.04 LTS)
  • Python 3 (desarrollado con Python 3.8.10)
  • pypacker
  • pcapy-ng
  • pyOpenSSL
Descargar herramienta
  • geoip2
    • Conjuntos de datos MaxMind GeoIP2
      • Usado para mapear direcciones IP a códigos de país
      • Ver la sección de Instalación para configuración
  • Opcional

    • oui.txt
      • usado por algunos plugins que manejan direcciones MAC
      • colocar en <dshell>/data/
    • elasticsearch
      • usado en el módulo de salida elasticout
      • solo necesario si se planea usar elasticsearch para almacenar la salida
    • pyJA3
      • usado en el plugin tls

    Instalación

    1. Instalar Dshell con pip
    • python3 -m pip install Dshell/ O python3 -m pip install <Dshell-tarball>
    1. Configurar geoip2 colocando los archivos del conjunto de datos MaxMind GeoLite2 (GeoLite2-ASN.mmdb, GeoLite2-City.mmdb, GeoLite2-Country.mmdb) en [...]/site-packages/dshell/data/GeoIP/
    2. Ejecutar dshell. Esto debería llevarte a un prompt Dshell> .

    Uso Básico

    • decode -l
      • Esto listará todos los plugins disponibles, junto con información básica sobre ellos
    • decode -h
      • Muestra las opciones genéricas de línea de comandos disponibles para la mayoría de plugins, como el modo amigable para daltónicos en todas las salidas de color
    • decode -p <plugin>
      • Muestra información sobre un plugin, incluyendo las opciones de línea de comandos disponibles
    • decode -p <plugin> <pcap>
      • Ejecuta el plugin seleccionado en un archivo pcap o pcapng
    • decode -p <plugin1>+<plugin2> <pcap>
      • Encadena dos (o más) plugins y ejecútalos en un archivo pcap
    • decode -p <plugin> -i <interface>
      • Ejecuta el plugin seleccionado en vivo en una interfaz (puede requerir privilegios de superusuario)

    Ejemplos de Uso

    Mostrando consultas DNS en tráfico de ejemplo

    root@kitploit:~
    Dshell> decode -p dns ~/pcap/dns.cap | sort
    [DNS] 2005-03-30 03:47:46    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 4146, TXT? google.com., TXT: b'\x0fv=spf1 ptr ?all' **
    [DNS] 2005-03-30 03:47:50    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 63343, MX? google.com., MX: b'\x00(\x05smtp4\xc0\x0c', MX: b'\x00\n\x05smtp5\xc0\x0c', MX: b'\x00\n\x05smtp6\xc0\x0c', MX: b'\x00\n\x05smtp1\xc0\x0c', MX: b'\x00\n\x05smtp2\xc0\x0c', MX: b'\x00(\x05smtp3\xc0\x0c' **
    [DNS] 2005-03-30 03:47:59    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 18849, LOC? google.com. **
    [DNS] 2005-03-30 03:48:07    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 39867, PTR? 104.9.192.66.in-addr.arpa., PTR: 66-192-9-104.gen.twtelecom.net. **
    [DNS] 2005-03-30 03:49:18    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 30144, A? www.netbsd.org., A: 204.152.190.12 (ttl 82159s) **
    [DNS] 2005-03-30 03:49:35    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 61652, AAAA? www.netbsd.org., AAAA: 2001:4f8:4:7:2e0:81ff:fe52:9a6b (ttl 86400s) **
    [DNS] 2005-03-30 03:50:35    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 32569, AAAA? www.netbsd.org., AAAA: 2001:4f8:4:7:2e0:81ff:fe52:9a6b (ttl 86340s) **
    [DNS] 2005-03-30 03:50:44    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 36275, AAAA? www.google.com., CNAME: 'www.l.google.com.' **
    [DNS] 2005-03-30 03:50:54    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 56482, AAAA? www.l.google.com. **
    [DNS] 2005-03-30 03:51:35    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 48159, AAAA? www.example.com. **
    [DNS] 2005-03-30 03:51:46    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 9837, AAAA? www.example.notginh., NXDOMAIN **
    [DNS] 2005-03-30 03:52:17    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 65251, AAAA: 2001:4f8:0:2::d (ttl 600s), A: 204.152.184.88 (ttl 600s) **
    [DNS] 2005-03-30 03:52:17    192.168.170.8:32796 --   192.168.170.20:53    ** ID: 23123, PTR? 1.0.0.127.in-addr.arpa., PTR: localhost. **
    [DNS] 2005-03-30 03:52:17    192.168.170.8:32797 --   192.168.170.20:53    ** ID: 8330, NS: b'\x06ns-ext\x04nrt1\xc0\x0c', NS: b'\x06ns-ext\x04sth1\xc0\x0c', NS: b'\x06ns-ext\xc0\x0c', NS: b'\x06ns-ext\x04lga1\xc0\x0c' **
    [DNS] 2005-03-30 03:52:17   192.168.170.56:1707  --      217.13.4.24:53    ** ID: 12910, SRV? _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.utelsystems.local., NXDOMAIN **
    [DNS] 2005-03-30 03:52:17   192.168.170.56:1708  --      217.13.4.24:53    ** ID: 61793, SRV? _ldap._tcp.dc._msdcs.utelsystems.local., NXDOMAIN **
    [DNS] 2005-03-30 03:52:17   192.168.170.56:1709  --      217.13.4.24:53    ** ID: 33633, SRV? _ldap._tcp.05b5292b-34b8-4fb7-85a3-8beef5fd2069.domains._msdcs.utelsystems.local., NXDOMAIN **
    [DNS] 2005-03-30 03:52:17   192.168.170.56:1710  --      217.13.4.24:53    ** ID: 53344, A? GRIMM.utelsystems.local., NXDOMAIN **
    [DNS] 2005-03-30 03:52:25   192.168.170.56:1711  --      217.13.4.24:53    ** ID: 30307, A? GRIMM.utelsystems.local., NXDOMAIN **
    

    Siguiendo y reensamblando un flujo en tráfico de ejemplo

    root@kitploit:~
    Dshell> decode -p followstream ~/pcap/v6-http.cap 
    Connection 1 (TCP)
    Start: 2007-08-05 15:16:44.189851
    End:   2007-08-05 15:16:44.219460
    2001:6f8:102d:0:2d0:9ff:fee3:e8de: 59201 -> 2001:6f8:900:7c0::2:    80 (300 bytes)
    2001:6f8:900:7c0::2:    80 -> 2001:6f8:102d:0:2d0:9ff:fee3:e8de: 59201 (2379 bytes)
    
    GET / HTTP/1.0
    Host: cl-1985.ham-01.de.sixxs.net
    Accept: text/html, text/plain, text/css, text/sgml, */*;q=0.01
    Accept-Encoding: gzip, bzip2
    Accept-Language: en
    User-Agent: Lynx/2.8.6rel.2 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.8b
    
    
    
    HTTP/1.1 200 OK
    Date: Sun, 05 Aug 2007 19:16:44 GMT
    Server: Apache
    Content-Length: 2121
    Connection: close
    Content-Type: text/html
    
    <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
    <html>
     <head>
      <title>Index of /</title>
     </head>
     <body>
    <h1>Index of /</h1>
    <pre><img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/blank.gif" alt="Icon "> <a href="?C=N;O=D">Name</a>                    <a href="?C=M;O=A">Last modified</a>      <a href="?C=S;O=A">Size</a>  <a href="?C=D;O=A">Description</a><hr><img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/folder.gif" alt="[DIR]"> <a href="https://github.com/usarmyresearchlab/dshell/blob/master/202-vorbereitung">202-vorbereitung/</a>       06-Jul-2007 14:31    -   
    <img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/layout.gif" alt="[   ]"> <a href="https://github.com/usarmyresearchlab/dshell/blob/master/Efficient_Video_on_demand_over_Multicast.pdf">Efficient_Video_on_d..&gt;</a> 19-Dec-2006 03:17  291K  
    <img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/unknown.gif" alt="[   ]"> <a href="https://github.com/usarmyresearchlab/dshell/blob/master/Welcome%20Stranger%21%21%21">Welcome Stranger!!!</a>     28-Dec-2006 03:46    0   
    <img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/text.gif" alt="[TXT]"> <a href="https://github.com/usarmyresearchlab/dshell/blob/master/barschel.htm">barschel.htm</a>            31-Jul-2007 02:21   44K  
    <img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/folder.gif" alt="[DIR]"> <a href="https://github.com/usarmyresearchlab/dshell/blob/master/bnd">bnd/</a>                    30-Dec-2006 08:59    -   
    <img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/folder.gif" alt="[DIR]"> <a href="https://github.com/usarmyresearchlab/dshell/blob/master/cia">cia/</a>                    28-Jun-2007 00:04    -   
    <img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/layout.gif" alt="[   ]"> <a href="https://github.com/usarmyresearchlab/dshell/blob/master/cisco_ccna_640-801_command_reference_guide.pdf">cisco_ccna_640-801_c..&gt;</a> 28-Dec-2006 03:48  236K  
    <img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/folder.gif" alt="[DIR]"> <a href="https://github.com/usarmyresearchlab/dshell/blob/master/doc">doc/</a>                    19-Sep-2006 01:43    -   
    <img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/folder.gif" alt="[DIR]"> <a href="https://github.com/usarmyresearchlab/dshell/blob/master/freenetproto">freenetproto/</a>           06-Dec-2006 09:00    -   
    <img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/folder.gif" alt="[DIR]"> <a href="https://github.com/usarmyresearchlab/dshell/blob/master/korrupt">korrupt/</a>                03-Jul-2007 11:57    -   
    <img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/folder.gif" alt="[DIR]"> <a href="https://github.com/usarmyresearchlab/dshell/blob/master/mp3_technosets">mp3_technosets/</a>         04-Jul-2007 08:56    -   
    <img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/text.gif" alt="[TXT]"> <a href="https://github.com/usarmyresearchlab/dshell/blob/master/neues_von_rainald_goetz.htm">neues_von_rainald_go..&gt;</a> 21-Mar-2007 23:27   31K  
    <img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/text.gif" alt="[TXT]"> <a href="https://github.com/usarmyresearchlab/dshell/blob/master/neues_von_rainald_goetz0.htm">neues_von_rainald_go..&gt;</a> 21-Mar-2007 23:29   36K  
    <img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/master/icons/layout.gif" alt="[   ]"> <a href="https://github.com/usarmyresearchlab/dshell/blob/master/pruef.pdf">pruef.pdf</a>               28-Dec-2006 07:48   88K  
    <hr></pre>
    </body></html>
    

    Encadenando plugins para ver datos de flujo para un código de país específico en tráfico de ejemplo (nota: los handshakes TCP no están incluidos en el conteo de paquetes)

    root@kitploit:~
    Dshell> decode -p country+netflow --country_code=JP ~/pcap/SkypeIRC.cap
    2006-08-25 15:32:20.766761       192.168.1.2 ->  202.232.205.123  (-- -> JP)   UDP   60583   33438     1      0       64        0  0.0000s
    2006-08-25 15:32:20.634046       192.168.1.2 ->  202.232.205.123  (-- -> JP)   UDP   60583   33435     1      0       64        0  0.0000s
    2006-08-25 15:32:20.747503       192.168.1.2 ->  202.232.205.123  (-- -> JP)   UDP   60583   33437     1      0       64        0  0.0000s
    2006-08-25 15:32:20.651501       192.168.1.2 ->  202.232.205.123  (-- -> JP)   UDP   60583   33436     1      0       64        0  0.0000s
    

    Recolectando tráfico DNS de varios archivos y almacenándolo en un nuevo archivo pcap.

    root@kitploit:~
    Dshell> decode -p dns+pcapwriter --pcapwriter_outfile=test.pcap ~/pcap/*.cap > /dev/null
    Dshell> tcpdump -nnr test.pcap | head
    reading from file test.pcap, link-type EN10MB (Ethernet)
    15:36:08.670569 IP 192.168.1.2.2131 > 192.168.1.1.53: 40209+ A? ui.skype.com. (30)
    15:36:08.670687 IP 192.168.1.2.2131 > 192.168.1.1.53: 40210+ AAAA? ui.skype.com. (30)
    15:36:08.674022 IP 192.168.1.1.53 > 192.168.1.2.2131: 40209- 1/0/0 A 212.72.49.131 (46)
    15:36:09.011208 IP 192.168.1.1.53 > 192.168.1.2.2131: 40210 0/1/0 (94)
    15:36:10.171350 IP 192.168.1.2.2131 > 192.168.1.1.53: 40210+ AAAA? ui.skype.com. (30)
    15:36:10.961350 IP 192.168.1.1.53 > 192.168.1.2.2131: 40210* 0/1/0 (85)
    15:36:10.961608 IP 192.168.1.2.2131 > 192.168.1.1.53: 40211+ AAAA? ui.skype.com. (30)
    15:36:11.294333 IP 192.168.1.1.53 > 192.168.1.2.2131: 40211 0/1/0 (94)
    15:32:21.664798 IP 192.168.1.2.2130 > 192.168.1.1.53: 39862+ A? ui.skype.com. (30)
    15:32:21.664913 IP 192.168.1.2.2130 > 192.168.1.1.53: 39863+ AAAA? ui.skype.com. (30)
    

    Recolectando datos TFTP y convirtiendo alertas a formato JSON usando tráfico de ejemplo

    root@kitploit:~
    Dshell> decode -p tftp -O jsonout ~/pcap/tftp_*.pcap
    {"ts": 1367411051.972852, "sip": "192.168.0.253", "sport": 50618, "dip": "192.168.0.10", "dport": 3445, "readwrite": "read", "filename": "rfc1350.txt", "plugin": "tftp", "pcapfile": "/home/pcap/tftp_rrq.pcap", "data": "read  rfc1350.txt (24599 bytes) "}
    {"ts": 1367053679.45274, "sip": "192.168.0.1", "sport": 57509, "dip": "192.168.0.13", "dport": 2087, "readwrite": "write", "filename": "rfc1350.txt", "plugin": "tftp", "pcapfile": "/home/pcap/tftp_wrq.pcap", "data": "write rfc1350.txt (24599 bytes) "}
    

    Ejecutando un plugin dentro de un script Python separado usando tráfico de ejemplo

    root@kitploit:~
    # Import required Dshell libraries
    import dshell.decode as decode
    import dshell.plugins.tftp.tftp as tftp
    
    # Instantiate plugin
    plugin = tftp.DshellPlugin()
    # Define plugin-specific arguments, if needed
    dargs = {plugin: {"rip": True, "outdir": "/tmp/"}}
    # Add plugin(s) to plugin chain
    decode.plugin_chain = [plugin]
    # Run decode main function with all other arguments
    decode.main(
        debug=True,
        files=["/home/user/pcap/tftp_rrq.pcap", "/home/user/pcap/tftp_wrq.pcap"],
        plugin_args=dargs
    )