Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
Dshell — Dshell एक नेटवर्क फोरेंसिक विश्लेषण फ्रेमवर्क है। | Kitploit
उपकरण/GitHubGitHub/usarmyresearchlab/dshell
पैकेट स्निफिंग और विश्लेषणनेटवर्क फोरेंसिकफोरेंसिकडिजिटल फोरेंसिकDNS विश्लेषणलॉग विश्लेषण
GitHubusarmyresearchlab/dshell

Dshell

Dshell एक नेटवर्क फोरेंसिक विश्लेषण फ्रेमवर्क है।

रिपॉजिटरी देखें
5.5k1.1k2 साल पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

Dshell

एक विस्तारणीय नेटवर्क फोरेंसिक विश्लेषण ढांचा। यह नेटवर्क पैकेट कैप्चर के विच्छेदन का समर्थन करने के लिए प्लगइन्स के तेजी से विकास को सक्षम बनाता है।

मुख्य विशेषताएँ:

  • विशेष प्लगइन्स का उपयोग करके गहन पैकेट विश्लेषण
  • मजबूत स्ट्रीम पुनर्संयोजन
  • IPv4 और IPv6 समर्थन
  • कई उपयोगकर्ता-चयन योग्य आउटपुट प्रारूप और कस्टम आउटपुट हैंडलर बनाने की क्षमता
  • श्रृंखलाबद्ध करने योग्य प्लगइन्स
  • डेटा स्रोत के प्रसंस्करण को अलग-अलग Python प्रक्रियाओं में विभाजित करने का समानांतर प्रसंस्करण विकल्प
  • मुख्य Dshell प्लगइन निर्देशिकाओं को ओवरलैप किए बिना नए बाहरी रूप से विकसित प्लगइन्स को साझा करने और स्थापित करने के लिए बाहरी प्लगइन पैक के विकास को सक्षम बनाता है

गाइड

  • Dshell उपयोगकर्ता गाइड
    • स्थापना के साथ-साथ उदाहरणों के साथ बुनियादी और उन्नत विश्लेषण के लिए एक मार्गदर्शिका
    • नए और अनुभवी अंतिम उपयोगकर्ताओं को डिकोडर-शेल (Dshell) ढांचे के उपयोग और समझने में मदद करता है
  • Dshell डेवलपर गाइड
    • बुनियादी उदाहरणों के साथ-साथ मुख्य फ़ंक्शन और वर्ग परिभाषाओं, और डेटा प्रवाह के अवलोकन के साथ प्लगइन विकास के लिए एक मार्गदर्शिका
    • अंतिम उपयोगकर्ताओं को नए कस्टम Dshell प्लगइन्स विकसित करने और मौजूदा प्लगइन्स को संशोधित करने में मदद करता है

आवश्यकताएँ

  • Linux (Ubuntu 20.04 LTS पर विकसित)
  • Python 3 (Python 3.8.10 के साथ विकसित)
  • pypacker
  • pcapy-ng
  • pyOpenSSL
  • geoip2
    • MaxMind GeoIP2 डेटा सेट
      • IP पतों को देश कोड में मैप करने के लिए उपयोग किया जाता है
      • कॉन्फ़िगरेशन के लिए स्थापना अनुभाग देखें

वैकल्पिक

  • oui.txt
    • MAC पतों को संभालने वाले कुछ प्लगइन्स द्वारा उपयोग किया जाता है
    • <dshell>/data/ में रखें
  • elasticsearch
    • elasticout आउटपुट मॉड्यूल में उपयोग किया जाता है
    • केवल तभी आवश्यक है जब आउटपुट को संग्रहीत करने के लिए elasticsearch का उपयोग करने की योजना हो
  • pyJA3
    • tls प्लगइन में उपयोग किया जाता है

स्थापना

  1. pip के साथ Dshell स्थापित करें
  • python3 -m pip install Dshell/ या python3 -m pip install <Dshell-tarball>
  1. MaxMind GeoLite2 डेटा सेट फ़ाइलों (GeoLite2-ASN.mmdb, GeoLite2-City.mmdb, GeoLite2-Country.mmdb) को [...]/site-packages/dshell/data/GeoIP/ में रखकर geoip2 कॉन्फ़िगर करें
  2. dshell चलाएँ। यह आपको एक Dshell> प्रॉम्प्ट पर ले जाना चाहिए।

मूल उपयोग

  • decode -l
    • यह सभी उपलब्ध प्लगइन्स को उनकी बुनियादी जानकारी के साथ सूचीबद्ध करेगा
  • decode -h
    • अधिकांश प्लगइन्स के लिए उपलब्ध सामान्य कमांड-लाइन फ़्लैग दिखाएं, जैसे सभी रंग आउटपुट के लिए कलर ब्लाइंड फ्रेंडली मोड
  • decode -p <plugin>
    • एक प्लगइन के बारे में जानकारी प्रदर्शित करें, जिसमें उपलब्ध कमांड-लाइन फ़्लैग शामिल हैं
  • decode -p <plugin> <pcap>
    • चयनित प्लगइन को pcap या pcapng फ़ाइल पर चलाएँ
  • decode -p <plugin1>+<plugin2> <pcap>
    • दो (या अधिक) प्लगइन्स को एक साथ जोड़ें और उन्हें pcap फ़ाइल पर चलाएँ
  • decode -p <plugin> -i <interface>
    • चयनित प्लगइन को इंटरफ़ेस पर लाइव चलाएँ (सुपरयूज़र विशेषाधिकारों की आवश्यकता हो सकती है)

उपयोग उदाहरण

sample traffic में DNS लुकअप दिखाना

root@kitploit:~
Dshell> decode -p dns ~/pcap/dns.cap | sort
[DNS] 2005-03-30 03:47:46    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 4146, TXT? google.com., TXT: b'\x0fv=spf1 ptr ?all' **
[DNS] 2005-03-30 03:47:50    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 63343, MX? google.com., MX: b'\x00(\x05smtp4\xc0\x0c', MX: b'\x00\n\x05smtp5\xc0\x0c', MX: b'\x00\n\x05smtp6\xc0\x0c', MX: b'\x00\n\x05smtp1\xc0\x0c', MX: b'\x00\n\x05smtp2\xc0\x0c', MX: b'\x00(\x05smtp3\xc0\x0c' **
[DNS] 2005-03-30 03:47:59    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 18849, LOC? google.com. **
[DNS] 2005-03-30 03:48:07    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 39867, PTR? 104.9.192.66.in-addr.arpa., PTR: 66-192-9-104.gen.twtelecom.net. **
[DNS] 2005-03-30 03:49:18    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 30144, A? www.netbsd.org., A: 204.152.190.12 (ttl 82159s) **
[DNS] 2005-03-30 03:49:35    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 61652, AAAA? www.netbsd.org., AAAA: 2001:4f8:4:7:2e0:81ff:fe52:9a6b (ttl 86400s) **
[DNS] 2005-03-30 03:50:35    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 32569, AAAA? www.netbsd.org., AAAA: 2001:4f8:4:7:2e0:81ff:fe52:9a6b (ttl 86340s) **
[DNS] 2005-03-30 03:50:44    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 36275, AAAA? www.google.com., CNAME: 'www.l.google.com.' **
[DNS] 2005-03-30 03:50:54    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 56482, AAAA? www.l.google.com. **
[DNS] 2005-03-30 03:51:35    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 48159, AAAA? www.example.com. **
[DNS] 2005-03-30 03:51:46    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 9837, AAAA? www.example.notginh., NXDOMAIN **
[DNS] 2005-03-30 03:52:17    192.168.170.8:32795 --   192.168.170.20:53    ** ID: 65251, AAAA: 2001:4f8:0:2::d (ttl 600s), A: 204.152.184.88 (ttl 600s) **
[DNS] 2005-03-30 03:52:17    192.168.170.8:32796 --   192.168.170.20:53    ** ID: 23123, PTR? 1.0.0.127.in-addr.arpa., PTR: localhost. **
[DNS] 2005-03-30 03:52:17    192.168.170.8:32797 --   192.168.170.20:53    ** ID: 8330, NS: b'\x06ns-ext\x04nrt1\xc0\x0c', NS: b'\x06ns-ext\x04sth1\xc0\x0c', NS: b'\x06ns-ext\xc0\x0c', NS: b'\x06ns-ext\x04lga1\xc0\x0c' **
[DNS] 2005-03-30 03:52:17   192.168.170.56:1707  --      217.13.4.24:53    ** ID: 12910, SRV? _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.utelsystems.local., NXDOMAIN **
[DNS] 2005-03-30 03:52:17   192.168.170.56:1708  --      217.13.4.24:53    ** ID: 61793, SRV? _ldap._tcp.dc._msdcs.utelsystems.local., NXDOMAIN **
[DNS] 2005-03-30 03:52:17   192.168.170.56:1709  --      217.13.4.24:53    ** ID: 33633, SRV? _ldap._tcp.05b5292b-34b8-4fb7-85a3-8beef5fd2069.domains._msdcs.utelsystems.local., NXDOMAIN **
[DNS] 2005-03-30 03:52:17   192.168.170.56:1710  --      217.13.4.24:53    ** ID: 53344, A? GRIMM.utelsystems.local., NXDOMAIN **
[DNS] 2005-03-30 03:52:25   192.168.170.56:1711  --      217.13.4.24:53    ** ID: 30307, A? GRIMM.utelsystems.local., NXDOMAIN **

sample traffic में एक स्ट्रीम का अनुसरण और पुनर्संयोजन

root@kitploit:~
Dshell> decode -p followstream ~/pcap/v6-http.cap 
Connection 1 (TCP)
Start: 2007-08-05 15:16:44.189851
End:   2007-08-05 15:16:44.219460
2001:6f8:102d:0:2d0:9ff:fee3:e8de: 59201 -> 2001:6f8:900:7c0::2:    80 (300 bytes)
2001:6f8:900:7c0::2:    80 -> 2001:6f8:102d:0:2d0:9ff:fee3:e8de: 59201 (2379 bytes)

GET / HTTP/1.0
Host: cl-1985.ham-01.de.sixxs.net
Accept: text/html, text/plain, text/css, text/sgml, */*;q=0.01
Accept-Encoding: gzip, bzip2
Accept-Language: en
User-Agent: Lynx/2.8.6rel.2 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.8b



HTTP/1.1 200 OK
Date: Sun, 05 Aug 2007 19:16:44 GMT
Server: Apache
Content-Length: 2121
Connection: close
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
<html>
 <head>
  <title>Index of /</title>
 </head>
 <body>
<h1>Index of /</h1>
<pre><img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/blank.gif" alt="Icon "> <a href="?C=N;O=D">Name</a>                    <a href="?C=M;O=A">Last modified</a>      <a href="?C=S;O=A">Size</a>  <a href="?C=D;O=A">Description</a><hr><img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/folder.gif" alt="[DIR]"> <a href="202-vorbereitung/">202-vorbereitung/</a>       06-Jul-2007 14:31    -   
<img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/layout.gif" alt="[   ]"> <a href="Efficient_Video_on_demand_over_Multicast.pdf">Efficient_Video_on_d..&gt;</a> 19-Dec-2006 03:17  291K  
<img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/unknown.gif" alt="[   ]"> <a href="Welcome%20Stranger!!!">Welcome Stranger!!!</a>     28-Dec-2006 03:46    0   
<img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/text.gif" alt="[TXT]"> <a href="barschel.htm">barschel.htm</a>            31-Jul-2007 02:21   44K  
<img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/folder.gif" alt="[DIR]"> <a href="bnd/">bnd/</a>                    30-Dec-2006 08:59    -   
<img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/folder.gif" alt="[DIR]"> <a href="cia/">cia/</a>                    28-Jun-2007 00:04    -   
<img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/layout.gif" alt="[   ]"> <a href="cisco_ccna_640-801_command_reference_guide.pdf">cisco_ccna_640-801_c..&gt;</a> 28-Dec-2006 03:48  236K  
<img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/folder.gif" alt="[DIR]"> <a href="doc/">doc/</a>                    19-Sep-2006 01:43    -   
<img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/folder.gif" alt="[DIR]"> <a href="freenetproto/">freenetproto/</a>           06-Dec-2006 09:00    -   
<img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/folder.gif" alt="[DIR]"> <a href="korrupt/">korrupt/</a>                03-Jul-2007 11:57    -   
<img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/folder.gif" alt="[DIR]"> <a href="mp3_technosets/">mp3_technosets/</a>         04-Jul-2007 08:56    -   
<img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/text.gif" alt="[TXT]"> <a href="neues_von_rainald_goetz.htm">neues_von_rainald_go..&gt;</a> 21-Mar-2007 23:27   31K  
<img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/text.gif" alt="[TXT]"> <a href="neues_von_rainald_goetz0.htm">neues_von_rainald_go..&gt;</a> 21-Mar-2007 23:29   36K  
<img src="https://raw.githubusercontent.com/usarmyresearchlab/dshell/HEAD/icons/layout.gif" alt="[   ]"> <a href="pruef.pdf">pruef.pdf</a>               28-Dec-2006 07:48   88K  
<hr></pre>
</body></html>

sample traffic में एक विशिष्ट देश कोड के लिए प्रवाह डेटा देखने के लिए प्लगइन्स को श्रृंखलाबद्ध करना (नोट: पैकेट गणना में TCP हैंडशेक शामिल नहीं हैं)

root@kitploit:~
Dshell> decode -p country+netflow --country_code=JP ~/pcap/SkypeIRC.cap
2006-08-25 15:32:20.766761       192.168.1.2 ->  202.232.205.123  (-- -> JP)   UDP   60583   33438     1      0       64        0  0.0000s
2006-08-25 15:32:20.634046       192.168.1.2 ->  202.232.205.123  (-- -> JP)   UDP   60583   33435     1      0       64        0  0.0000s
2006-08-25 15:32:20.747503       192.168.1.2 ->  202.232.205.123  (-- -> JP)   UDP   60583   33437     1      0       64        0  0.0000s
2006-08-25 15:32:20.651501       192.168.1.2 ->  202.232.205.123  (-- -> JP)   UDP   60583   33436     1      0       64        0  0.0000s

कई फ़ाइलों से DNS ट्रैफ़िक एकत्र करना और इसे एक नई pcap फ़ाइल में संग्रहीत करना।

root@kitploit:~
Dshell> decode -p dns+pcapwriter --pcapwriter_outfile=test.pcap ~/pcap/*.cap > /dev/null
Dshell> tcpdump -nnr test.pcap | head
reading from file test.pcap, link-type EN10MB (Ethernet)
15:36:08.670569 IP 192.168.1.2.2131 > 192.168.1.1.53: 40209+ A? ui.skype.com. (30)
15:36:08.670687 IP 192.168.1.2.2131 > 192.168.1.1.53: 40210+ AAAA? ui.skype.com. (30)
15:36:08.674022 IP 192.168.1.1.53 > 192.168.1.2.2131: 40209- 1/0/0 A 212.72.49.131 (46)
15:36:09.011208 IP 192.168.1.1.53 > 192.168.1.2.2131: 40210 0/1/0 (94)
15:36:10.171350 IP 192.168.1.2.2131 > 192.168.1.1.53: 40210+ AAAA? ui.skype.com. (30)
15:36:10.961350 IP 192.168.1.1.53 > 192.168.1.2.2131: 40210* 0/1/0 (85)
15:36:10.961608 IP 192.168.1.2.2131 > 192.168.1.1.53: 40211+ AAAA? ui.skype.com. (30)
15:36:11.294333 IP 192.168.1.1.53 > 192.168.1.2.2131: 40211 0/1/0 (94)
15:32:21.664798 IP 192.168.1.2.2130 > 192.168.1.1.53: 39862+ A? ui.skype.com. (30)
15:32:21.664913 IP 192.168.1.2.2130 > 192.168.1.1.53: 39863+ AAAA? ui.skype.com. (30)

sample traffic का उपयोग करके TFTP डेटा एकत्र करना और अलर्ट को JSON प्रारूप में परिवर्तित करना

root@kitploit:~
Dshell> decode -p tftp -O jsonout ~/pcap/tftp_*.pcap
{"ts": 1367411051.972852, "sip": "192.168.0.253", "sport": 50618, "dip": "192.168.0.10", "dport": 3445, "readwrite": "read", "filename": "rfc1350.txt", "plugin": "tftp", "pcapfile": "/home/pcap/tftp_rrq.pcap", "data": "read  rfc1350.txt (24599 bytes) "}
{"ts": 1367053679.45274, "sip": "192.168.0.1", "sport": 57509, "dip": "192.168.0.13", "dport": 2087, "readwrite": "write", "filename": "rfc1350.txt", "plugin": "tftp", "pcapfile": "/home/pcap/tftp_wrq.pcap", "data": "write rfc1350.txt (24599 bytes) "}

sample traffic का उपयोग करके एक अलग Python स्क्रिप्ट के भीतर एक प्लगइन चलाना

root@kitploit:~
# Import required Dshell libraries
import dshell.decode as decode
import dshell.plugins.tftp.tftp as tftp

# Instantiate plugin
plugin = tftp.DshellPlugin()
# Define plugin-specific arguments, if needed
dargs = {plugin: {"rip": True, "outdir": "/tmp/"}}
# Add plugin(s) to plugin chain
decode.plugin_chain = [plugin]
# Run decode main function with all other arguments
decode.main(
    debug=True,
    files=["/home/user/pcap/tftp_rrq.pcap", "/home/user/pcap/tftp_wrq.pcap"],
    plugin_args=dargs
)
टूल डाउनलोड करें