dpkt
fast, simple packet creation / parsing, with definitions for the basic TCP/IP protocols
Decision gist · record as of 2026-08-14
Yes, if you need lightweight, dependency-free packet parsing for network analysis or protocol work. The dormant status is not a blocker—the library is stable and feature-complete for standard TCP/IP protocols. Install it when you want to avoid heavier frameworks like Scapy or when you need minimal overhead. Verify that its protocol coverage matches your specific use case, especially for newer or less common protocols.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Installation is straightforward with no runtime dependencies.
- The project is dormant (last release 2022-08-18, 1457 days ago) but remains stable and archived repository is not flagged, suggesting it is feature-complete rather than abandoned.
License · maintenance · safety
BSD (permissive) — BSD license is permissive, allowing commercial and private use with minimal restrictions—suitable for most projects that can include a license notice.
last release 2022-08-18 (1457 days) · last repo commit 2024-07-26 · 1,159 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,722,501 downloads/mo, #3,616 on PyPI
Alternatives
Verify before relying
pip install dpkt
import dpkt
# Parse an Ethernet frame
eth = dpkt.ethernet.Ethernet(raw_packet_bytes)
ip = eth.data
print(ip.src, ip.dst)- Whether the package actively handles modern protocol variants (e.g., IPv6 extensions, newer TCP options) given dormant maintenance status.
- Performance characteristics on large packet volumes or real-time capture scenarios compared to alternatives.
What it is and what it does
dpkt is a Python module for parsing and constructing packets at the TCP/IP protocol level. It provides definitions for basic protocols (Ethernet, IP, TCP, UDP, and others) and allows you to unpack raw bytes into structured protocol objects or build packets from scratch. The library has no runtime dependencies and is designed for speed and simplicity, making it suitable for network analysis, packet inspection, and protocol-level debugging.
The project entered dormancy after its 2022 release but remains functional and stable. It supports Python 2.7 through 3.9 (classifiers list these versions), though the lack of recent updates means it may not cover the latest protocol extensions or edge cases. It is widely used in network security, packet capture analysis, and educational contexts where direct protocol-level access is needed.
Use it for
- Analyze captured network traffic (pcap files) by parsing Ethernet, IP, TCP, UDP, and application-layer protocols.
- Build custom network packets for testing, fuzzing, or protocol validation without external dependencies.
- Extract and inspect protocol headers from raw bytes in network monitoring or IDS/IPS tools.
- Educational projects or reverse-engineering tasks requiring low-level packet inspection.
- Integrate packet parsing into security research or penetration testing workflows.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need lightweight, dependency-free packet parsing for network analysis or protocol work.
The dormant status is not a blocker—the library is stable and feature-complete for standard TCP/IP protocols. Install it when you want to avoid heavier frameworks like Scapy or when you need minimal overhead. Verify that its protocol coverage matches your specific use case, especially for newer or less common protocols.
Install
dpkt on PyPI
Before you install
Installation is straightforward with no runtime dependencies. The project is dormant (last release 2022-08-18, 1457 days ago) but remains stable and archived repository is not flagged, suggesting it is feature-complete rather than abandoned.
License in practice
BSD license is permissive, allowing commercial and private use with minimal restrictions—suitable for most projects that can include a license notice.
Quickstart
pip install dpkt
import dpkt
# Parse an Ethernet frame
eth = dpkt.ethernet.Ethernet(raw_packet_bytes)
ip = eth.data
print(ip.src, ip.dst)
Verify before relying
- Whether the package actively handles modern protocol variants (e.g., IPv6 extensions, newer TCP options) given dormant maintenance status.
- Performance characteristics on large packet volumes or real-time capture scenarios compared to alternatives.
Package facts
| License | BSD permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Dormant 1,457 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 1,722,501 / month, #3,616 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseNatural Language :: EnglishProgramming Language :: Python :: 2.7Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPy |
Evidence: dpkt-1.9.8-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “packet parsing python”
- dpktdpkt parses and creates TCP/IP protocol packets with minimal…
- pysharkPyshark wraps tshark (Wireshark's command-line tool) to parse network…
- pmd-net-protoParses, assembles, and validates network protocol packets (Ethernet…
Give your agent the search over MCP, or paste the wish link into any chat.
More Networking packages
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
psutil retrieves real-time information about running processes and system resources (CPU, memory, disks, network, sensors) across multiple operating systems, enabling system monitoring, process profiling, and resource management.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
uvloop is a drop-in replacement for Python's built-in asyncio event loop, implemented in Cython and using libuv, that accelerates async I/O operations.
execnet lets you spawn and communicate with Python interpreters across local processes, remote hosts, and different platforms, using a simple API for task distribution and inter-process messaging.
However, the aging maintenance status (275 days since last release) means you should verify it meets your concurrency and performance needs before committing to a…
PyZMQ provides Python bindings for ZeroMQ (ØMQ), a lightweight messaging library that enables fast, asynchronous communication between distributed processes and applications.
See also impacket · pmd-net-proto · scapy · pyshark · pypcap · pydivert · rtp · pingparsing · pure-pcapy3 · pythonping