$npx skillfedfor your agent

pyshark

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors

Worth itPyPI NetworkingReleased Apr 20231.0M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — pyshark-0.6-py3-none-any.whl
v0.6 · released 2023-04-26 · 4 runtime deps: lxml, termcolor, packaging, appdirs

Yes. Pyshark is a solid choice if you need to parse network packets in Python and want to reuse Wireshark's dissectors rather than writing your own. The install friction is low, the license is permissive, there are no known vulnerabilities, and the project is actively maintained. The main gotcha is the external tshark dependency—you must have Wireshark installed separately. If you're comfortable with that requirement and need programmatic packet analysis, this is a practical tool.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires tshark (Wireshark command-line utility) to be installed and in PATH; on macOS may require XCode command-line tools for libxml support.
  • Low friction: pure Python wheel with four lightweight runtime dependencies (lxml, termcolor, packaging, appdirs).
  • Maintenance is active but the author has noted capacity constraints and is seeking contributors.

License · maintenance · safety

MIT (permissive) — MIT license is permissive—you can use, modify, and distribute pyshark freely in commercial and private projects with minimal restrictions.

last release 2023-04-26 (1206 days) · last repo commit 2026-03-22 · 2,493 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,046,838 downloads/mo, #4,450 on PyPI

Verify before relying

pip install pyshark

import pyshark
cap = pyshark.FileCapture('/path/to/capture.pcap')
packet = cap[0]
print(packet.ip.src)
  • Whether tshark version compatibility issues affect parsing of specific protocol types or capture formats.
  • Performance characteristics when parsing very large capture files or high-volume live captures.
  • Current maintenance timeline and responsiveness to bug reports given the stated contributor shortage.
Same gist for agents: .md · .json

What it is and what it does

Pyshark is a Python wrapper around tshark that lets you parse network packets without reimplementing Wireshark's dissectors. Instead of parsing packets from scratch, it delegates to tshark's XML export and reads the structured output, giving you access to all protocol layers and fields that Wireshark understands. You can read from saved capture files (PCAP, PCAP-NG, etc.), live network interfaces, or remote hosts running rpcapd, and filter packets using BPF or Wireshark display filters.

The package is built on four runtime dependencies: lxml for XML parsing, termcolor for terminal output, packaging for version handling, and appdirs for cross-platform file paths. It supports Python 3.7 and later, and the repository is actively maintained with recent commits, though the maintainer has noted capacity constraints and welcomes contributors.

Use it for

  • Analyze saved network captures programmatically to extract protocol fields, build traffic reports, or detect anomalies.
  • Capture and inspect live traffic on a network interface in real time, filtering by protocol or BPF rules.
  • Decrypt encrypted traffic (WEP, WPA-PWD, WPA-PSK) and parse the decrypted packets using Wireshark dissectors.
  • Build network monitoring or security analysis tools that leverage Wireshark's protocol knowledge without reimplementing parsers.
  • Automate packet inspection workflows that would otherwise require manual Wireshark GUI interaction.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

Pyshark is a solid choice if you need to parse network packets in Python and want to reuse Wireshark's dissectors rather than writing your own. The install friction is low, the license is permissive, there are no known vulnerabilities, and the project is actively maintained. The main gotcha is the external tshark dependency—you must have Wireshark installed separately. If you're comfortable with that requirement and need programmatic packet analysis, this is a practical tool.

Install

pyshark on PyPI

Before you install

Low friction: pure Python wheel with four lightweight runtime dependencies (lxml, termcolor, packaging, appdirs). Maintenance is active but the author has noted capacity constraints and is seeking contributors.

Requires tshark (Wireshark command-line utility) to be installed and in PATH; on macOS may require XCode command-line tools for libxml support.

License in practice

MIT license is permissive—you can use, modify, and distribute pyshark freely in commercial and private projects with minimal restrictions.

Quickstart

pip install pyshark

import pyshark
cap = pyshark.FileCapture('/path/to/capture.pcap')
packet = cap[0]
print(packet.ip.src)

Verify before relying

  • Whether tshark version compatibility issues affect parsing of specific protocol types or capture formats.
  • Performance characteristics when parsing very large capture files or high-volume live captures.
  • Current maintenance timeline and responsiveness to bug reports given the stated contributor shortage.

Package facts

LicenseMIT permissive
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependencies
4 packages
lxmltermcolorpackagingappdirs
MaintenanceActively maintained 1,206 days since the last release
Last repo commit
First released
Downloads1,046,838 / month, #4,450 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: MIT LicenseProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9

Evidence: pyshark-0.6-py3-none-any.whl

Tags

Capabilities
network packet parsing pythonwireshark packet analysistshark python wrapperlive packet capture pythonpcap file parsingnetwork traffic analysispacket dissection python
Topics
network-analysispacket-capturewireshark-integration
PyPI keywords
wiresharkcapturepacketsparsingpacket

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “wireshark packet analysis”

  • pysharkPyshark wraps tshark (Wireshark's command-line tool) to parse network…
  • python-pcapngParses and writes pcap-ng packet capture files, the format used by…
  • dpktdpkt parses and creates TCP/IP protocol packets with minimal…

Give your agent the search over MCP, or paste the wish link into any chat.

More Networking packages

h11 With conditions
PyPI · WWW/HTTP · released Apr 2025

h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.

MITpure Python · 3.8+aging
894.9Mdownloads / mo
psutil Worth it
PyPI · Libraries · released Jan 2026

psutil retrieves real-time information about running processes and system resources (CPU, memory, disks, network, sensors) across multiple operating systems, enabling system monitoring, process profiling, and resource management.

permissive licensecompiled wheel · 3.6+
387.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
uvloop With conditions
PyPI · Networking · released Oct 2025

uvloop is a drop-in replacement for Python's built-in asyncio event loop, implemented in Cython and using libuv, that accelerates async I/O operations.

Apache-2.0compiled wheel · 3.8.1+
257.9Mdownloads / mo
execnet With conditions
PyPI · Libraries · released Nov 2025

execnet lets you spawn and communicate with Python interpreters across local processes, remote hosts, and different platforms, using a simple API for task distribution and inter-process messaging.

However, the aging maintenance status (275 days since last release) means you should verify it meets your concurrency and performance needs before committing to a…

MITpure Python · 3.8+aging
172.1Mdownloads / mo
pyzmq Worth it
PyPI · Networking · released Sep 2025

PyZMQ provides Python bindings for ZeroMQ (ØMQ), a lightweight messaging library that enables fast, asynchronous communication between distributed processes and applications.

BSD-3-Clausecompiled wheel · 3.8+
109.5Mdownloads / mo

See also pypcap · python-pcapng · scapy · dpkt · pure-pcapy3 · pydivert · rtp · pmd-net-proto · dnslib · pylibsrtp