scapy
Scapy: interactive packet manipulation tool
Decision gist · record as of 2026-08-14
Yes, if you need low-level packet manipulation and network analysis. Scapy is production-stable, actively maintained, has no required dependencies, and is widely used for security research and network engineering. However, the GPL-2.0 copyleft license is a hard blocker for proprietary software, and you must have root/administrator access to use packet capture and injection features. Evaluate the license constraint first.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires root/administrator privileges to send and receive raw packets on most systems.
- On Windows, additional system dependencies must be installed as documented.
- Installation is straightforward with no runtime Python dependencies.
License · maintenance · safety
GPL-2.0-only (copyleft) — Scapy is licensed under GPL-2.0-only (copyleft). Any derivative work or distribution must also be released under GPL-2.0, and source code must be made available to users. This is a significant constraint for proprietary or closed-source projects.
last release 2025-12-26 (231 days) · last repo commit 2026-08-14 · 12,470 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 5,230,356 downloads/mo, #2,134 on PyPI
Alternatives
Verify before relying
pip install scapy
from scapy.all import IP, ICMP, sr1
p = IP(dst="example.com")/ICMP()
r = sr1(p)- Whether the package's cross-platform support (Linux, OSX, BSD, Windows) is equally mature on all platforms.
- Performance characteristics when handling high-volume packet streams or very large pcap files.
- Current state of optional feature modules (plotting, cryptography integration) and their maintenance status.
What it is and what it does
Scapy is a packet manipulation library that lets you construct, send, capture, and analyze network packets at a low level. It supports a wide range of protocols and can be used interactively as a shell or imported as a library in Python scripts. The library handles classical network tasks like scanning, tracerouting, and probing, but also excels at specialized work such as crafting malformed frames, injecting 802.11 packets, and combining advanced techniques like VLAN hopping or ARP cache poisoning.
The package has no required runtime dependencies and works on Linux, BSD, macOS, and Windows (with platform-specific setup). It requires Python 3.7 or later and is actively maintained. Most operations require root or administrator privileges to access raw sockets. Optional features like plotting or cryptography support can be added by installing additional packages separately.
Use it for
- Build custom network scanning and reconnaissance tools that go beyond standard utilities.
- Develop unit tests and integration tests for network protocol implementations and behavior.
- Analyze and decode captured network traffic from pcap files for security research or troubleshooting.
- Craft and send non-standard or malformed packets to test network device robustness and security.
- Prototype network attack or defense techniques in a controlled, interactive environment.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need low-level packet manipulation and network analysis.
Scapy is production-stable, actively maintained, has no required dependencies, and is widely used for security research and network engineering. However, the GPL-2.0 copyleft license is a hard blocker for proprietary software, and you must have root/administrator access to use packet capture and injection features. Evaluate the license constraint first.
Install
scapy on PyPI
Before you install
Installation is straightforward with no runtime Python dependencies. The project is actively maintained with recent commits and a large repository following, making it a stable choice for production use.
Requires root/administrator privileges to send and receive raw packets on most systems. On Windows, additional system dependencies must be installed as documented.
License in practice
Scapy is licensed under GPL-2.0-only (copyleft). Any derivative work or distribution must also be released under GPL-2.0, and source code must be made available to users. This is a significant constraint for proprietary or closed-source projects.
Quickstart
pip install scapy
from scapy.all import IP, ICMP, sr1
p = IP(dst="example.com")/ICMP()
r = sr1(p)
Verify before relying
- Whether the package's cross-platform support (Linux, OSX, BSD, Windows) is equally mature on all platforms.
- Performance characteristics when handling high-volume packet streams or very large pcap files.
- Current state of optional feature modules (plotting, cryptography integration) and their maintenance status.
Package facts
| License | GPL-2.0-only copyleft |
| Python support | Supports the current Python release <4,>=3.7 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 231 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 5,230,356 / month, #2,134 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersIntended Audience :: Information TechnologyIntended Audience :: Science/ResearchIntended Audience :: System AdministratorsIntended Audience :: Telecommunications IndustryLicense :: OSI Approved :: GNU General Public License v2 (GPLv2)Programming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: SecurityTopic :: System :: NetworkingTopic :: System :: Networking :: Monitoring |
Evidence: scapy-2.7.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “packet manipulation python”
- scapyScapy is a Python library for forging, decoding, sending, and…
- rtpDecodes, encodes, and manipulates RTP (Real-time Transport Protocol)…
- pydivertPyDivert is a Python binding for the WinDivert Windows driver that…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also pyshark · pypcap · dpkt · pydivert · pure-pcapy3 · impacket · rtp · ifcopenshell · threatwire · python-pcapng