Project

vanken

0.0
The project is in a healthy, maintained state
Inspect pcap and pcapng captures with a virtual packet list, protocol details, byte view, and display filters.
2005
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026
 Dependencies

Runtime

~> 1.1
= 2.0.0.rc2
~> 0.12.4
 Project Readme

Vanken

A Ruby packet analyzer for live capture, pcap files, and protocol inspection.

Gem version Gem downloads CI Ruby 3.3 or newer MIT license

Website · User Guide · Features · Installation · Quick start


Vanken opens pcap and pcapng captures in a desktop or terminal interface, with a packet list, protocol details, and synchronized byte highlighting. It uses redhound for packet analysis and Zaniah for its interface.

Vanken packet inspection

Features

  • Inspect packets with a sortable virtual list, protocol tree, byte view, and custom field columns.
  • Apply typed display filters with completion, history, and bookmarks; search by filter, bytes, text, or regular expression.
  • Use coloring rules, marks, ignored packets, time references, and conversation navigation.
  • Follow TCP streams, inspect expert diagnostics, and explore protocol hierarchy, conversations, endpoints, and I/O graphs.
  • Capture on Linux and macOS with BPF filters, automatic stop conditions, and rotating pcapng files.
  • Configure Decode As rules and explicitly trusted Ruby dissector plugins.
  • Save pcap/pcapng, export dissections as JSON, NDJSON, text, or CSV, and recover interrupted capture sessions.
  • Switch profiles, Japanese or English, and dark, light, system, or high-contrast themes. Optional address resolution runs asynchronously and is disabled by default.

Installation

Install the released gem:

gem install vanken
vanken --version

Vanken requires Ruby 3.3 or newer. Ruby 3.4 or 4.0 with YJIT is recommended; the launcher enables YJIT when available. Native Linux windows need the Vulkan loader and drivers, fonts, and zenity for file dialogs. On Ubuntu:

sudo apt install libvulkan1 mesa-vulkan-drivers fonts-dejavu-core fonts-noto-cjk zenity

Linux and macOS support live capture. Windows supports file inspection. Run Vanken as your normal user. Live capture needs device access or an administrator-installed helper with a fixed, root-owned runtime. The gem includes vanken-setup-permissions for Linux policies and macOS BPF access; follow the capture permissions guide before installing system permissions.

Quick start

Open a capture in the desktop interface:

vanken capture.pcapng

Use a real terminal, or print filtered packet columns without a window:

vanken --tui capture.pcapng
vanken --headless --read capture.pcapng --print-columns --filter 'tcp.port == 443'

Select a packet to inspect its fields and bytes. Enter a display filter such as tcp.port == 443 or ip.addr in {192.0.2.0/24, 198.51.100.5}, then press Enter in the filter field. Vanken display filters and BPF acquisition filters are separate languages; see the filter reference.

Run vanken without a path to open the welcome screen and choose a capture interface. Ctrl+O opens a file, Ctrl+E starts or stops capture, and Ctrl+Shift+K opens the command palette. The native macOS window uses Command instead of Ctrl; the terminal uses Ctrl on both platforms. Tab, Shift+Tab, Enter, and Escape navigate terminal controls. Run vanken --help for all CLI options.

Configuration and limits

Preferences use safe YAML in the platform's user configuration directory. Profiles separate preferences, columns, coloring rules, bookmarks, Decode As, and plugins; recent files and window geometry are shared. Stop capture before switching profiles or changing dissectors. Plugins execute with your account's permissions and require explicit trust. See the usage guide for settings paths, keyboard controls, stream and export limits, and recovery.

Live acquisition can outpace analysis on slower systems. Captured packets are stored while queued analysis finishes, but throughput, redraw latency, and memory targets remain unmet in some measured workloads. See the performance guide for handling large captures and understanding the current limits.

Documentation

License

Vanken is released under the MIT License.