Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- SET outputpath="C:\test2.csv"
- SET inputpath="C:\capture.pcapng"
- REM Displays the packets analysis and create an output file for them
- tshark -r %inputpath% -E separator=, -T fields -e frame.number -e ip.src -e ip.dst_host -e ipv6.src -e ipv6.dst -e eth.src -e eth.dst -e ip.proto -e tcp.srcport -e tcp.dstport -e udp.srcport -e udp.dstport -e _ws.col.Protocol -e _ws.col.Info -E header=y > %outputpath%
- REM Gets the amount of packets for each filter and append to the output file
- tshark -r %inputpath% -Y "http" | find /c /v "" >> %outputpath%
- tshark -r %inputpath% -Y "dns" | find /c /v "" >> %outputpath%
- tshark -r %inputpath% -Y "tcp" | find /c /v "" >> %outputpath%
- tshark -r %inputpath% -Y "arp" | find /c /v "" >> %outputpath%
- tshark -r %inputpath% -Y "udp" | find /c /v "" >> %outputpath%
- REM Gets the amount of 3 way hand-shake packets
- tshark -r %inputpath% -Y "tcp.flags.syn==1 or (tcp.seq==1 and tcp.ack==1 and tcp.len==0 and tcp.analysis.initial_rtt)" | find /c /v "" > temp.txt
- SET /p number=<temp.txt
- REM Divides the amount of packets by 3(as you need 3 packets to form a 3 way hand-shake)
- SET /A amount=%number%/3
- echo %amount% >> %outputpath%
- PAUSE
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement