Skip to content

About

Work-in-progress TCP/UDP network packet analyzer and interceptor with Frida support and Photon protocol dissection.

Topics

Resources

Stars

2 stars

Watchers

0 watching

Forks

Latest commit

 

History

6 Commits

Folders and files

Repository files navigation

PacketCraft

PacketCraft is a Windows desktop packet-analysis and interception tool aimed at low-level game protocol research. It captures complete IPv4/IPv6 packets with WinDivert, keeps application payloads separately, supports Frida plaintext hooks, and provides strict Photon GpBinaryV16/GpBinaryV18 inspection and editing.

Use it only on software and networks you own or are authorized to test.

Current capabilities

  • Full raw IP-frame retention plus validated TCP/UDP payload extraction
  • IPv4, IPv6 extension-header, and fragment-aware parsing
  • TCP sequence/ACK/flags/window metadata and bounded directional stream reassembly
  • Retransmission, overlap, out-of-order, gap-fill, and stream-offset diagnostics
  • HTTP/1 message/body/chunked decoding across TCP segments
  • TLS record and handshake metadata, including ClientHello SNI, ALPN, and supported versions
  • HTTP/2 frame, WebSocket frame/mask, JSON, UTF-8 text, and binary payload classification
  • Bidirectional TCP Streams workspace with searchable flows, conversation view, and per-direction data
  • Dynamic process, protocol, and port filters
  • Non-blocking intercept hold/forward/drop/modify workflow with Photon transport bypass, reliable-command auto-ACK, and retransmission deduplication
  • PCAP export using real IP frames; JSON/CSV export for wire and Frida records
  • Photon UDP command parsing, fragment reassembly, PID-scoped payload keys, and AES-CBC payload decryption
  • Photon GpBinaryV16 and GpBinaryV18 values, including heterogeneous maps, typed arrays, dictionary arrays, hashtable arrays, custom values, events, requests, and responses
  • Checked Photon reserialization and protocol-aware operation injection
  • Frida socket, TLS, Steam P2P, Photon high-level event, and InitPayloadEncryption hooks

Synthetic high-level Photon hook events are labeled Frida/Photon Event; they are never presented as captured wire packets.

Intercepting Photon traffic

The interceptor defaults to Application data only. Empty TCP control packets and Photon ACK, Ping, Connect, VerifyConnect, Disconnect, ServerTime, and AckToAll commands continue flowing while operation, response, event, fragment, RPC, and other application-bearing packets can stop at a Hold rule.

Auto-ACK held reliable Photon prevents a sender from retransmitting the same reliable sequence while it is being inspected. PacketCraft also deduplicates any retransmission that races the generated ACK. If the held command is later dropped, the sender intentionally retains that ACK; this is the expected semantics of an interactive reliability-layer interceptor.

Held TCP application segments use a separate flow/sequence-range/payload identity. Exact retransmissions therefore remain one pending breakpoint instead of flooding the interceptor; payloads that differ at the same sequence are deliberately kept distinct and observable.

The default tool timeout is Never. A finite timeout can be selected in seconds; expiry then forwards the original packet and is reported in the interceptor status. Remote applications can still have their own request/session timeout. Use F to forward the selected packet and advance to the next queued breakpoint, or use Forward all to drain the queue.

Build prerequisites

  • Windows 10/11 x64
  • Visual Studio C++ toolchain with C++20 support
  • CMake 3.20 or newer and Ninja
  • Qt 6 (Core, Widgets, and Network)
  • WinDivert and Frida Core development files under the ignored local dependency tree:
third_party/
  WinDivert/
    windivert.h
    x64/WinDivert.lib
    x64/WinDivert.dll
    x64/WinDivert64.sys
  Frida/
    include/frida-core.h
    frida-core.lib

Example developer build:

cmake -S . -B build -G Ninja `
  -DCMAKE_PREFIX_PATH=C:\Qt\6.11.1\msvc2022_64 `
  -DCMAKE_BUILD_TYPE=Debug
cmake --build build --parallel
ctest --test-dir build --output-on-failure

Packet capture requires Administrator privileges. The build copies WinDivert runtime files and the bundled Frida scripts beside PacketCraft.exe.

Photon architecture

  • PhotonParser: Photon UDP frames, commands, strict message detection, and bounded fragment reassembly
  • PhotonValueCodec: safe bounded GpBinaryV16/V18 decoding
  • PhotonSerializer: checked message/frame encoding; refuses partial or encrypted edits
  • PhotonTypes: lossless semantic values and display metadata
  • PhotonCryptoStore: process-scoped key ownership and payload decryption
  • PhotonInject: protocol-aware ACK and operation frame construction

TCP and TLS analysis

TCP decoding is flow-based rather than packet-based:

  1. PacketParser retains sequence, acknowledgement, flags, header length, window, and urgent pointer metadata.
  2. TcpStreamReassembler removes retransmission overlap, buffers bounded out-of-order segments, fills gaps, and emits only newly contiguous bytes.
  3. PayloadDecoder identifies and decodes HTTP/1, TLS records/handshakes, HTTP/2 frames, WebSocket frames, JSON, text, and unknown binary data.
  4. TrafficAnalyzer maintains bounded per-flow decoder state and applies the same semantics to WinDivert wire data and Frida plaintext records.

The Packet History protocol column shows the detected application protocol. Select a packet for TCP metadata, decoder fields, diagnostics, raw segment bytes, and reassembled bytes. The TCP Streams tab groups both directions of a connection, supports endpoint/protocol/context search, and provides conversation plus A→B/B→A views.

TLS application records on the wire are intentionally labeled encrypted. There is no universal way to recover their plaintext from ciphertext alone. Attach the Frida hook to an authorized target to capture data at OpenSSL/BoringSSL, SChannel, WinHTTP, WinINet, GnuTLS, mbedTLS, or libcurl plaintext boundaries. Hook records carry API handle/context identities so concurrent plaintext streams from the same PID are not merged. Custom application encryption still requires a protocol-specific key source or application hook.

For the reliable TLS workflow, select a wire packet and use Tools -> Attach Frida to <process> (PID ...) (Ctrl+Shift+F). This targets the exact process owning the socket instead of a similarly named parent process. Generate new traffic and check Frida Logs:

  • [TLS COVERAGE] lists hooks installed in that PID.
  • [TLS HIT] proves that a supported hook actually observed plaintext.
  • Decrypted records appear separately with Source = Frida/TLS; the original Source = WinDivert TLS record remains ciphertext by design.

Chromium/Electron applications such as Discord and WebView commonly perform networking in a child process and may embed a stripped BoringSSL build with no public SSL_read/SSL_write export. Selecting the packet first solves the child-PID problem. If coverage is installed but no [TLS HIT] appears, that exact application build needs either TLS session-key logging enabled before the handshake or a version-specific BoringSSL/high-level IPC hook. Attaching after the request cannot retroactively recover plaintext or session secrets from an existing ciphertext record.

Resource bounds protect long-running sessions: 4 MiB pending/reassembly limits per flow, 4,096 active flow states, two-minute inactive-state expiry, 16 MiB framed-message limits, and 256 KiB decoded text/body retention per record. These failures remain visible as diagnostics instead of being silently ignored.

The codec tests cover V16/V18 round trips, arbitrary map keys, compact integers, UTF-8 strings, map/custom arrays, malformed frames, partial-frame rejection, and intercept command classification. Capture tests cover IPv4, IPv6, direction metadata, UDP bounds, raw-frame retention, non-initial fragments, and endpoint reversal. Queue tests cover indefinite holds, retransmission deduplication, explicit release, and observable configured timeout behavior. TCP tests cover header metadata, segmented HTTP, chunked bodies, retransmission suppression, out-of-order gap fill, split TLS/HTTP2 headers, TLS SNI extraction, WebSocket unmasking, and Frida stream identity isolation.

About

Work-in-progress TCP/UDP network packet analyzer and interceptor with Frida support and Photon protocol dissection.

Topics

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Contributors

Languages