Network flow extractor that analyzes pcap/pcapng files to identify outbound connections with automatic DNS hostname resolution.

MITAuto-check passed

Install Netflows

skills CLI
$ npx skills add BrownFineSecurity/iothackbot --skill netflows -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BrownFineSecurity/iothackbot netflows --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BrownFineSecurity/iothackbot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/netflows .claude/skills/netflows && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
netflows
GitHub stars
858
Token cost
~1k tokens
SKILL.md length
431 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Network flow extractor that analyzes pcap/pcapng files to identify outbound connections with automatic DNS hostname resolution.

  • Works in 3 steps: Gather requirements → Execute the analysis → Interpret results
  • You need to enumerate network destinations
  • SKILL.md covers Tool Overview, Instructions, Usage and Parameters, plus 4 more sections
  • Calls jq

What it does

Netflows is an agent skill from BrownFineSecurity/iothackbot. Network flow extractor that analyzes pcap/pcapng files to identify outbound connections with automatic DNS hostname resolution. Use when you need to enumerate network destinations, identify what hosts a device communicates with, or map IP addresses to hostnames from packet captures.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: IoT HackBot: A collection of Claude Skills and custom tooling for hybrid IoT pentesting. The licence is MIT.

When your agent uses it

  • You need to enumerate network destinations
  • Identify what hosts a device communicates with
  • Map IP addresses to hostnames from packet captures

Example prompts

  • “/netflows”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Gather requirements
  2. Execute the analysis
  3. Interpret results

What it can do on your machine

Read from SKILL.md and the folder at commit d443c40. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Netflows loads about 1k tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 431 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BrownFineSecurity/iothackbot at commit d443c40, republished under its MIT licence (© BrownFineSecurity). 431 words, ~1,029 tokens.

Download SKILL.mdSave it as .claude/skills/netflows/SKILL.md (or your agent's skills folder).
name
netflows
description
Network flow extractor that analyzes pcap/pcapng files to identify outbound connections with automatic DNS hostname resolution. Use when you need to enumerate network destinations, identify what hosts a device communicates with, or map IP addresses to hostnames from packet captures.

NetFlows - Network Flow Extractor with DNS Resolution

You are helping the user extract and analyze network flows from packet capture files using the netflows tool.

Tool Overview

NetFlows analyzes pcap/pcapng files to:

  • Extract unique TCP and UDP flows (destination IP:port pairs)
  • Build a DNS resolution table from DNS responses in the capture
  • Automatically resolve IP addresses to hostnames where possible
  • Filter flows by source IP address
  • Generate a summary of all network destinations contacted

This is particularly useful for IoT device analysis to understand what external services a device communicates with.

Instructions

When the user asks to analyze network flows, extract destinations, or identify what hosts a device talks to:

  1. Gather requirements:

    • Get the pcap/pcapng file path(s)
    • Ask if they want to filter by a specific source IP (e.g., the IoT device's IP)
    • Determine preferred output format
  2. Execute the analysis:

    • Use the netflows command from the iothackbot bin directory
  3. Interpret results:

    • Explain resolved hostnames and their significance
    • Note any unresolved IPs that may need further investigation
    • Highlight interesting patterns (cloud services, P2P connections, etc.)

Usage

Basic Analysis

Analyze a pcap file showing all flows:

bash
netflows capture.pcap
Filter by Source IP

Extract flows from a specific device:

bash
netflows capture.pcap --source-ip 192.168.1.100
Multiple Files

Analyze multiple capture files:

bash
netflows capture1.pcap capture2.pcapng
Output Formats
bash
# Human-readable colored output (default)
netflows capture.pcap --format text

# Machine-readable JSON
netflows capture.pcap --format json

# Minimal output - just hostname:port list
netflows capture.pcap --format quiet

Parameters

Input:

  • pcap_files: One or more pcap/pcapng files to analyze (required)

Filtering:

  • -s, --source-ip: Filter flows originating from this IP address

Output:

  • --format text|json|quiet: Output format (default: text)
  • -v, --verbose: Enable verbose output

Examples

Analyze IoT device traffic:

bash
netflows iot-capture.pcap --source-ip 192.168.1.50

Get just the flow list for scripting:

bash
netflows capture.pcap -s 10.0.0.100 --format quiet

JSON output for parsing:

bash
netflows capture.pcap --format json | jq '.data[].flow_summary'
Show full SKILL.md (177 more words)Show less

Output Information

Text format includes:

  • DNS mappings discovered (IP -> hostname)
  • TCP flows with hostname resolution status
  • UDP flows with hostname resolution status
  • Consolidated flow summary (hostname:port or ip:port)

JSON format includes:

  • dns_mappings: Dictionary of IP to hostname mappings
  • tcp_flows: List of TCP flow objects with hostname, ip, port
  • udp_flows: List of UDP flow objects with hostname, ip, port
  • flow_summary: List of "hostname:port" or "ip:port" strings
  • dns_queries: List of DNS domains queried
  • total_packets: Number of packets analyzed

Use Cases

  1. IoT Device Profiling: Identify all cloud services and endpoints an IoT device communicates with
  2. Network Forensics: Enumerate destinations contacted during an incident
  3. Privacy Analysis: Discover telemetry and tracking endpoints
  4. Firewall Rule Creation: Generate allowlist/blocklist of endpoints
  5. Malware Analysis: Identify C2 servers and exfiltration destinations

Important Notes

  • The tool resolves hostnames using DNS responses found within the same pcap file
  • IPs without corresponding DNS lookups in the capture will show as "unresolved"
  • Supports both pcap and pcapng formats
  • Does not require elevated privileges (unlike live capture tools)
  • Large pcap files may take time to process

© BrownFineSecurity, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/netflows of BrownFineSecurity/iothackbot.

Open the folder on GitHubat commit d443c40

Compare with similar skills

Netflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Netflows compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Netflows this skillBrownFineSecurity/iothackbot858—~1kAutomated safety check: PassMIT
Agent Code Analyzerruvnet/ruflo74k3 repos~1.5kAutomated safety check: PassMIT
Agent Pagerank Analyzerruvnet/ruflo74k3 repos~2.9kAutomated safety check: PassMIT
Agent Performance Analyzerruvnet/ruflo74k2 repos~1.3kAutomated safety check: PassMIT
Diff Analyzeruvnet/ruflo74k—~450Automated safety check: NotesMIT
Agent Analyze Code Qualityruvnet/ruflo74k2 repos~1.2kAutomated safety check: PassMIT

Similar skills

  • Agent skill for code-analyzer - invoke with $agent-code-analyzer

    74k GitHub starsUsed in 3 repos~1.5k tokens
    DevelopmentAuto-check passed
  • Agent skill for pagerank-analyzer - invoke with $agent-pagerank-analyzer

    74k GitHub starsUsed in 3 repos~2.9k tokens
    Auto-check passed
  • Agent skill for performance-analyzer - invoke with $agent-performance-analyzer

    74k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed
  • Diff Analyze

    ruvnet/ruflo

    Analyze git diffs for risk scoring, reviewer recommendations, and change classification.

    74k GitHub stars~450 tokensUpdated today
    DevelopmentAuto-check: notes
  • Agent skill for analyze-code-quality - invoke with $agent-analyze-code-quality

    74k GitHub starsUsed in 2 repos~1.2k tokens
    DevelopmentAuto-check passed
  • Roslyn Analyzers

    github/awesome-copilot

    Official

    Build, review, debug, package, and test Roslyn diagnostic analyzers, code fix providers, and incremental source generators.

    40k GitHub stars~9k tokensUpdated today
    Auto-check passed

More from BrownFineSecurity/iothackbot

All 8 skills in this repo
  • Chipsec

    BrownFineSecurity/iothackbot

    Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework.

    858 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Ffind

    BrownFineSecurity/iothackbot

    Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems.

    858 GitHub starsUsed in 1 repo~730 tokens
    Auto-check: notes
  • Iotnet

    BrownFineSecurity/iothackbot

    IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.

    858 GitHub starsUsed in 1 repo~1k tokens
    Auto-check: notes
  • Nmap

    BrownFineSecurity/iothackbot

    Professional network reconnaissance and port scanning using nmap.

    858 GitHub starsUsed in 1 repo~3.8k tokens
    Auto-check: notes
  • Onvifscan

    BrownFineSecurity/iothackbot

    ONVIF device security scanner for testing authentication and brute-forcing credentials.

    858 GitHub starsUsed in 1 repo~608 tokens
    Auto-check passed
  • Wsdiscovery

    BrownFineSecurity/iothackbot

    WS-Discovery protocol scanner for discovering and enumerating ONVIF cameras and IoT devices on the network.

    858 GitHub starsUsed in 1 repo~628 tokens
    Auto-check passed

Questions about Netflows

What does Netflows do?

Network flow extractor that analyzes pcap/pcapng files to identify outbound connections with automatic DNS hostname resolution. Netflows is an agent skill from BrownFineSecurity/iothackbot. Network flow extractor that analyzes pcap/pcapng files to identify outbound connections with automatic DNS hostname resolution.

When should I use Netflows?

Netflows fits situations like: you need to enumerate network destinations; identify what hosts a device communicates with; map IP addresses to hostnames from packet captures.

How do I install Netflows in Claude Code?

Run `npx skills add BrownFineSecurity/iothackbot --skill netflows -a claude-code`. Or copy the skill folder (skills/netflows in BrownFineSecurity/iothackbot) into .claude/skills/netflows in your project. Claude Code loads it when a task matches its description.

How do I install Netflows in Codex?

Run `npx skills add BrownFineSecurity/iothackbot --skill netflows -a codex`. Or copy the skill folder (skills/netflows in BrownFineSecurity/iothackbot) into .agents/skills/netflows in your project. Codex loads it when a task matches its description.

Can I use Netflows in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BrownFineSecurity/iothackbot --skill netflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/netflows, .gemini/skills/netflows, .github/skills/netflows and .opencode/skills/netflows in your project.

What does Netflows need to run?

Going by SKILL.md and its folder, Netflows needs the command-line tools its instructions call (jq).

Does Netflows access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Netflows safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Netflows use?

Netflows is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Netflows use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Netflows?

Skills that share tags, products or a category with Netflows: Agent Code Analyzer (ruvnet/ruflo, 74k stars), Agent Pagerank Analyzer (ruvnet/ruflo, 74k stars), Agent Performance Analyzer (ruvnet/ruflo, 74k stars) and Diff Analyze (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Netflows?

BrownFineSecurity (a GitHub organization) maintains it in BrownFineSecurity/iothackbot, which has 858 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on June 1, 2026.

Source: BrownFineSecurity/iothackbot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.