{"id":475,"date":"2008-07-10T06:30:34","date_gmt":"2008-07-10T14:30:34","guid":{"rendered":"http:\/\/www.sapien.com\/blog\/?p=475"},"modified":"2008-07-10T07:03:49","modified_gmt":"2008-07-10T15:03:49","slug":"get-packet","status":"publish","type":"post","link":"https:\/\/dev.sapien.com\/blog\/2008\/07\/10\/get-packet\/","title":{"rendered":"Get-Packet"},"content":{"rendered":"<p>A few days ago I blogged about <a target=\"_blank\" href=\"http:\/\/www.sapien.com\/blog\/2008\/07\/03\/powershell-ip-packet-sniffer-script\/\">packet sniffer PowerShell script<\/a>. Needless to say I was intrigued and spent some time dissecting to better understand it. Don&#8217;t worry, no PowerShell scripts were harmed during this operation. This is a nifty piece of PowerShell coding. Of course I&#8217;m never one to leave well enough alone so I had to add a few touches which I hope the original author doesn&#8217;t mind. You can download my version <a target=\"_blank\" href=\"http:\/\/www.sapien.com\/blog\/wp-content\/uploads\/2008\/07\/get-packet.txt\">here<\/a><\/p>\n<p>First, the original script kept running unless you pressed Ctrl-C.&nbsp; I made some slight modifications so that the script could end more gracefully.<\/p>\n<p><code>$ESCkey&nbsp; = 27<br \/>\nWrite-Host &quot;Press the ESC key to stop sniffing&quot; -foregroundcolor &quot;CYAN&quot;<br \/>\n$Running=$true<br \/>\nWhile ($Running)<br \/>\n&nbsp;{<br \/>\n&nbsp;<br \/>\n&nbsp; if ($host.ui.RawUi.KeyAvailable) {<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $key = $host.ui.RawUI.ReadKey(&quot;NoEcho,IncludeKeyUp,IncludeKeyDown&quot;)<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; if ($key.VirtualKeyCode -eq $ESCkey) { <br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $Running=$False<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }<\/code><\/p>\n<p>The main packet sniffing code is within the While loop. It will run until the Esc key is pressed. The ReadKey() method detects key strokes and if the VirtualKeyCode property equals the value for the Esc key, $Running is set to $False and the script will end. This makes it much easier to save output to a variable:<\/p>\n<p><font face=\"Consolas\" color=\"#0000ff\">PS C:\\$sniff=c:\\scripts\\get-packet.ps1<\/font><\/p>\n<p>I also added a timestamp property to the custom object so I could do time-related analysis later.<\/p>\n<p><code>$obj | Add-Member noteproperty Time (Get-Date)<\/code><\/p>\n<p>This property lets me do tasks like this which displays packet information with a timestamp value that includes milliseconds<\/p>\n<p><font face=\"Consolas\" color=\"#0000ff\">PS C:\\&gt;$sniff [0..100] | Select @{Name=&quot;timeStamp&quot;;Expression={(new-timespan $_.time).ToString() }},Source,Destination,Protocol,*Port<\/font><\/p>\n<p><font face=\"Consolas\" color=\"#0000ff\">timeStamp&nbsp;&nbsp; : 21:32:18.2082876<br \/>\nSource&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 207.46.236.102<br \/>\nDestination : 172.16.10.102<br \/>\nProtocol&nbsp;&nbsp;&nbsp; : TCP<br \/>\nDestPort&nbsp;&nbsp;&nbsp; : 50392<br \/>\nSourcePort&nbsp; : 21 <\/font><\/p>\n<p><font face=\"Consolas\" color=\"#0000ff\">timeStamp&nbsp;&nbsp; : 21:32:18.1892849<br \/>\nSource&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 207.46.236.102<br \/>\nDestination : 172.16.10.102<br \/>\nProtocol&nbsp;&nbsp;&nbsp; : TCP<br \/>\nDestPort&nbsp;&nbsp;&nbsp; : 50392<br \/>\nSourcePort&nbsp; : 21 <\/font><\/p>\n<p><font face=\"Consolas\" color=\"#0000ff\">timeStamp&nbsp;&nbsp; : 21:32:18.1642815<br \/>\nSource&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : 207.46.236.102<br \/>\nDestination : 172.16.10.102<br \/>\nProtocol&nbsp;&nbsp;&nbsp; : TCP<br \/>\nDestPort&nbsp;&nbsp;&nbsp; : 50395<br \/>\nSourcePort&nbsp; : 20<\/font><\/p>\n<p>I also made some slight changes to the original code for creating the custom object which is probably just a personal preference since the original worked just fine. The original was written as one long pipelined expression.&nbsp; Personally I found it harder to troubleshoot.<\/p>\n<p>Once I&#8217;ve saved my trace to a variable, here are some things I can do with it. Depending on how long your trace ran, this variable could be quite large.<\/p>\n<p><font face=\"Consolas\" color=\"#0000ff\">PS C:\\&gt; $sniff | sort protocol | group protocol | format-table Count,Name -autosize <\/font><\/p>\n<p><font face=\"Consolas\" color=\"#0000ff\">Count Name<br \/>\n&#8212;&#8211; &#8212;-<br \/>\n&nbsp;&nbsp; 42 ICMP<br \/>\n&nbsp;&nbsp; 17 IGMP<br \/>\n6496 TCP<br \/>\n&nbsp; 163 UDP<\/font><\/p>\n<p><font face=\"Consolas\" color=\"#0000ff\">PS C:\\&gt; $sniff | sort SourcePort | group SourcePort |&nbsp;<\/font><font face=\"Consolas\" color=\"#0000ff\">sort count -descending | <br \/>\n&gt;&gt; Select -first 5 |&nbsp;format-table Count,Name -autosize<br \/>\n&gt;&gt;<br \/>\n<\/font><font face=\"Consolas\" color=\"#0000ff\"><br \/>\nCount Name<br \/>\n&#8212;- &#8212;-<br \/>\n5747 80<br \/>\n401 143<br \/>\n113 23<br \/>\n&nbsp; 93 53<br \/>\n&nbsp; 59 0<\/font><\/p>\n<p>If you have suggestions for enhancements or improvements, I&#8217;d love to hear them. Stay tuned to the blog as well.&nbsp; I have an addition to this script that I think you&#8217;ll find interesting, at least I hope so.<\/p>\n<p>&nbsp;<\/p>\n<p>While ($Running)<br \/>\n&nbsp;&nbsp;&nbsp; {<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp; if ($host.ui.RawUi.KeyAvailable) {<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $key = $host.ui.RawUI.ReadKey(&quot;NoEcho,IncludeKeyUp,IncludeKeyDown&quot;)<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; if ($key.VirtualKeyCode -eq $ESCkey) { <br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; $Running=$False<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A few days ago I blogged about packet sniffer PowerShell script. Needless to say I was intrigued and spent some time dissecting to better understand it. Don&#8217;t worry, no PowerShell scripts were harmed during this operation. This is a nifty piece of PowerShell coding. Of course I&#8217;m never one to leave well enough alone so I had to add a few touches which I hope the original author doesn&#8217;t mind.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[25],"tags":[223,221,28,57,219],"class_list":["post-475","post","type-post","status-publish","format-standard","hentry","category-windows-powershell","tag-add-member","tag-network","tag-powershell","tag-scripting","tag-trace"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts\/475","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/comments?post=475"}],"version-history":[{"count":0,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/posts\/475\/revisions"}],"wp:attachment":[{"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/media?parent=475"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/categories?post=475"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dev.sapien.com\/blog\/wp-json\/wp\/v2\/tags?post=475"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}