Agent Skills: analyzing-network-flow-data-with-netflow

>-

UncategorizedID: autohandai/community-skills/analyzing-network-flow-data-with-netflow

Install this agent skill to your local

pnpm dlx add-skill https://github.com/autohandai/community-skills/tree/HEAD/analyzing-network-flow-data-with-netflow

Skill Files

Browse the full folder contents for analyzing-network-flow-data-with-netflow.

Download Skill

Loading file tree…

analyzing-network-flow-data-with-netflow/SKILL.md

Skill Metadata

Name
analyzing-network-flow-data-with-netflow
Description
>-

Instructions

  1. Install dependencies: pip install netflow
  2. Collect NetFlow/IPFIX data from routers or use the built-in collector: python -m netflow.collector -p 9995
  3. Parse captured flow data using netflow.parse_packet().
  4. Analyze flows for:
    • Port scanning: single source to many destinations on same port
    • Data exfiltration: high byte-count outbound flows to unusual destinations
    • C2 beaconing: periodic connections with consistent intervals
    • Volumetric anomalies: traffic spikes beyond baseline thresholds
  5. Generate a prioritized findings report.
python scripts/agent.py --flow-file captured_flows.json --output netflow_report.json

Examples

Parse NetFlow v9 Packet

import netflow
data, _ = netflow.parse_packet(raw_bytes, templates={})
for flow in data.flows:
    print(flow.IPV4_SRC_ADDR, flow.IPV4_DST_ADDR, flow.IN_BYTES)