The Scapy homepage
Score7.3
Rank#3 of 33
PriceFree
Free planYes
Runs onAPI, Linux, macOS, Self-hosted, Web, Windows

Summary

Scapy is a free Python program and library for working directly with network packets. It can forge or decode packets, send and capture them, and pair requests with replies. Use it as an interactive shell or from Python code; its uses include scanning, tracerouting, probing, network discovery, and unit tests. Rather than relying on fixed packet templates, users can set field values and combine protocol layers. Scapy returns decoded packets after probes, before interpretation, for further analysis. It can read and write pcap files and inject invalid frames or custom 802.11 frames. The project also documents how to add protocols and extend Scapy with add-ons. It runs on Linux, macOS, BSD, and Windows, though Windows installation requires Npcap. Plotting requires Matplotlib, and TLS decryption and PKI operations require the cryptography package. Scapy's code, tests, and tools use GPL v2; its documentation uses CC BY-NC-SA 2.5.

Who it is for

Scapy suits developers, IT staff, researchers, system administrators, and telecommunications users who need configurable packet manipulation and network probing. It is designed for users who want to define packet behavior rather than rely on fixed-purpose utilities.

What is good

  • Works as an interactive shell or Python library
  • Supports packet capture and pcap files
  • Allows arbitrary field values and stacked protocol layers
  • Provides decoded probe results for analysis

What to know first

  • Windows installation requires Npcap
  • Plotting requires Matplotlib
  • TLS decryption and PKI operations require cryptography
  • Code, tests, and tools are licensed under GPL v2

Everything Xiaomi review

Scapy: the full review

Scapy offers flexible packet construction and analysis for users comfortable working with Python. Optional dependencies and its GPL v2 licensing are worth considering before adopting it.

Overview

Scapy is a Python program and library for building, sending, capturing, and decoding network packets. It suits developers, administrators, researchers, and other users who want to shape probes themselves rather than rely on fixed-purpose tools. Its flexibility is the draw; working in Python and GPL v2 licensing make it a less natural fit for users seeking a turnkey interface or proprietary software.

Key features

Scapy works both as an interactive shell and as a Python library. Its Python-based packet description lets users set arbitrary field values and stack protocol layers without choosing from predetermined templates. That control is useful for custom probes and unusual packet handling, but it assumes comfort with Python rather than offering a narrow, guided workflow.

It can forge or decode packets, send and capture traffic, and match requests with replies. After a probe, it returns complete decoded packets before interpretation, leaving users free to analyze results their own way. Scapy also supports scanning, tracerouting, probing, network discovery, unit tests, and attacks. The breadth makes it adaptable for varied network work, though it places more responsibility on the user to decide how to interpret raw results.

Packet work extends to reading and storing PCAP files, injecting invalid frames, and creating custom 802.11 frames. Protocol documentation explains how to add new protocols and extend Scapy with add-ons, a practical advantage when standard packet definitions do not cover a task. Optional integrations include Matplotlib, PyX, Graphviz, ImageMagick, VPython-Jupyter, and cryptography; plotting requires Matplotlib, while TLS decryption and PKI operations require cryptography.

Online documentation includes installation guidance, usage guides, troubleshooting, and an API reference. The latest release can be installed with pip install scapy, or run through the run_scapy and run_scapy.bat scripts without installation. Windows installation requires Npcap.

Pricing

Scapy is free: its plan costs 0.00 USD per free and is licensed under GPLv2, with Python 3.7+ required. There is no paid tier or free trial. The free plan provides the packet-manipulation program and library without a stated seat count or usage quota; users should weigh GPL v2 for the code, tests, and tools, and CC BY-NC-SA 2.5 for the documentation, against their licensing needs.

Platforms

Scapy runs on Linux, macOS, BSD, and Windows, with Npcap required for Windows installation. The directory lists API, Linux, macOS, self-hosted, web, and Windows. Its capture and deployment options are marked both, and it supports remote capture, PCAP, CLI tools, traffic decryption, and flow analysis. The breadth suits varied environments, but the Windows Npcap dependency is an added setup requirement.

Who it's for

Scapy is best for users who need customizable packet manipulation and network probing: developers, IT and science or research teams, system administrators, and telecommunications professionals. It is a strong choice when arbitrary packet construction or analysis before interpretation matters. Users who prefer a fixed-purpose utility over a Python-driven workflow should consider a more focused analyzer.

Pros and cons

  • Pros: Arbitrary field values and protocol-layer stacking give users control over packet construction beyond predetermined templates.
  • Pros: Full decoded probe results, PCAP handling, and packet capture support flexible analysis and testing workflows.
  • Pros: Free GPL v2 software with protocol-extension guidance and an API reference can serve both scripting and interactive work.
  • Cons: Python is central to Scapy’s packet-description approach, which may not suit users looking for a guided, fixed-purpose interface.
  • Cons: Some tasks depend on optional packages; Windows installation also requires Npcap.
  • Cons: GPL v2 applies to code, tests, and tools, while documentation has a separate CC BY-NC-SA 2.5 license, so licensing fit needs consideration.

Alternatives

For another free packet-focused choice, NETCAP offers a free forever open-source CLI with 66+ audit record types and community support; its Pro plan costs 548.00 USD per month (billed). NetworkMiner is a free-edition option with source code written in managed C# on the Microsoft .NET Framework and released as GPLv2 software. Kismet is a free and open-source alternative with no paid plan or usage limit stated.

tcpdump is a free BSD-licensed option; capture permission depends on operating system and configuration. TShark is a free alternative from the Wireshark project, maintained by a nonprofit supported by donations. Wireshark offers its full version without a license fee. Arkime is open source, with no paid-only features or license fees. OpenGrep is an open-source static analysis engine delivered as a CLI.

Browse more tools in Network Protocol Analyzers and Network Packet Analyzer Software.

Verdict

Choose Scapy if you need free, highly customizable packet construction and probing in a Python workflow. Its raw decoded results and protocol extensibility are compelling for users who want to control how packets are built and analyzed. Look elsewhere if you need a fixed-purpose tool, want to avoid Python, or cannot work with its GPL v2 licensing and optional package requirements.

Scapy plans and pricing

All plans
Scapy Free GPLv2 license · Python 3.7+ scapy.net · 2 Oct 2026

Compared on network packet analyzer software

Free plan
Yesscapy.net
Traffic decryption
Yesscapy.net

Facts

Purpose
Scapy is a Python packet manipulation program and library that can forge or decode packets, send and capture them, and match requests with replies.github.com · 30 Sept 2026
Shell and library
Scapy can be used as an interactive shell or as a library.github.com · 30 Sept 2026
Network tasks
The project lists scanning, tracerouting, probing, unit tests, and network discovery among Scapy’s uses.github.com · 30 Sept 2026
Packet handling
Scapy can read and store packets in pcap files and can inject invalid frames and custom 802.11 frames.github.com · 30 Sept 2026
Protocol extensions
The documentation includes instructions for adding new protocols and extending Scapy with add-ons.scapy.readthedocs.io · 30 Sept 2026
Platform support
Scapy runs on Linux, macOS, BSD, and Windows; Windows installation requires Npcap.scapy.readthedocs.io · 30 Sept 2026
Optional dependencies
Plotting requires Matplotlib, while TLS decryption and PKI operations require the cryptography package.scapy.readthedocs.io · 30 Sept 2026
Security reporting
GitHub’s security page says the project has not set up a SECURITY.md file and provides a vulnerability reporting link.github.com · 30 Sept 2026
License
Scapy’s code, tests, and tools are licensed under GPL v2.github.com · 30 Sept 2026
Intended audiences
The project metadata lists developers, IT, science and research, system administrators, and telecommunications as intended audiences.github.com · 30 Sept 2026
Documentation
The project provides online documentation with installation instructions, usage guides, troubleshooting, and an API reference.scapy.readthedocs.io · 30 Sept 2026
Use cases
Scapy supports scanning, tracerouting, probing, unit tests, attacks and network discovery.scapy.readthedocs.io · 2 Oct 2026
Interactive modes
Scapy can be used as an interactive shell or as a library.github.com · 2 Oct 2026
Packet flexibility
Users can set arbitrary field values and stack protocol layers without predetermined templates.scapy.readthedocs.io · 2 Oct 2026
Raw results
After a probe, Scapy returns the full decoded packets before interpretation so users can analyze them in different ways.scapy.readthedocs.io · 2 Oct 2026
Python DSL
Scapy uses Python syntax and interpreter capabilities as a domain-specific language for describing packets.scapy.readthedocs.io · 2 Oct 2026
Platforms
Scapy runs on Linux, macOS, BSD and Windows; Windows installation requires Npcap.scapy.readthedocs.io · 2 Oct 2026
Installation
The latest release can be installed with pip install scapy, and it can also run from the run_scapy or run_scapy.bat scripts without installation.scapy.readthedocs.io · 2 Oct 2026
Optional integrations
Optional features can use Matplotlib, PyX, Graphviz, ImageMagick, VPython-Jupyter and cryptography.scapy.readthedocs.io · 2 Oct 2026
Licensing
Scapy code, tests and tools are licensed under GPL v2, while its documentation is licensed under CC BY-NC-SA 2.5.github.com · 2 Oct 2026
Security support
Critical bugs should be reported privately through GitHub's security tab, and the project supports only the latest Scapy master version.github.com · 2 Oct 2026
Release
Scapy documentation lists release 2.7.1 dated October 1, 2026.scapy.readthedocs.io · 2 Oct 2026
Audience
Scapy is intended for users who need customizable network probing and packet manipulation tools rather than fixed-purpose utilities.scapy.readthedocs.io · 2 Oct 2026

Best Scapy alternatives

See all 12

Where it ranks on Everything Xiaomi

Is Scapy yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources