PacketTools · Documentation

ASK — Analyst’s Shark Knife

A comprehensive Wireshark Lua plugin suite for security analytics and IOC research — real-time threat intelligence lookups straight from the packet context menu.

ASK logo
Version 0.2.7 Status License GPL v2 Wireshark 4.2+ Lua 5.1+

Version 0.2.7 improved Shodan error handling for Community subscription users, with clearer messages about subscription limits. Some features require external tools (nmap, dig, traceroute) and API keys — check the Feature Matrix below before installing.

Features

  • DNS & IP Registration (RDAP) — modern RDAP lookups, no API key required
  • IP Reputation — AbuseIPDB and VirusTotal integration
  • IP Intelligence — Shodan, IPinfo, GreyNoise, AlienVault OTX, Abuse.ch (URLhaus/ThreatFox), with VPN/Proxy/Tor detection
  • URL Reputation — urlscan.io sandbox analysis, VirusTotal, AlienVault OTX, URLhaus
  • Domain Reputation — VirusTotal and AlienVault OTX domain analysis
  • TLS Certificate Analysis — direct certificate inspection plus Certificate Transparency logs
  • SSL/TLS Security Analysis — SSLLabs API integration, no API key required
  • Email Analysis — SMTP/IMF email address analysis
  • DNS Analytics — Cloudflare DoH with dig/nslookup fallback (PTR, A, AAAA, MX, TXT, NS, SOA, CNAME)
  • Network Diagnostics — ping and traceroute
  • Network Scanning — nmap integration (SYN scan, service scan, Vulners vulnerability scan)
  • Scan Detector — optional post-dissector plugin for real-time scan detection (SYN, ACK, FIN, XMAS, NULL, UDP, ARP)

Usage

Access ASK from Wireshark’s packet context menu: right-click on a packet field → ASK → feature.

  • IP address: IP Dest → ASK → IP Reputation (AbuseIPDB)
  • DNS query: DNS → ASK → DNS Registration Info (RDAP)
  • TLS Certificate: TLS → ASK → Certificate Analysis
  • HTTP URL: HTTP → ASK → URL Reputation (urlscan.io)

Screenshots

Context menu

ASK context menu

Right-click on any packet field to access ASK features

IP reputation lookup

ASK IP reputation

IP reputation scores from multiple threat intelligence sources

URL analysis

ASK URL reputation

urlscan.io sandbox results and VirusTotal scanning

Certificate analysis

ASK certificate analysis

TLS certificate inspection and Certificate Transparency logs

Installer

ASK installer

Guided installer with version checking and upgrade detection

Installation

macOS / Linux

cd installers/macos && chmod +x install.sh && ./install.sh
cd installers/linux && chmod +x install.sh && ./install.sh

Windows — see the Windows Installation Guide: cd installers\windows; .\install.ps1

Each installer installs ask.lua, optionally the Scan Detector plugin and a JSON library, and runs the API key setup script.

Feature matrix

FeatureNo requirementsAPI keyExternal toolFree tier
DNS Registration (RDAP)✅❌❌Unlimited
IP Registration (RDAP)✅❌❌Unlimited
TLS Certificate Analysis✅❌❌Unlimited
SSL Security Analysis (SSLLabs)Limited❌curl60–120s first scan
Certificate Transparency✅❌❌Unlimited
Email Analysis✅❌❌Unlimited
IP Reputation (AbuseIPDB)❌✅❌1,000/day
IP Reputation (VirusTotal)❌✅❌4/min, 500/day
IP Intelligence (Shodan)❌Paid❌$49+ membership
IP Intelligence (IPinfo)❌✅❌50,000/month
IP Intelligence (GreyNoise)✅❌❌50 searches/week
IP Intelligence (AlienVault OTX)❌✅❌Unlimited (free)
URL Reputation (urlscan.io)LimitedRecommended❌100 scans/day
URL Reputation (VirusTotal)❌✅❌4/min, 500/day
Domain Reputation (VirusTotal)❌✅❌4/min, 500/day
DNS AnalyticsLimited❌curl / digN/A
Ping / Traceroute❌❌ping / tracerouteN/A
Nmap scans (SYN, Service, Vulners)❌❌nmapN/A
Scan Detector✅❌❌N/A

Requirements

  • Wireshark 4.2+ (for register_packet_menu support)
  • curl (for API requests and Cloudflare DoH / SSLLabs)
  • Lua JSON library (recommended, improves parsing performance)

Documentation

GuideLink
Quick Start GuideQUICKSTART.md
Platform installersinstallers/
JSON library installINSTALL_JSON_LIBRARY.md
ChangelogCHANGELOG.md

License

GNU General Public License v2.0 — see LICENSE.

Acknowledgments

Wireshark team; AbuseIPDB, VirusTotal, Shodan, IPinfo, urlscan.io, AlienVault OTX, Abuse.ch for their free tiers; RDAP.org; ssl-checker.io; Cloudflare DoH; and rxi/json.lua (MIT License).

View on GitHub → github.com/netwho/ASK