vkg6835/signature-traffic-detector ? reverse-engineered prompt
Reverse engineered prompt
Build me a Rust command line tool that reads a pcap file, rebuilds the network conversations, and tells me which ones look benign, suspicious, or malicious by matching them against known bad indicators from abuse.ch feeds. It should work offline too, using a bundled fallback set if there is no API key or network access, and it should cache feed downloads so it does not fetch them every time. I want it to understand basic Ethernet, IPv4, TCP, UDP, DNS, HTTP, and TLS enough to pull out things like hostnames, URLs, SNI, and payload hashes, then generate a clear console summary plus a JSON report of every flow and every match. Please also include a small demo mode that can generate a sample pcap and a few useful flags like verbose output, rule listing, exact matches only, and a confidence threshold. Look up current docs online if you need to.
Are you gonna build this?
make sure you review the code using coderabbit