At first glance, the Packet Squirrel looks like a small, pocket-sized plastic ethernet adapter or mini router with two Ethernet ports and a USB slot. In reality, it is a covert, inline network interceptor and auditing tool (a "Device-in-the-Middle"). Placed directly between a target device (such as a VoIP phone, desktop workstation, security camera, or printer) and the wall jack leading to the corporate network switch, it silently captures network traffic, manipulates connections, or creates secure remote tunnels without alerting the user or computer.
Silent Packet Capture (PCAP):
Intercepts all network traffic flowing through the cable and saves raw packet recordings (tcpdump) directly to an attached USB flash drive for analysis in tools like Wireshark.
Stealth Operation ("Transparent Mode"):
Can operate completely invisibly at Layer 2. In stealth mode, the Packet Squirrel does not assign itself an IP address or MAC address on the target network, making standard network discovery scans unable to see it.
Network Manipulation & Spoofing:
Can actively manipulate network traffic by redirecting web browser requests (DNS Spoofing), blocking specific network connections (TCP Killing), or proxying data streams.
Encrypted Remote Tunnels (OpenVPN / WireGuard):
Can establish an encrypted, outbound VPN connection back to an auditor's command server, allowing security professionals to remotely access and test the internal network from anywhere in the world.
Flexible Hardware Switch & Storage:
Features a physical multi-position switch to easily flip between different pre-loaded testing payloads, plus USB mass storage support for saving large network capture files.
Network Packet Interception & Auditing:
Evaluates whether sensitive internal communications—such as corporate emails, unencrypted passwords, VoIP phone calls, or medical images—are transmitted across the wire in readable, clear text.
Rogue Device & Network Isolation Testing (JAIL / ISOLATE):
Tests whether an infected or unauthorized device can be programmatically isolated from the rest of the corporate network while maintaining administrative oversight.
DNS Spoofing & Phishing Resilience Checks:
Tests whether target workstations properly validate domain names and encrypted HTTPS certificates when a malicious device attempts to redirect website traffic.
Remote Access & Persistent Audit Tunnels:
Allows authorized security teams to maintain secure, encrypted remote access to a target segment during an extended physical penetration testing engagement.
Because inline network tools intercept physical wire signals downstream from endpoint operating systems, traditional software antivirus cannot detect them. Recommended defenses include:
Network Access Control (802.1X Port Authentication):
Enforce strict 802.1X authentication on switch ports. If an unauthorized hardware device disconnects and reconnects the network link without valid cryptographic credentials, shut down the switch port immediately.
Port Security & MAC Address Limits:
Configure switch ports to limit maximum allowed MAC addresses to 1 and immediately drop ports if link state changes unexpectedly.
Physical Cable & Wall Jack Inspections:
Conduct regular physical walkthroughs of offices to inspect Ethernet wall jacks, workstation desk wiring, IP conference phones, and network printers for unauthorized dongles.
Enforce Full Encryption in Transit (TLS / IPSec):
Ensure all internal services (web portals, database connections, VoIP, local file shares) enforce strong TLS/HTTPS encryption so intercepted packet captures (.pcap) contain only unreadable ciphertext.
Cable Management Cages:
Encase exposed network drops in public reception areas, lobbies, and conference rooms inside lockable conduits or wire cages.
Green (Blinking): Packet Squirrel is booting up.
Blue (Blinking): Device is in arming mode.
Red (Blinking): Error reading USB.