Passive network discovery tool focused on Layer 2 and Layer 3 packets
...It aggregates discovered hosts by MAC address, attempts to
measure passive RTTs for request/response protocols, maintains per-protocol RTT
histories and simple service hints, and can emit structured events and a final
table in JSON or CSV formats.
...It offers powerful filters called “tags” and distributions that let you narrow results to specific categories like bug bounties, cryptocurrencies, or AWS-related artifacts. For automation and integration, pyWhat provides a CLI with options for rarity filtering, sorting, and JSON export, as well as an API that can be imported into other Python programs.