Security Tool Architecture: How Wireshark, Nmap & mitmproxy Work Inside

Security tools get used constantly and read almost never. Wireshark, Nmap, mitmproxy and OpenSSH are some of the most carefully engineered C and Python codebases in open source, because a parsing bug in a packet analyzer or a privilege bug in an SSH daemon is itself a vulnerability. The architecture is the security model.

Each page below is an analysis of the actual source: module maps, execution flows and diagrams generated from the code, not a feature tour. If you want to know how a dissector table dispatches packets or how a scanner schedules thousands of probes, this is where it lives.

Security Tools: full architecture breakdowns

Patterns that show up across security tooling

Untrusted input is the default

Every tool here parses bytes an attacker controls: packets, TLS streams, service banners, SSH handshakes. The architectural response is isolation. Parsers are separated from the code that holds privileges, and malformed input is expected rather than exceptional.

Plugin engines around a stable core

Wireshark registers protocol dissectors into dispatch tables, Nmap runs Lua scripts through its scripting engine, and mitmproxy exposes event hooks to addons. The core handles capture, scheduling and I/O; the long tail of protocols and checks lives in plugins.

Privilege separation

OpenSSH splits into a small privileged monitor and an unprivileged process that does the risky parsing. Capture tools drop root after opening the interface. The code that needs power is kept as small as possible and audited hardest.

More security-relevant architectures

  • vaultwarden Architecture — Rust
    Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs

Frequently asked questions

How is Wireshark structured internally?

Wireshark separates packet capture, a dissection engine and the user interface. Protocol dissectors register themselves into dispatch tables keyed by port, protocol number or heuristics, so adding a protocol means adding a dissector rather than changing the core. The Wireshark analysis below maps those modules from the source.

How does Nmap scan so many hosts at once?

Nmap schedules probes asynchronously and adapts timing to observed network conditions, instead of waiting on each host in turn. Service detection and the Nmap Scripting Engine (Lua) run on top of that scan core.

What is privilege separation?

A design where a program is split into a small privileged part and a larger unprivileged part that handles untrusted input. If the unprivileged part is compromised, the attacker does not get the privileges. OpenSSH is the classic example.

Can I get this analysis for my own codebase?

Yes. These pages are generated by Revibe's codebase analysis. Import a repository from GitHub or upload a zip and you get the same architecture diagrams, module maps and execution flows for your own project.

Explore every analysis in the Revibe Codes gallery, or analyze your own codebase to get the same architecture diagrams, module maps, and execution flows.