- Python 100%
2026-09-24 verification confirmed inx 41/42 are wire-verified (not inferred); only inx 13/14 leaves are compression-shadowed. Mark 13/14 medium, the rest high. |
||
|---|---|---|
| apkl_intel | ||
| apkl_intel_cli.py | ||
| APKL_INTEL_SPEC.md | ||
| README.md | ||
anthem-ebx
EBX tooling and the apkl_intel capture decoder.
apkl_intel
Decodes an Anthem packet capture (.apkl, a classic pcap) into structured
account/game intel. Blaze runs over TCP (TDF-encoded); the game runs over UDP
(commudp / Frostbite frames). One tool reads both.
python apkl_intel_cli.py <capture.apkl> [--json out.json] [--full]
Output
| field | source | status |
|---|---|---|
pilot_name |
Blaze UserAdded USER/NAME |
working |
persona_id |
Blaze UserAdded USER/ID |
working |
nucleus_account_id |
Blaze UserAdded USER/AID |
working |
persona_namespace |
Blaze UserAdded USER/NASP |
working |
country |
Blaze UserAdded USER/CNTY |
working |
region (datacenter) |
Blaze NotifyGameSetup GAME/PSAS |
working |
ping_sites |
Blaze traffic (aws-/bio-) | selected site working; full list partial |
mission_intent |
Blaze createGame / NotifyGameSetup ATTR |
partial (ExpeditionGameId; questId/startPoint) |
blaze.message_inventory |
all Blaze packets | working |
level_name |
game-UDP cid=260 LoadLevel | working (always Levels/Root/Root) |
missions_loaded (idx -> on-disk path) |
game-UDP cid=207 + cid=56, toc-verified | working |
spawns (ghost CREATE -> name) |
game-UDP bit-10 ghost stream + cid=207 / EBX | partial (see below) |
character_count / active_character |
HTTPS EBS /api/character/{pid}/... (TLS 443) |
BLOCKED - not in the apkl |
Verified across multiple real captures (Polysaur US/aws-iad tutorial: level Levels/Root/Root + 4 cid=207 missions, idx 14/44 toc-verified; SigmaHeroh BR/aws-brz customization: persona/region only, no mission load).
Honest limitations (see APKL_INTEL_SPEC.md sec 10):
- Characters: the roster/active javelin are HTTPS EBS over TLS 443, not on
the wire. The tool emits
persona_idand the EBS URL it would query. - Spawns: ghost CREATE bodies are opaque (no length prefix), so only a CREATE
that is the FIRST new/existing ghost in its frame is extractable; busy
playthrough captures surface few/none (see
spawn_diagnostics). SubLevel spawns overlapmissions_loaded; entity spawns are RTTI-walled. The ghost stream IS located (bit-10) and reported in diagnostics. - cid=56 names: long bundle names are LZ-compressed on the wire; full names
come from
EA_FULL_PARITY_INX_NAME_TABLE+ the toc. Pure tutorials send zero cid=56 (client builds names from the toc locally). inx 41/42 are inferred. - Perf: ~10s on the largest tutorial capture (69MB / ~19k game datagrams).
Layout
apkl_intel/
capture.py pcap -> TCP flows (Blaze) + UDP datagrams (game)
tdf.py helpers over parse_blaze_pcap TDF trees
blaze.py Blaze v2 split + decode -> persona/region/pilot/mission
game_udp.py commudp/frostbite -> missions + spawns [integration seam]
spawns.py bit-10 StreamManagerGhost CREATE extraction [integration seam]
ebx_resolve.py resolve references -> names via on-disk EBX [integration seam]
report.py assemble the unified output
apkl_intel_cli.py
Dependencies
Reuses two mature Python 3 libraries in the anthemproject tree (see
apkl_intel/deps.py; override via env):
parse_blaze_pcap.py(ANTHEM_TOOLS_DIR) - pcap + TCP + Blaze v2 + TDF.frostbite_ebx/- on-disk EBX + superbundle + codec (for spawn resolution).ANTHEM_GAME_DATA- on-diskData/Win32dir (defaultC:/gamews/Anthem2/...).
Grounding
Field locations are grounded in real captures and cross-checked against
anthem-blaze Components_Client/*. The game-UDP mission/spawn decoders and the
EBX resolution are specified against the decompiled functions + Frostbite source
in APKL_INTEL_SPEC.md.