For i need a software to monitor the entire network traffic from my network set network policies and setup alerts, the strongest matches are gyulyvgc/sniffnet (Sniffnet is a desktop network traffic analyzer that provides), ntop/ntopng (ntopng is a self-hostable web-based network traffic monitoring tool) and arkime/arkime (Arkime is a distributed full packet capture system and). aol/moloch and tianshiyeben/wgcloud round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Hand-picked open-source network traffic monitors for setting policies and alerts. Compare the top tools and find the right fit.
This application is a desktop network traffic analyzer that provides real-time monitoring and forensic inspection of data packets. By interfacing directly with low-level system drivers, it captures raw network traffic from physical or virtual adapters to identify communication patterns, track bandwidth usage, and diagnose connectivity issues. The system distinguishes itself through an immediate-mode graphical interface that rebuilds the display state every frame, ensuring high responsiveness during live data updates. It maintains performance by using asynchronous message passing to decouple t
Sniffnet is a desktop network traffic analyzer that provides real-time packet capture, bandwidth monitoring, and alert management, though it functions as a local GUI application rather than a centralized, self-hosted server tool for policy enforcement.
ntopng is a web-based network traffic monitoring tool and flow data aggregator. It functions as a network security monitor, an SNMP network management system, and an industrial protocol analyzer for OT and SCADA environments. The system provides specialized inspection for industrial protocols such as Modbus, DNP3, and IEC 60870. It distinguishes itself through behavioral threat detection, encrypted traffic analysis via handshake fingerprinting, and the ability to identify hardware and operating systems using DHCP and MAC address patterns. Its broader capabilities include real-time traffic an
ntopng is a self-hostable web-based network traffic monitoring tool that offers flow visualization, metrics, and network alerting systems, though it focuses more on traffic analysis and protocol inspection than strict policy enforcement.
Arkime is a distributed packet analysis platform and full packet capture system designed for recording raw network traffic, indexing metadata, and performing network forensics. It functions as a network traffic indexer and security tool that enables the monitoring, querying, and browsing of large-scale network traffic across multi-cluster architectures. The platform distinguishes itself through its ability to manage distributed capture clusters from a centralized administrative dashboard. It integrates external data feeds with internal traffic logs to identify known threats and provides a pro
Arkime is a distributed full packet capture system and network traffic indexer that provides deep packet analysis and monitoring capabilities, though it lacks dedicated network policy enforcement features.
Moloch is a full packet capture system and network forensics platform designed for large scale network traffic recording and indexing. It functions as a distributed packet indexer that stores raw data in PCAP format for deep packet analysis and security investigations. The system distinguishes itself through a decentralized architecture that distributes capture and viewing components across multiple nodes to handle high volumes of network traffic. It utilizes a web-based management interface for browsing network sessions and provides a programmable API for exporting captured traffic and metad
Moloch is a distributed packet capture and forensics platform that provides deep traffic analysis and session browsing, though it lacks built-in network policy enforcement and automated alerting features.
wgcloud is a comprehensive suite of monitoring and management tools designed for Linux servers, network devices, containers, and middleware. It functions as a centralized dashboard for tracking real-time hardware metrics, auditing the health of Docker and Kubernetes environments, and maintaining an IT asset management system for physical and cloud infrastructure. The platform is distinguished by its integrated remote administration capabilities, featuring a web-based SSH client for executing bulk commands and managing servers directly from a browser. It further differentiates itself with AI-d
This Java-based infrastructure monitoring tool offers real-time dashboards, device discovery, and multi-channel alerting, though it focuses more on server health and asset management than deep packet capture and traffic analysis.
Portmaster is a host-based network firewall and privacy tool that monitors and controls all system network traffic. It operates by intercepting data packets at the operating system level, allowing it to observe and manage every connection made by local software in real time. The software distinguishes itself through process-aware connection mapping, which correlates active network sockets with specific local applications to provide visibility into data transfers. It utilizes a user-space policy engine to enforce granular security rules, enabling users to restrict internet access, block specif
Portmaster is a host-based network firewall and traffic monitor that inspects connections and enforces granular rules, making it a strong tool for local network control though it focuses more on host endpoints than comprehensive enterprise flow visualization.
Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o
Maltrail is a network traffic analysis and intrusion detection system featuring sensor-based monitoring and threat dashboards, though it focuses more on malicious traffic detection than general network policy enforcement.
FastNetMon is a network traffic analyzer and DDoS detection system designed to identify and mitigate distributed denial of service attacks. It functions as a BGP blackhole controller and mitigation orchestrator, monitoring network traffic in real time to detect hosts that exceed predefined thresholds for packets, bytes, or flows per second. The system distinguishes itself through automated mitigation capabilities, using BGP-based route announcements to block malicious IP addresses across network infrastructure. It supports hardware-specific interventions for vendors such as Juniper and MikroT
FastNetMon is a high-performance network traffic analyzer and DDoS detection system that captures packets and flows, provides metric-based analysis, and triggers automated mitigations, though it focuses more on security and DDoS defense rather than comprehensive general-purpose network policy enforcement and visualization.
Pi.Alert is a self-hosted local area network monitoring utility and scanner that catalogs connected hardware, tracks real-time online status, and alerts administrators to unauthorized devices. It combines multiple discovery methods including address resolution protocol requests, dynamic host configuration protocol lease parsing, and domain name system query logs to comprehensively locate and identify active equipment. The application serves a centralized web-based management interface backed by a relational database inventory to store device metadata, user classifications, and historical acti
Pi.Alert is a self-hostable network monitoring tool that scans connected Wi-Fi and LAN devices to provide alerts for unknown or disconnected devices, though it focuses more on intrusion detection than deep traffic analysis and policy enforcement.
Pi.Alert is a home network monitoring and intruder detection system designed to track connected devices and maintain an active inventory across local area networks. It functions as a network discovery tool, topology mapper, and uptime monitor that alerts administrators when unknown devices connect or known hardware goes offline. The platform provides a central dashboard for visualizing infrastructure links, monitoring website availability, and inspecting SSL certificates through periodic health checks. The application supports distributed satellite scanning, allowing remote monitoring nodes i
Pi.alert is a self-hostable network monitoring tool that tracks connected devices and scans for security issues, though it is more focused on device inventory and alerts than deep packet capture or policy enforcement.
| Repositorio | Estrellas | Lenguaje | Licencia | Último push |
|---|---|---|---|---|
| gyulyvgc/sniffnet | 39.3K | Rust | Apache-2.0 | |
| ntop/ntopng | 7.9K | Lua | GPL-3.0 | |
| arkime/arkime | 7.4K | C | Apache-2.0 | |
| aol/moloch | 7.4K | C | Apache-2.0 | |
| tianshiyeben/wgcloud | 5.1K | Java | Apache-2.0 | |
| safing/portmaster | 13K | Go | GPL-3.0 | |
| stamparm/maltrail | 8.5K | Python | MIT | |
| pavel-odintsov/fastnetmon | 3.7K | C++ | GPL-2.0 | |
| pucherot/pi.alert | 2.5K | JavaScript | GPL-3.0 | |
| leiweibau/pi.alert | 1K | PHP | gpl-3.0 |