For a tool for capturing and analyzing network traffic, the strongest matches are gyulyvgc/sniffnet (Sniffnet is a full-featured desktop network traffic analyzer with), wireshark/wireshark (Wireshark is the leading open-source network protocol analyzer: it) and arkime/arkime (Arkime is a full-packet capture and metadata-indexing platform with). ntop/ntopng and emanuele-f/pcapdroid round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Open-source tools for monitoring, intercepting, and inspecting data packets across local and wide area networks.
This application is a desktop network traffic analyzer that provides real-time monitoring and forensic inspection of data packets. By interfacing directly with low-level system drivers, it captures raw network traffic from physical or virtual adapters to identify communication patterns, track bandwidth usage, and diagnose connectivity issues. The system distinguishes itself through an immediate-mode graphical interface that rebuilds the display state every frame, ensuring high responsiveness during live data updates. It maintains performance by using asynchronous message passing to decouple t
Sniffnet is a full-featured desktop network traffic analyzer with real-time packet capture, protocol analysis, and a responsive GUI, making it a strong fit for your packet capture and analysis needs.
Wireshark is a network protocol analyzer and traffic inspector used for capturing and inspecting network traffic. It functions as a packet capture tool that intercepts live data from network interfaces and a TCP/IP dissector that decodes network protocol layers to translate raw binary packets into human-readable fields. The system provides capabilities for protocol stream reconstruction, grouping related packets into cohesive conversations between endpoints. It also operates as a packet file converter, allowing for the reading, modification, and conversion of network capture files across vari
Wireshark is the leading open-source network protocol analyzer: it captures live packets from interfaces, dissects hundreds of protocols, provides real-time traffic analysis and filtering, offers both a graphical interface and the command-line tshark tool, generates statistics and graphs, and can export captured data to pcap format — exactly matching your search.
Arkime is a distributed packet analysis platform and full packet capture system designed for recording raw network traffic, indexing metadata, and performing network forensics. It functions as a network traffic indexer and security tool that enables the monitoring, querying, and browsing of large-scale network traffic across multi-cluster architectures. The platform distinguishes itself through its ability to manage distributed capture clusters from a centralized administrative dashboard. It integrates external data feeds with internal traffic logs to identify known threats and provides a pro
Arkime is a full-packet capture and metadata-indexing platform with a centralized dashboard for querying and browsing network traffic, making it a comprehensive match for real-time packet analysis, protocol dissection, and traffic pattern inspection.
ntopng is a web-based network traffic monitoring tool and flow data aggregator. It functions as a network security monitor, an SNMP network management system, and an industrial protocol analyzer for OT and SCADA environments. The system provides specialized inspection for industrial protocols such as Modbus, DNP3, and IEC 60870. It distinguishes itself through behavioral threat detection, encrypted traffic analysis via handshake fingerprinting, and the ability to identify hardware and operating systems using DHCP and MAC address patterns. Its broader capabilities include real-time traffic an
ntopng is a comprehensive web-based network traffic monitoring and analysis tool with real-time traffic capture, protocol dissection (including industrial protocols), behavioral analysis, and extensive dashboards and statistics, exactly matching the need for a full-featured open-source packet analyzer.
PCAPdroid is an Android network traffic analyzer and packet capture tool that operates without requiring root access. It functions as a VPN-based firewall and network controller, capable of recording traffic in PCAPng format and blocking connections to specific domains or malicious hosts. The project distinguishes itself through a proxy-based system for decrypting TLS traffic and routing device network traffic through SOCKS5 proxies or the Tor network. It further allows for the modification of live HTTP requests and responses via custom scripts. Its capabilities cover application connection
PCAPdroid is an Android network traffic analyzer that captures packets without root and exports them in PCAP format, but it lacks a command-line interface and is limited to mobile devices rather than general network interfaces.
Termshark is a terminal-based network packet analyzer and protocol flow inspector. It serves as a keyboard-driven interface for the tshark command-line utility, providing a terminal user interface to monitor data flow and analyze network traffic. The tool functions as a terminal interface for Wireshark, utilizing its filtering and inspection logic to analyze recorded capture files or live network interfaces. It specifically enables the reassembly and inspection of TCP and UDP flows to isolate traffic patterns and analyze network conversations by protocol. The system includes capabilities for
Termshark is a terminal-based network packet analyzer that uses Wireshark's capture and dissection engine, offering live capture, protocol inspection, and filtering through a keyboard-driven TUI—this fits your need for a traffic analysis tool, though its interface is terminal-based rather than graphical.
Moloch is a full packet capture system and network forensics platform designed for large scale network traffic recording and indexing. It functions as a distributed packet indexer that stores raw data in PCAP format for deep packet analysis and security investigations. The system distinguishes itself through a decentralized architecture that distributes capture and viewing components across multiple nodes to handle high volumes of network traffic. It utilizes a web-based management interface for browsing network sessions and provides a programmable API for exporting captured traffic and metad
Moloch is a full packet capture and network forensics platform that records and indexes raw network traffic with a web-based GUI and PCAP export, fitting the packet analysis search even though it lacks explicit real-time analysis and CLI tools.
Scapy is a network packet manipulation tool and protocol analysis suite designed for crafting, sending, sniffing, and dissecting network traffic. It functions as a framework for building custom network tools that interact directly with low-level packet headers and payloads, enabling users to perform security research and network diagnostics. The system distinguishes itself through a layer-based construction model that allows users to define protocols as stacked objects, which automatically handle checksums and field offsets. It utilizes dynamic field reflection to map packet structures to bin
Scapy is a Python-based packet manipulation and analysis suite that lets you capture, dissect, and filter network traffic in real time via its interactive command-line interface, making it a capable packet analyzer; however, it lacks a dedicated graphical user interface and built-in statistics graphs, so it fits the search for a flexible, programmable tool rather than a turnkey GUI application.
PCredz is a network credential extraction tool and traffic analyzer designed to intercept passwords, hashes, and tokens from IPv4 and IPv6 traffic. It functions as both a real-time monitor for live network interfaces and a parser for saved packet capture files. The tool identifies sensitive information, including credit card numbers and authentication tokens, using protocol-aware parsing. It further acts as a password hash recovery utility by normalizing captured authentication hashes into specific syntaxes compatible with external recovery software. Capabilities include real-time traffic in
PCredz captures packets from live interfaces or saved pcap files and performs protocol-aware extraction of credentials, hashes, and tokens, making it a specialized traffic analyzer — it matches the core packet-capture-and-analysis capability, though its focus on credential interception means it does not offer the broader traffic-pattern visualization or GUI you may be looking for.
Dshell is a network forensic analysis framework and traffic processor designed for the deep packet inspection of IPv4 and IPv6 traffic. It functions as an extensible forensic plugin system that captures, inspects, and analyzes network data to identify security anomalies and reconstruct communication streams. The system utilizes a plugin-based processing engine that allows for custom plugin development and plugin chaining. This modular architecture enables the creation of specialized analysis pipelines where network data is passed through a sequence of processing units for multi-step analysis.
Dshell is a network forensic analysis framework that captures and inspects IPv4/IPv6 traffic with deep packet inspection and protocol analysis, fitting the packet analyzer category, though it lacks a graphical user interface and specializes in forensic analysis rather than offering real-time graphs or statistics.
Zeek is a network analysis framework and security monitoring tool that transforms raw network packets into high-level semantic logs. It functions as an application protocol analyzer and network intrusion detection system designed to extract meaning from network traffic and monitor for malicious activity. The system focuses on archiving network activity and maintaining historical records of application-layer state for forensic investigation and auditing. It utilizes a combination of modular protocol analyzers and customizable detection policies to perform deep semantic analysis of numerous app
Zeek is a network analysis framework that captures packets and performs deep protocol dissection and traffic analysis, but it lacks a graphical user interface and is primarily script-driven, so it fits the core packet-analysis intent without covering every listed feature.
Bettercap is a modular framework designed for network reconnaissance, security testing, and the execution of man-in-the-middle attacks. It functions as a comprehensive utility for surveying wired and wireless network segments, identifying connected devices, and analyzing communication protocols through real-time traffic interception and manipulation. The platform distinguishes itself through an event-driven architecture that coordinates network state changes and packet-level data through a centralized message pipeline. It provides a programmable scripting engine and an API for orchestrating s
Bettercap is a modular framework for network reconnaissance and attack that captures packets and analyzes protocols in real-time through its event-driven pipeline and scripting engine, fitting your need for a packet analysis tool despite lacking a graphical interface and built-in statistics.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| gyulyvgc/sniffnet | 39.3K | Rust | Apache-2.0 | |
| wireshark/wireshark | 9.5K | C | GPL-2.0 | |
| arkime/arkime | 7.4K | C | Apache-2.0 | |
| ntop/ntopng | 7.9K | Lua | GPL-3.0 | |
| emanuele-f/pcapdroid | 4.1K | Java | GPL-3.0 | |
| gcla/termshark | 9.9K | Go | MIT | |
| aol/moloch | 7.4K | C | Apache-2.0 | |
| secdev/scapy | 12.1K | Python | gpl-2.0 | |
| lgandx/pcredz | 2.5K | Python | GPL-3.0 | |
| usarmyresearchlab/dshell | 5.5K | Python | NOASSERTION |