awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Network traffic monitor

Ranking updated Jul 30, 2026

For i need a software to monitor the entire network traffic from my network set network policies and setup alerts, the strongest matches are gyulyvgc/sniffnet (Sniffnet is a desktop network traffic analyzer that provides), ntop/ntopng (ntopng is a self-hostable web-based network traffic monitoring tool) and arkime/arkime (Arkime is a distributed full packet capture system and). aol/moloch and tianshiyeben/wgcloud round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

Hand-picked open-source network traffic monitors for setting policies and alerts. Compare the top tools and find the right fit.

Network traffic monitor

Find the best repos with AI.We'll search the best matching repositories with AI.
  • gyulyvgc/sniffnetGyulyVGC avatar

    GyulyVGC/sniffnet

    39,325View on GitHub↗

    This application is a desktop network traffic analyzer that provides real-time monitoring and forensic inspection of data packets. By interfacing directly with low-level system drivers, it captures raw network traffic from physical or virtual adapters to identify communication patterns, track bandwidth usage, and diagnose connectivity issues. The system distinguishes itself through an immediate-mode graphical interface that rebuilds the display state every frame, ensuring high responsiveness during live data updates. It maintains performance by using asynchronous message passing to decouple t

    Sniffnet is a desktop network traffic analyzer that provides real-time packet capture, bandwidth monitoring, and alert management, though it functions as a local GUI application rather than a centralized, self-hosted server tool for policy enforcement.

    RustPacket Capture EnginesPacket InspectionPacket Capture Utilities
    View on GitHub↗39,325
  • ntop/ntopngntop avatar

    ntop/ntopng

    7,880View on GitHub↗

    ntopng is a web-based network traffic monitoring tool and flow data aggregator. It functions as a network security monitor, an SNMP network management system, and an industrial protocol analyzer for OT and SCADA environments. The system provides specialized inspection for industrial protocols such as Modbus, DNP3, and IEC 60870. It distinguishes itself through behavioral threat detection, encrypted traffic analysis via handshake fingerprinting, and the ability to identify hardware and operating systems using DHCP and MAC address patterns. Its broader capabilities include real-time traffic an

    ntopng is a self-hostable web-based network traffic monitoring tool that offers flow visualization, metrics, and network alerting systems, though it focuses more on traffic analysis and protocol inspection than strict policy enforcement.

    LuaNetwork Alerting SystemsNetwork Traffic DashboardsPacket Capture Engines
    View on GitHub↗7,880
  • arkime/arkimearkime avatar

    arkime/arkime

    7,399View on GitHub↗

    Arkime is a distributed packet analysis platform and full packet capture system designed for recording raw network traffic, indexing metadata, and performing network forensics. It functions as a network traffic indexer and security tool that enables the monitoring, querying, and browsing of large-scale network traffic across multi-cluster architectures. The platform distinguishes itself through its ability to manage distributed capture clusters from a centralized administrative dashboard. It integrates external data feeds with internal traffic logs to identify known threats and provides a pro

    Arkime is a distributed full packet capture system and network traffic indexer that provides deep packet analysis and monitoring capabilities, though it lacks dedicated network policy enforcement features.

    CPacket Capture EnginesPacket Capture UtilitiesPacket Capture Utilities
    View on GitHub↗7,399
  • aol/molochaol avatar

    aol/moloch

    7,399View on GitHub↗

    Moloch is a full packet capture system and network forensics platform designed for large scale network traffic recording and indexing. It functions as a distributed packet indexer that stores raw data in PCAP format for deep packet analysis and security investigations. The system distinguishes itself through a decentralized architecture that distributes capture and viewing components across multiple nodes to handle high volumes of network traffic. It utilizes a web-based management interface for browsing network sessions and provides a programmable API for exporting captured traffic and metad

    Moloch is a distributed packet capture and forensics platform that provides deep traffic analysis and session browsing, though it lacks built-in network policy enforcement and automated alerting features.

    CPacket Capture EnginesPacket Capture Utilities
    View on GitHub↗7,399
  • tianshiyeben/wgcloudtianshiyeben avatar

    tianshiyeben/wgcloud

    5,147View on GitHub↗

    wgcloud is a comprehensive suite of monitoring and management tools designed for Linux servers, network devices, containers, and middleware. It functions as a centralized dashboard for tracking real-time hardware metrics, auditing the health of Docker and Kubernetes environments, and maintaining an IT asset management system for physical and cloud infrastructure. The platform is distinguished by its integrated remote administration capabilities, featuring a web-based SSH client for executing bulk commands and managing servers directly from a browser. It further differentiates itself with AI-d

    This Java-based infrastructure monitoring tool offers real-time dashboards, device discovery, and multi-channel alerting, though it focuses more on server health and asset management than deep packet capture and traffic analysis.

    JavaAlerting SystemsAlert Thresholds
    View on GitHub↗5,147
  • safing/portmastersafing avatar

    safing/portmaster

    13,003View on GitHub↗

    Portmaster is a host-based network firewall and privacy tool that monitors and controls all system network traffic. It operates by intercepting data packets at the operating system level, allowing it to observe and manage every connection made by local software in real time. The software distinguishes itself through process-aware connection mapping, which correlates active network sockets with specific local applications to provide visibility into data transfers. It utilizes a user-space policy engine to enforce granular security rules, enabling users to restrict internet access, block specif

    Portmaster is a host-based network firewall and traffic monitor that inspects connections and enforces granular rules, making it a strong tool for local network control though it focuses more on host endpoints than comprehensive enterprise flow visualization.

    GoReal-Time Network Monitors
    View on GitHub↗13,003
  • stamparm/maltrailstamparm avatar

    stamparm/maltrail

    8,498View on GitHub↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Maltrail is a network traffic analysis and intrusion detection system featuring sensor-based monitoring and threat dashboards, though it focuses more on malicious traffic detection than general network policy enforcement.

    PythonPacket Capture Filters
    View on GitHub↗8,498
  • pavel-odintsov/fastnetmonpavel-odintsov avatar

    pavel-odintsov/fastnetmon

    3,672View on GitHub↗

    FastNetMon is a network traffic analyzer and DDoS detection system designed to identify and mitigate distributed denial of service attacks. It functions as a BGP blackhole controller and mitigation orchestrator, monitoring network traffic in real time to detect hosts that exceed predefined thresholds for packets, bytes, or flows per second. The system distinguishes itself through automated mitigation capabilities, using BGP-based route announcements to block malicious IP addresses across network infrastructure. It supports hardware-specific interventions for vendors such as Juniper and MikroT

    FastNetMon is a high-performance network traffic analyzer and DDoS detection system that captures packets and flows, provides metric-based analysis, and triggers automated mitigations, though it focuses more on security and DDoS defense rather than comprehensive general-purpose network policy enforcement and visualization.

    C++DDoS Attack DetectionsDDoS ProtectionsBGP Blackhole Controllers
    View on GitHub↗3,672
  • pucherot/pi.alertpucherot avatar

    pucherot/Pi.Alert

    2,521View on GitHub↗

    Pi.Alert is a self-hosted local area network monitoring utility and scanner that catalogs connected hardware, tracks real-time online status, and alerts administrators to unauthorized devices. It combines multiple discovery methods including address resolution protocol requests, dynamic host configuration protocol lease parsing, and domain name system query logs to comprehensively locate and identify active equipment. The application serves a centralized web-based management interface backed by a relational database inventory to store device metadata, user classifications, and historical acti

    Pi.Alert is a self-hostable network monitoring tool that scans connected Wi-Fi and LAN devices to provide alerts for unknown or disconnected devices, though it focuses more on intrusion detection than deep traffic analysis and policy enforcement.

    JavaScriptNetwork Alerting Systems
    View on GitHub↗2,521
  • leiweibau/pi.alertleiweibau avatar

    leiweibau/Pi.Alert

    1,000View on GitHub↗

    Pi.Alert is a home network monitoring and intruder detection system designed to track connected devices and maintain an active inventory across local area networks. It functions as a network discovery tool, topology mapper, and uptime monitor that alerts administrators when unknown devices connect or known hardware goes offline. The platform provides a central dashboard for visualizing infrastructure links, monitoring website availability, and inspecting SSL certificates through periodic health checks. The application supports distributed satellite scanning, allowing remote monitoring nodes i

    Pi.alert is a self-hostable network monitoring tool that tracks connected devices and scans for security issues, though it is more focused on device inventory and alerts than deep packet capture or policy enforcement.

    PHPHome Network MonitorsDevice Profile ConfigurationsEndpoint Authentication
    View on GitHub↗1,000

Related searches

  • an open source network monitoring tool
  • Network traffic analyzer
  • an open source firewall for network security
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
gyulyvgc/sniffnet39.3KRustApache-2.0Jun 14, 2026
ntop/ntopng7.9KLuaGPL-3.0Jun 16, 2026
arkime/arkime7.4KCApache-2.0Jun 16, 2026
aol/moloch7.4KCApache-2.0Jun 16, 2026
tianshiyeben/wgcloud5.1KJavaApache-2.0May 31, 2026
safing/portmaster13KGoGPL-3.0Jun 16, 2026
stamparm/maltrail8.5KPythonMITJun 16, 2026
pavel-odintsov/fastnetmon3.7KC++GPL-2.0Jun 17, 2026
pucherot/pi.alert2.5KJavaScriptGPL-3.0Feb 8, 2024
leiweibau/pi.alert1KPHPgpl-3.0Feb 19, 2026
  • a tool for capturing and analyzing network traffic
  • an open source tool for network security
  • an open source network monitoring tool
  • an intrusion detection system
  • Network Security and Analysis