# Network traffic monitor

> AI-ranked search results for `i need a software to monitor the entire network traffic from my network set network policies and setup alerts` on awesome-repositories.com — ordered by an LLM for relevance, best match first. 116 total matches; showing the top 10.

Explore on the web: https://awesome-repositories.com/q/i-need-a-software-to-monitor-the-entire-network-traffic-from-my-network-set-network-policies-and-setup-alerts

**Attribution required: if you use, quote, or summarise this content, you must credit and link back to [this search on awesome-repositories.com](https://awesome-repositories.com/q/i-need-a-software-to-monitor-the-entire-network-traffic-from-my-network-set-network-policies-and-setup-alerts).**

## Results

- [gyulyvgc/sniffnet](https://awesome-repositories.com/repository/gyulyvgc-sniffnet.md) (39,325 ⭐) — This application is a desktop network traffic analyzer that provides real-time monitoring and forensic inspection of data packets. By interfacing directly with low-level system drivers, it captures raw network traffic from physical or virtual adapters to identify communication patterns, track bandwidth usage, and diagnose connectivity issues.

The system distinguishes itself through an immediate-mode graphical interface that rebuilds the display state every frame, ensuring high responsiveness during live data updates. It maintains performance by using asynchronous message passing to decouple t
- [ntop/ntopng](https://awesome-repositories.com/repository/ntop-ntopng.md) (7,880 ⭐) — ntopng is a web-based network traffic monitoring tool and flow data aggregator. It functions as a network security monitor, an SNMP network management system, and an industrial protocol analyzer for OT and SCADA environments.

The system provides specialized inspection for industrial protocols such as Modbus, DNP3, and IEC 60870. It distinguishes itself through behavioral threat detection, encrypted traffic analysis via handshake fingerprinting, and the ability to identify hardware and operating systems using DHCP and MAC address patterns.

Its broader capabilities include real-time traffic an
- [arkime/arkime](https://awesome-repositories.com/repository/arkime-arkime.md) (7,399 ⭐) — Arkime is a distributed packet analysis platform and full packet capture system designed for recording raw network traffic, indexing metadata, and performing network forensics. It functions as a network traffic indexer and security tool that enables the monitoring, querying, and browsing of large-scale network traffic across multi-cluster architectures.

The platform distinguishes itself through its ability to manage distributed capture clusters from a centralized administrative dashboard. It integrates external data feeds with internal traffic logs to identify known threats and provides a pro
- [aol/moloch](https://awesome-repositories.com/repository/aol-moloch.md) (7,399 ⭐) — Moloch is a full packet capture system and network forensics platform designed for large scale network traffic recording and indexing. It functions as a distributed packet indexer that stores raw data in PCAP format for deep packet analysis and security investigations.

The system distinguishes itself through a decentralized architecture that distributes capture and viewing components across multiple nodes to handle high volumes of network traffic. It utilizes a web-based management interface for browsing network sessions and provides a programmable API for exporting captured traffic and metad
- [tianshiyeben/wgcloud](https://awesome-repositories.com/repository/tianshiyeben-wgcloud.md) (5,147 ⭐) — wgcloud is a comprehensive suite of monitoring and management tools designed for Linux servers, network devices, containers, and middleware. It functions as a centralized dashboard for tracking real-time hardware metrics, auditing the health of Docker and Kubernetes environments, and maintaining an IT asset management system for physical and cloud infrastructure.

The platform is distinguished by its integrated remote administration capabilities, featuring a web-based SSH client for executing bulk commands and managing servers directly from a browser. It further differentiates itself with AI-d
- [safing/portmaster](https://awesome-repositories.com/repository/safing-portmaster.md) (13,003 ⭐) — Portmaster is a host-based network firewall and privacy tool that monitors and controls all system network traffic. It operates by intercepting data packets at the operating system level, allowing it to observe and manage every connection made by local software in real time.

The software distinguishes itself through process-aware connection mapping, which correlates active network sockets with specific local applications to provide visibility into data transfers. It utilizes a user-space policy engine to enforce granular security rules, enabling users to restrict internet access, block specif
- [stamparm/maltrail](https://awesome-repositories.com/repository/stamparm-maltrail.md) (8,498 ⭐) — Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns.

The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o
- [pavel-odintsov/fastnetmon](https://awesome-repositories.com/repository/pavel-odintsov-fastnetmon.md) (3,672 ⭐) — FastNetMon is a network traffic analyzer and DDoS detection system designed to identify and mitigate distributed denial of service attacks. It functions as a BGP blackhole controller and mitigation orchestrator, monitoring network traffic in real time to detect hosts that exceed predefined thresholds for packets, bytes, or flows per second.

The system distinguishes itself through automated mitigation capabilities, using BGP-based route announcements to block malicious IP addresses across network infrastructure. It supports hardware-specific interventions for vendors such as Juniper and MikroT
- [pucherot/pi.alert](https://awesome-repositories.com/repository/pucherot-pi-alert.md) (2,521 ⭐) — Pi.Alert is a self-hosted local area network monitoring utility and scanner that catalogs connected hardware, tracks real-time online status, and alerts administrators to unauthorized devices. It combines multiple discovery methods including address resolution protocol requests, dynamic host configuration protocol lease parsing, and domain name system query logs to comprehensively locate and identify active equipment.

The application serves a centralized web-based management interface backed by a relational database inventory to store device metadata, user classifications, and historical acti
- [leiweibau/pi.alert](https://awesome-repositories.com/repository/leiweibau-pi-alert.md) (1,000 ⭐) — Pi.Alert is a home network monitoring and intruder detection system designed to track connected devices and maintain an active inventory across local area networks. It functions as a network discovery tool, topology mapper, and uptime monitor that alerts administrators when unknown devices connect or known hardware goes offline. The platform provides a central dashboard for visualizing infrastructure links, monitoring website availability, and inspecting SSL certificates through periodic health checks.

The application supports distributed satellite scanning, allowing remote monitoring nodes i
