awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
aol avatar

aol/moloch

0
View on GitHub↗
7,399 stars·1,154 forks·C·Apache-2.0·19 viewsarkime.com↗

Moloch

Moloch is a full packet capture system and network forensics platform designed for large scale network traffic recording and indexing. It functions as a distributed packet indexer that stores raw data in PCAP format for deep packet analysis and security investigations.

The system distinguishes itself through a decentralized architecture that distributes capture and viewing components across multiple nodes to handle high volumes of network traffic. It utilizes a web-based management interface for browsing network sessions and provides a programmable API for exporting captured traffic and metadata.

The platform covers several core capability areas, including network metadata indexing for rapid event retrieval, distributed network monitoring, and detailed network traffic forensics. Data access is protected through authentication proxies, API keys, passwords, and encrypted connections.

Features

  • Packet Capture Storage - Provides large-scale capturing of network traffic to disk in PCAP format for long-term storage.
  • Network - Extracts session-level information from packets and stores it in a searchable database.
  • Network Session Indexing - Parses captured packets into a searchable database for rapid retrieval of network events.
  • Search Engine Integrations - Uses Elasticsearch to index and query packet metadata for rapid forensic lookups.
  • Distributed Capture Probes - Distributes traffic collection across multiple remote nodes to handle high volumes of network data.
  • Network Traffic Analyzers - Provides tools for searching and exploring indexed network sessions to investigate security incidents.
  • Packet Capture Engines - Operates as a full-scale system for intercepting raw network traffic and storing it for analysis.
  • Packet Capture Utilities - Records raw network traffic to disk in PCAP format for detailed security analysis.
  • Metadata Indexing - Implements a distributed indexer that extracts and stores session-level metadata for rapid retrieval of network events.
  • Network Monitoring Systems - Provides a distributed platform for monitoring and indexing network traffic across multiple systems.
  • Network Traffic Export - Exports captured network data in PCAP or JSON formats for external analysis.
  • Network Management Interfaces - Provides a web-based interface for browsing network sessions and exporting captured traffic.
  • Traffic Session Browsers - Provides a web interface to search and explore individual network sessions and packet details.
  • Client-Server Architectures - Implements a structural separation between the data-processing backend and a browser-based visualization frontend.
  • Traffic Data Export - Provides programmable interfaces to export captured network traffic and metadata for external analysis.
  • Network Forensics - Large-scale IPv4 packet capture and indexing system.
  • Hunting Tools - Large-scale packet capture and indexing system.
  • Network Analysis - Indexes and stores large-scale IPv4 traffic.
  • Network Security - Large-scale packet capture, indexing, and search system.

Star history

Star history chart for aol/molochStar history chart for aol/moloch

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Moloch

Similar open-source projects, ranked by how many features they share with Moloch.
  • arkime/arkimearkime avatar

    arkime/arkime

    7,399View on GitHub↗

    Arkime is a distributed packet analysis platform and full packet capture system designed for recording raw network traffic, indexing metadata, and performing network forensics. It functions as a network traffic indexer and security tool that enables the monitoring, querying, and browsing of large-scale network traffic across multi-cluster architectures. The platform distinguishes itself through its ability to manage distributed capture clusters from a centralized administrative dashboard. It integrates external data feeds with internal traffic logs to identify known threats and provides a pro

    C
    View on GitHub↗7,399
  • gyulyvgc/sniffnetGyulyVGC avatar

    GyulyVGC/sniffnet

    39,325View on GitHub↗

    This application is a desktop network traffic analyzer that provides real-time monitoring and forensic inspection of data packets. By interfacing directly with low-level system drivers, it captures raw network traffic from physical or virtual adapters to identify communication patterns, track bandwidth usage, and diagnose connectivity issues. The system distinguishes itself through an immediate-mode graphical interface that rebuilds the display state every frame, ensuring high responsiveness during live data updates. It maintains performance by using asynchronous message passing to decouple t

    Rustapplicationguiiced
    View on GitHub↗39,325
  • wireshark/wiresharkwireshark avatar

    wireshark/wireshark

    9,477View on GitHub↗

    Wireshark is a network protocol analyzer and traffic inspector used for capturing and inspecting network traffic. It functions as a packet capture tool that intercepts live data from network interfaces and a TCP/IP dissector that decodes network protocol layers to translate raw binary packets into human-readable fields. The system provides capabilities for protocol stream reconstruction, grouping related packets into cohesive conversations between endpoints. It also operates as a packet file converter, allowing for the reading, modification, and conversion of network capture files across vari

    Cpacket-capturestratosharktshark
    View on GitHub↗9,477
  • emanuele-f/pcapdroidemanuele-f avatar

    emanuele-f/PCAPdroid

    4,133View on GitHub↗

    PCAPdroid is an Android network traffic analyzer and packet capture tool that operates without requiring root access. It functions as a VPN-based firewall and network controller, capable of recording traffic in PCAPng format and blocking connections to specific domains or malicious hosts. The project distinguishes itself through a proxy-based system for decrypting TLS traffic and routing device network traffic through SOCKS5 proxies or the Tor network. It further allows for the modification of live HTTP requests and responses via custom scripts. Its capabilities cover application connection

    Javaandroidcapture-trafficdecryption
    View on GitHub↗4,133
See all 30 alternatives to Moloch→

Frequently asked questions

What does aol/moloch do?

Moloch is a full packet capture system and network forensics platform designed for large scale network traffic recording and indexing. It functions as a distributed packet indexer that stores raw data in PCAP format for deep packet analysis and security investigations.

What are the main features of aol/moloch?

The main features of aol/moloch are: Packet Capture Storage, Network, Network Session Indexing, Search Engine Integrations, Distributed Capture Probes, Network Traffic Analyzers, Packet Capture Engines, Packet Capture Utilities.

What are some open-source alternatives to aol/moloch?

Open-source alternatives to aol/moloch include: arkime/arkime — Arkime is a distributed packet analysis platform and full packet capture system designed for recording raw network… gyulyvgc/sniffnet — This application is a desktop network traffic analyzer that provides real-time monitoring and forensic inspection of… wireshark/wireshark — Wireshark is a network protocol analyzer and traffic inspector used for capturing and inspecting network traffic. It… emanuele-f/pcapdroid — PCAPdroid is an Android network traffic analyzer and packet capture tool that operates without requiring root access.… ntop/ntopng — ntopng is a web-based network traffic monitoring tool and flow data aggregator. It functions as a network security… gcla/termshark — Termshark is a terminal-based network packet analyzer and protocol flow inspector. It serves as a keyboard-driven…