awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
arkime avatar

arkime/arkime

0
View on GitHub↗
7,399 stars·1,154 forks·C·Apache-2.0·35 viewsarkime.com↗

Arkime

Arkime is a distributed packet analysis platform and full packet capture system designed for recording raw network traffic, indexing metadata, and performing network forensics. It functions as a network traffic indexer and security tool that enables the monitoring, querying, and browsing of large-scale network traffic across multi-cluster architectures.

The platform distinguishes itself through its ability to manage distributed capture clusters from a centralized administrative dashboard. It integrates external data feeds with internal traffic logs to identify known threats and provides a programmatic interface for exporting raw traffic streams and session metadata to external analysis software.

The system covers broad capability areas including network security monitoring, multi-cluster health observability, and traffic data search. It incorporates role-based access control to protect sensitive packet data and provides a web-based interface for packet capture browsing and forensic investigation.

Features

  • Packet Capture Storage - Records raw network traffic across multiple nodes and stores the data in local packet files.
  • Network Forensics - Provides a web-based interface for querying indexed data and analyzing full network packets.
  • Network Session Indexing - Indexes network session metadata to enable rapid retrieval and analysis of specific communication events.
  • Network Traffic Queries - Enables querying indexed packet data to identify patterns or anomalies within large-scale network captures.
  • Distributed Capture Probes - Manages a distributed architecture of remote network sensors that forward traffic data to a central server.
  • Full Packet Capture Systems - Provides a complete system for recording raw network packets, indexing metadata, and storing traffic for forensics.
  • Packet Capture Utilities - Provides a web interface for browsing recorded raw network traffic and exporting data for external forensic analysis.
  • Packet Capture Engines - Implements a high-performance engine for intercepting and recording raw network traffic.
  • Packet Capture Utilities - Records and stores full raw network traffic for deep security analysis and detailed forensic investigations.
  • Metadata Indexing - Extracts session metadata from raw packets into searchable indexes for fast querying of large traffic volumes.
  • Role-Based Access Control - Restricts access to sensitive packet data and system configurations using role-based permissions.
  • Cluster Health Monitoring - Features a centralized health dashboard to track node connectivity and performance across distributed capture points.
  • Distributed Packet Analysis Platforms - Ships a multi-cluster architecture for centralized monitoring, querying, and browsing of large-scale network traffic.
  • Indicator Feed Ingestion - Integrates high-fidelity indicator feeds with internal logs to identify known network threats.
  • Traffic Stream APIs - Provides a programmatic interface to stream raw capture files and session metadata to third-party analysis software.
  • System Access Restrictions - Implements technical controls using passwords, API keys, and proxies to restrict unauthorized system access.
  • Dashboard Access Controls - Restricts the ability to modify system configurations and manage settings based on assigned user roles.
  • Interface Access Security - Protects captured packet data and management interfaces via API keys, passwords, and authentication proxies.
  • Session Metadata Exports - Allows downloading packet captures and session data in structured formats for external security tool integration.
  • Traffic Data Export - Provides utilities for saving and interoperating network capture data via programmatic interfaces.
  • Network Monitoring Tools - Large-scale full packet capture and search tool.
  • Network Security Monitoring - Stores and indexes network traffic for fast forensic access.

Star history

Star history chart for arkime/arkimeStar history chart for arkime/arkime

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Arkime

These projects share indexed features with Arkime. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • aol/molochaol avatar

    aol/moloch

    7,399View on GitHub↗

    Moloch is a full packet capture system and network forensics platform designed for large scale network traffic recording and indexing. It functions as a distributed packet indexer that stores raw data in PCAP format for deep packet analysis and security investigations. The system distinguishes itself through a decentralized architecture that distributes capture and viewing components across multiple nodes to handle high volumes of network traffic. It utilizes a web-based management interface for browsing network sessions and provides a programmable API for exporting captured traffic and metad

    C
    View on GitHub↗7,399
  • emanuele-f/pcapdroidemanuele-f avatar

    emanuele-f/PCAPdroid

    4,133View on GitHub↗

    PCAPdroid is an Android network traffic analyzer and packet capture tool that operates without requiring root access. It functions as a VPN-based firewall and network controller, capable of recording traffic in PCAPng format and blocking connections to specific domains or malicious hosts. The project distinguishes itself through a proxy-based system for decrypting TLS traffic and routing device network traffic through SOCKS5 proxies or the Tor network. It further allows for the modification of live HTTP requests and responses via custom scripts. Its capabilities cover application connection

    Javaandroidcapture-trafficdecryption
    View on GitHub↗4,133
  • ntop/ntopngntop avatar

    ntop/ntopng

    7,880View on GitHub↗

    ntopng is a web-based network traffic monitoring tool and flow data aggregator. It functions as a network security monitor, an SNMP network management system, and an industrial protocol analyzer for OT and SCADA environments. The system provides specialized inspection for industrial protocols such as Modbus, DNP3, and IEC 60870. It distinguishes itself through behavioral threat detection, encrypted traffic analysis via handshake fingerprinting, and the ability to identify hardware and operating systems using DHCP and MAC address patterns. Its broader capabilities include real-time traffic an

    Lua
    View on GitHub↗7,880
  • google/stenographergoogle avatar

    google/stenographer

    1,796View on GitHub↗

    Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. Discussion/announcements at stenographer@googlegroups.com

    Go
    View on GitHub↗1,796
Compare all 30 related projects→

Frequently asked questions

What does arkime/arkime do?

Arkime is a distributed packet analysis platform and full packet capture system designed for recording raw network traffic, indexing metadata, and performing network forensics. It functions as a network traffic indexer and security tool that enables the monitoring, querying, and browsing of large-scale network traffic across multi-cluster architectures.

What are the main features of arkime/arkime?

The main features of arkime/arkime are: Packet Capture Storage, Network Forensics, Network Session Indexing, Network Traffic Queries, Distributed Capture Probes, Full Packet Capture Systems, Packet Capture Utilities, Packet Capture Engines.

Which projects share features with arkime/arkime?

Projects with overlapping indexed features include: aol/moloch — Moloch is a full packet capture system and network forensics platform designed for large scale network traffic… emanuele-f/pcapdroid — PCAPdroid is an Android network traffic analyzer and packet capture tool that operates without requiring root access.… ntop/ntopng — ntopng is a web-based network traffic monitoring tool and flow data aggregator. It functions as a network security… google/stenographer — Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast… vendurehq/vendure — Vendure is a Node.js e-commerce engine and headless commerce framework built with NestJS and TypeScript. It serves as… gyulyvgc/sniffnet — This application is a desktop network traffic analyzer that provides real-time monitoring and forensic inspection of…