awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
ntop avatar

ntop/ntopng

0
View on GitHub↗
7,880 stars·741 forks·Lua·GPL-3.0·46 viewswww.ntop.org↗

Ntopng

ntopng is a web-based network traffic monitoring tool and flow data aggregator. It functions as a network security monitor, an SNMP network management system, and an industrial protocol analyzer for OT and SCADA environments.

The system provides specialized inspection for industrial protocols such as Modbus, DNP3, and IEC 60870. It distinguishes itself through behavioral threat detection, encrypted traffic analysis via handshake fingerprinting, and the ability to identify hardware and operating systems using DHCP and MAC address patterns.

Its broader capabilities include real-time traffic analysis and packet capture, network topology mapping, and the orchestration of tiered collector hierarchies. The platform also manages network access control through captive portals, enforces traffic quotas, and exports flow and alert data to external databases such as ClickHouse, Elasticsearch, and Kafka.

The project supports executing multiple independent monitoring instances on a single host using isolated configurations.

Features

  • Real-Time Network Monitors - Provides real-time observation of live network traffic and bandwidth usage.
  • Network Security Analysis - Detects security threats and anomalies through behavioral analysis, encrypted traffic inspection, and security tool integration.
  • Industrial - Inspects OT and SCADA traffic including Modbus, DNP3, and IEC 60870 for critical infrastructure monitoring.
  • Flow Data Ingestion - Ingests network flow records from multiple routers and observation points to monitor traffic patterns.
  • Flow Tracking Engines - Maintains real-time tables of active network connections to correlate IP and non-IP traffic activity.
  • Network Flow Analyzers - Ingests flow data from remote probes via TCP endpoints to centralize network traffic analysis.
  • Protocol Dissectors - Uses modular dissectors to parse and extract structured data from diverse industrial and network protocols.
  • Packet Capture Engines - Captures raw network traffic using BPF filters to extract flow records and protocol-specific metadata.
  • Traffic Flow Aggregators - Collects and distributes network flow records by grouping individual packets into logical connections.
  • Behavioral Threat Detection - Identifies attackers and anomalies through behavioral analysis and indicators of compromise scores.
  • Device Fingerprinting - Identifies hardware and operating systems by matching DHCP options, HTTP headers, and MAC addresses against known patterns.
  • Network Security Monitors - Detects security threats and anomalies through behavioral analysis and indicators of compromise.
  • Industrial Protocol Inspectors - Inspects OT, ICS, and SCADA traffic including Modbus, DNP3, and IEC 60870 for infrastructure monitoring.
  • Industrial IoT Ingestion - Inspects OT and SCADA protocols like Modbus and DNP3 to monitor critical infrastructure and industrial control systems.
  • Network Traffic Analysis - Reports IP and non-IP traffic generated and received by each host using the network.
  • Network Traffic Analyzers - Provides a web-based analyzer for monitoring real-time network data packets and host communication patterns.
  • SNMP Management - Polls network devices using SNMP to map topology and track interface health.
  • Historical Data Analysis - Retrieves archived network flows and security alerts from historical records for trend analysis.
  • Data Export - Exports flow and alert data to external systems including ClickHouse, Elasticsearch, Kafka, and InfluxDB.
  • Elasticsearch Exporters - Sends network flows and security alerts to an external Elasticsearch index for long-term storage and analysis.
  • Distributed Storage - Distributes network monitoring data across database nodes to ensure high availability and scalable storage.
  • Multi-Backend Data Export - Serializes network flows and security alerts to external time-series and document databases like ClickHouse and Elasticsearch.
  • Network Traffic Export - Sends flow records and security alerts to external databases like Elasticsearch, ClickHouse, or Kafka for long-term storage.
  • Network Statistics APIs - Offers a programmatic interface to retrieve host statistics and active flow time series for performance analysis.
  • Network Connectivity Mapping - Visualizes network device relationships and interface connectivity using SNMP data and LLDP mappings.
  • Packet Capture Utilities - Provides tools for recording raw network traffic to pcap files for offline analysis.
  • Tiered Collector Hierarchies - Organizes remote monitoring instances in a star or tiered topology to forward data to a central collector.
  • Network Access Control - Implements a captive portal and dynamic blacklists to regulate network traffic flow based on identity.
  • Active Network Monitors - Tests network health and latency by sending ICMP, HTTP, and HTTPS requests to hosts and services.
  • Encrypted Traffic Analysis - Inspects TLS and SSH handshakes using fingerprints to identify self-signed certificates and unsafe ciphers.
  • Monitoring Orchestrators - Links remote monitoring instances to a central collector using star or tiered topologies.
  • Network Alerting Systems - Triggers security and performance notifications via email, Slack, Discord, and Webhooks.
  • Performance Metrics APIs - Provides an authenticated REST API to retrieve interface data and network performance metrics for external tools.
  • Network Traffic Dashboards - Creates custom dashboards and plots from exported flow data to visualize network health and security trends.
  • Network Monitoring Tools - Web-based traffic monitoring and analysis.
  • System Monitoring - Web-based network traffic and security monitoring.

Star history

Star history chart for ntop/ntopngStar history chart for ntop/ntopng

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Ntopng

These projects share indexed features with Ntopng. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • gyulyvgc/sniffnetGyulyVGC avatar

    GyulyVGC/sniffnet

    39,325View on GitHub↗

    This application is a desktop network traffic analyzer that provides real-time monitoring and forensic inspection of data packets. By interfacing directly with low-level system drivers, it captures raw network traffic from physical or virtual adapters to identify communication patterns, track bandwidth usage, and diagnose connectivity issues. The system distinguishes itself through an immediate-mode graphical interface that rebuilds the display state every frame, ensuring high responsiveness during live data updates. It maintains performance by using asynchronous message passing to decouple t

    Rustapplicationguiiced
    View on GitHub↗39,325
  • imsnif/bandwhichimsnif avatar

    imsnif/bandwhich

    11,826View on GitHub↗

    bandwhich is a command-line network utility and terminal bandwidth monitor designed for real-time traffic analysis. It functions as a process-based traffic tracker that links network bandwidth usage directly to the system processes and remote hosts responsible for the data transfer. The tool provides a terminal user interface for monitoring active connections and identifying data-consuming applications. It performs background reverse DNS lookups to associate remote IP addresses with human-readable hostnames and tracks cumulative data utilization over the duration of a capture session. Its br

    Rustbandwidthclidashboard
    View on GitHub↗11,826
  • wireshark/wiresharkwireshark avatar

    wireshark/wireshark

    9,477View on GitHub↗

    Wireshark is a network protocol analyzer and traffic inspector used for capturing and inspecting network traffic. It functions as a packet capture tool that intercepts live data from network interfaces and a TCP/IP dissector that decodes network protocol layers to translate raw binary packets into human-readable fields. The system provides capabilities for protocol stream reconstruction, grouping related packets into cohesive conversations between endpoints. It also operates as a packet file converter, allowing for the reading, modification, and conversion of network capture files across vari

    Cpacket-capturestratosharktshark
    View on GitHub↗9,477
  • ntop/ndpintop avatar

    ntop/nDPI

    4,506View on GitHub↗

    nDPI is a deep packet inspection toolkit and network protocol classifier designed to identify protocols and detect security threats through packet payload inspection. It functions as a network security monitor and a traffic analysis framework used to determine the services originating network flows. The system utilizes a modular dissector architecture and a sequence-based dissector chain to interpret network traffic. It supports custom protocol definition and protocol dissector extensions, allowing for the identification of proprietary or new network protocols. The toolkit provides capabilit

    Ccybersecuritydeep-packet-inspectiondpi
    View on GitHub↗4,506
Compare all 30 related projects→

Frequently asked questions

What does ntop/ntopng do?

ntopng is a web-based network traffic monitoring tool and flow data aggregator. It functions as a network security monitor, an SNMP network management system, and an industrial protocol analyzer for OT and SCADA environments.

What are the main features of ntop/ntopng?

The main features of ntop/ntopng are: Real-Time Network Monitors, Network Security Analysis, Industrial, Flow Data Ingestion, Flow Tracking Engines, Network Flow Analyzers, Protocol Dissectors, Packet Capture Engines.

Which projects share features with ntop/ntopng?

Projects with overlapping indexed features include: gyulyvgc/sniffnet — This application is a desktop network traffic analyzer that provides real-time monitoring and forensic inspection of… imsnif/bandwhich — bandwhich is a command-line network utility and terminal bandwidth monitor designed for real-time traffic analysis. It… wireshark/wireshark — Wireshark is a network protocol analyzer and traffic inspector used for capturing and inspecting network traffic. It… oisf/suricata — Suricata is an open-source network intrusion detection and prevention engine that analyzes live network traffic in… ntop/ndpi — nDPI is a deep packet inspection toolkit and network protocol classifier designed to identify protocols and detect… stamparm/maltrail — Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network…