For network traffic analyzers, the strongest matches are ntop/ntopng (ntopng is a comprehensive network traffic analyzer that provides), gcla/termshark (Termshark provides a terminal-based interface for real-time packet capture) and wireshark/wireshark (Wireshark is the industry-standard network protocol analyzer that provides). aol/moloch and arkime/arkime round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Explore the best open-source network traffic analyzers. Compare top tools ranked by activity and features to find the best fit for your stack.
ntopng is a web-based network traffic monitoring tool and flow data aggregator. It functions as a network security monitor, an SNMP network management system, and an industrial protocol analyzer for OT and SCADA environments. The system provides specialized inspection for industrial protocols such as Modbus, DNP3, and IEC 60870. It distinguishes itself through behavioral threat detection, encrypted traffic analysis via handshake fingerprinting, and the ability to identify hardware and operating systems using DHCP and MAC address patterns. Its broader capabilities include real-time traffic an
ntopng is a comprehensive network traffic analyzer that provides real-time monitoring, flow-based analysis, protocol inspection, and alerting, making it a flagship tool for network visibility and security troubleshooting.
Termshark is a terminal-based network packet analyzer and protocol flow inspector. It serves as a keyboard-driven interface for the tshark command-line utility, providing a terminal user interface to monitor data flow and analyze network traffic. The tool functions as a terminal interface for Wireshark, utilizing its filtering and inspection logic to analyze recorded capture files or live network interfaces. It specifically enables the reassembly and inspection of TCP and UDP flows to isolate traffic patterns and analyze network conversations by protocol. The system includes capabilities for
Termshark provides a terminal-based interface for real-time packet capture, protocol analysis, and flow inspection, making it a capable tool for network troubleshooting and traffic monitoring.
Wireshark is a network protocol analyzer and traffic inspector used for capturing and inspecting network traffic. It functions as a packet capture tool that intercepts live data from network interfaces and a TCP/IP dissector that decodes network protocol layers to translate raw binary packets into human-readable fields. The system provides capabilities for protocol stream reconstruction, grouping related packets into cohesive conversations between endpoints. It also operates as a packet file converter, allowing for the reading, modification, and conversion of network capture files across vari
Wireshark is the industry-standard network protocol analyzer that provides deep packet inspection, real-time monitoring, and comprehensive protocol analysis, making it a flagship tool for network troubleshooting and security forensics.
Moloch is a full packet capture system and network forensics platform designed for large scale network traffic recording and indexing. It functions as a distributed packet indexer that stores raw data in PCAP format for deep packet analysis and security investigations. The system distinguishes itself through a decentralized architecture that distributes capture and viewing components across multiple nodes to handle high volumes of network traffic. It utilizes a web-based management interface for browsing network sessions and provides a programmable API for exporting captured traffic and metad
Moloch is a comprehensive network forensics and packet capture platform that provides the deep packet analysis, indexing, and visualization required for large-scale traffic monitoring and security investigations.
Arkime is a distributed packet analysis platform and full packet capture system designed for recording raw network traffic, indexing metadata, and performing network forensics. It functions as a network traffic indexer and security tool that enables the monitoring, querying, and browsing of large-scale network traffic across multi-cluster architectures. The platform distinguishes itself through its ability to manage distributed capture clusters from a centralized administrative dashboard. It integrates external data feeds with internal traffic logs to identify known threats and provides a pro
Arkime is a comprehensive, distributed packet capture and analysis platform that provides the full suite of required features, including raw traffic recording, protocol indexing, and visualization for network forensics and security monitoring.
Zeek is a network analysis framework and security monitoring tool that transforms raw network packets into high-level semantic logs. It functions as an application protocol analyzer and network intrusion detection system designed to extract meaning from network traffic and monitor for malicious activity. The system focuses on archiving network activity and maintaining historical records of application-layer state for forensic investigation and auditing. It utilizes a combination of modular protocol analyzers and customizable detection policies to perform deep semantic analysis of numerous app
Zeek is a powerful network analysis framework that performs deep packet inspection and protocol analysis to generate high-level logs, making it a comprehensive tool for monitoring and security auditing.
This application is a desktop network traffic analyzer that provides real-time monitoring and forensic inspection of data packets. By interfacing directly with low-level system drivers, it captures raw network traffic from physical or virtual adapters to identify communication patterns, track bandwidth usage, and diagnose connectivity issues. The system distinguishes itself through an immediate-mode graphical interface that rebuilds the display state every frame, ensuring high responsiveness during live data updates. It maintains performance by using asynchronous message passing to decouple t
This application provides real-time network monitoring, packet capture, and traffic visualization, making it a capable tool for diagnosing connectivity and analyzing network patterns.
httptap is a network utility for intercepting system-level packets and monitoring the HTTP and HTTPS traffic of Linux processes. It functions as a network packet sniffer and traffic monitor designed to capture and display real-time requests and responses sent by local applications. The project includes a local traffic redirector that maps remote hostnames or IP addresses to localhost for service testing. To support detailed inspection, it features a TLS termination proxy for decrypting HTTPS traffic and a HAR file exporter that dumps captured data into the standard HTTP Archive format for ext
This tool functions as a specialized network traffic analyzer focused on intercepting and inspecting HTTP/HTTPS traffic at the process level, providing real-time monitoring and packet capture capabilities suitable for debugging local application communication.
bandwhich is a command-line network utility and terminal bandwidth monitor designed for real-time traffic analysis. It functions as a process-based traffic tracker that links network bandwidth usage directly to the system processes and remote hosts responsible for the data transfer. The tool provides a terminal user interface for monitoring active connections and identifying data-consuming applications. It performs background reverse DNS lookups to associate remote IP addresses with human-readable hostnames and tracks cumulative data utilization over the duration of a capture session. Its br
This tool provides real-time monitoring and process-based traffic analysis, serving as a specialized network utility that helps identify bandwidth-consuming applications and connections.
Dshell is a network forensic analysis framework and traffic processor designed for the deep packet inspection of IPv4 and IPv6 traffic. It functions as an extensible forensic plugin system that captures, inspects, and analyzes network data to identify security anomalies and reconstruct communication streams. The system utilizes a plugin-based processing engine that allows for custom plugin development and plugin chaining. This modular architecture enables the creation of specialized analysis pipelines where network data is passed through a sequence of processing units for multi-step analysis.
Dshell is a network forensic analysis framework that provides deep packet inspection and traffic processing capabilities, making it a specialized tool for analyzing and reconstructing network communication streams.
Kubeshark is a network observability platform designed for Kubernetes environments, functioning as an eBPF-powered engine for cluster-wide traffic analysis. It captures, indexes, and visualizes network activity and API calls directly from the kernel, providing deep visibility into service-to-service communication without requiring sidecar proxies or manual code instrumentation. The platform distinguishes itself through its ability to perform protocol-aware traffic dissection and user-space cryptographic hooking, which allows for the inspection of encrypted traffic and the reconstruction of ap
Kubeshark is a specialized network traffic analyzer tailored for Kubernetes environments that provides packet capture, protocol dissection, and real-time visualization of service-to-service communication.
PCAPdroid is an Android network traffic analyzer and packet capture tool that operates without requiring root access. It functions as a VPN-based firewall and network controller, capable of recording traffic in PCAPng format and blocking connections to specific domains or malicious hosts. The project distinguishes itself through a proxy-based system for decrypting TLS traffic and routing device network traffic through SOCKS5 proxies or the Tor network. It further allows for the modification of live HTTP requests and responses via custom scripts. Its capabilities cover application connection
PCAPdroid is a specialized network traffic analyzer for Android that provides packet capture, real-time monitoring, and traffic visualization directly on mobile devices without requiring root access.
Kyanos is a diagnostic toolset for network analysis that uses eBPF to measure packet latency and trace traffic from the network card to the application. It functions as a kernel latency profiler and network performance monitor, providing capabilities to map external dependencies and capture network traffic. The project is distinguished by its ability to perform automatic SSL traffic decryption, converting encrypted requests and responses into plaintext for analysis. It further isolates bottlenecks by attributing latency across multiple stages, specifically tracing the time packets spend withi
Kyanos is a specialized network diagnostic tool that uses eBPF to capture, trace, and analyze traffic, providing the core packet capture and performance monitoring capabilities required for troubleshooting.
FastNetMon is a network traffic analyzer and DDoS detection system designed to identify and mitigate distributed denial of service attacks. It functions as a BGP blackhole controller and mitigation orchestrator, monitoring network traffic in real time to detect hosts that exceed predefined thresholds for packets, bytes, or flows per second. The system distinguishes itself through automated mitigation capabilities, using BGP-based route announcements to block malicious IP addresses across network infrastructure. It supports hardware-specific interventions for vendors such as Juniper and MikroT
FastNetMon is a specialized network traffic analyzer focused on real-time flow monitoring and DDoS detection, providing the core capabilities of traffic analysis and alerting even though its primary design goal is automated mitigation rather than general-purpose packet inspection.
Suricata is an open-source network intrusion detection and prevention engine that analyzes live network traffic in real-time to identify and alert on malicious activity. It operates as a rule-based threat detection system, matching traffic against user-defined signatures to detect known attack patterns and policy violations, and can be placed inline to actively block malicious packets before they reach their target. The engine inspects a wide range of application-layer protocols including HTTP, DNS, TLS, SMB, and MQTT, and supports high-performance packet capture through specialized hardware a
Suricata is a high-performance network intrusion detection and prevention engine that provides real-time traffic monitoring, protocol analysis, and packet capture, making it a powerful tool for security-focused network analysis.
Mitmproxy is an interactive, programmable network proxy engine designed for traffic analysis and protocol manipulation. It functions as a gateway that intercepts, inspects, and modifies network traffic in real-time, supporting HTTP, HTTPS, WebSocket, DNS, and generic TCP or UDP streams. By acting as a trusted certificate authority, the proxy can dynamically generate and sign certificates to decrypt and analyze secure TLS-encrypted connections. The project distinguishes itself through a highly extensible, event-driven architecture that allows users to automate traffic transformation using cust
Mitmproxy is a powerful interactive proxy that excels at real-time inspection, protocol analysis, and traffic manipulation, making it a highly effective tool for troubleshooting and security analysis despite its focus on proxy-based interception rather than passive packet sniffing.
Proxypin is a cross-platform HTTP and HTTPS proxy debugger designed to capture, inspect, and modify network traffic. It functions as a man-in-the-middle interceptor, allowing developers to analyze application data flows and validate network communication during development and testing. The tool distinguishes itself through its focus on mobile and remote device integration, utilizing QR-code-based configuration synchronization to simplify the setup of proxy settings and security certificates. It includes an event-driven scripting engine that enables programmatic manipulation of requests and re
This tool functions as a proxy-based debugger for inspecting and modifying HTTP/HTTPS traffic, which aligns with the core requirements for capturing and analyzing application-level network communication.
Pcap-Analyzer is a desktop utility designed for the forensic analysis of offline packet capture files. It functions by decoding binary network protocols into structured metadata, allowing users to examine network activity without requiring a live connection. The tool provides comprehensive capabilities for reconstructing communication sessions and extracting application-layer artifacts, such as transmitted files and credentials. It distinguishes itself through integrated geospatial mapping, which correlates source and destination network addresses with physical location databases to visualize
This tool provides visualization and analysis for offline packet capture files, serving as a focused utility for inspecting network traffic data.
Mizu is a suite of tools for capturing, indexing, and visualizing cloud-native network traffic and decrypted payloads for cluster-wide diagnostics. It provides Kubernetes network observability by using eBPF to index and visualize layer 4 and layer 7 traffic with full cluster context, allowing for the mapping of workload dependencies and the diagnosis of network failures. The project distinguishes itself by using kernel-level hooks to decrypt TLS traffic in plain text without requiring private keys. It further integrates a standardized context protocol to expose indexed network telemetry to AI
Mizu is a specialized network traffic analyzer designed specifically for Kubernetes environments, providing packet capture, protocol analysis, and visualization through eBPF-based observability.
| Repository | Stele | Limbaj | Licență | Ultimul push |
|---|---|---|---|---|
| ntop/ntopng | 7.9K | Lua | GPL-3.0 | |
| gcla/termshark | 9.9K | Go | MIT | |
| wireshark/wireshark | 9.5K | C | GPL-2.0 | |
| aol/moloch | 7.4K | C | Apache-2.0 | |
| arkime/arkime | 7.4K | C | Apache-2.0 | |
| zeek/zeek | 7.7K | C++ | NOASSERTION | |
| gyulyvgc/sniffnet | 39.3K | Rust | Apache-2.0 | |
| monasticacademy/httptap | 4.2K | Go | MIT | |
| imsnif/bandwhich | 11.8K | Rust | MIT | |
| usarmyresearchlab/dshell | 5.5K | Python | NOASSERTION |