awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
aol avatar

aol/moloch

0
View on GitHub↗
7,399 星标·1,154 分支·C·Apache-2.0·9 次浏览arkime.com↗

Moloch

Moloch is a full packet capture system and network forensics platform designed for large scale network traffic recording and indexing. It functions as a distributed packet indexer that stores raw data in PCAP format for deep packet analysis and security investigations.

The system distinguishes itself through a decentralized architecture that distributes capture and viewing components across multiple nodes to handle high volumes of network traffic. It utilizes a web-based management interface for browsing network sessions and provides a programmable API for exporting captured traffic and metadata.

The platform covers several core capability areas, including network metadata indexing for rapid event retrieval, distributed network monitoring, and detailed network traffic forensics. Data access is protected through authentication proxies, API keys, passwords, and encrypted connections.

Features

  • Packet Capture Storage - Provides large-scale capturing of network traffic to disk in PCAP format for long-term storage.
  • Network - Extracts session-level information from packets and stores it in a searchable database.
  • Network Session Indexing - Parses captured packets into a searchable database for rapid retrieval of network events.
  • Search Engine Integrations - Uses Elasticsearch to index and query packet metadata for rapid forensic lookups.
  • Distributed Capture Probes - Distributes traffic collection across multiple remote nodes to handle high volumes of network data.
  • Network Traffic Analyzers - Provides tools for searching and exploring indexed network sessions to investigate security incidents.
  • Packet Capture Engines - Operates as a full-scale system for intercepting raw network traffic and storing it for analysis.
  • Packet Capture Utilities - Records raw network traffic to disk in PCAP format for detailed security analysis.
  • Metadata Indexing - Implements a distributed indexer that extracts and stores session-level metadata for rapid retrieval of network events.
  • Network Monitoring Systems - Provides a distributed platform for monitoring and indexing network traffic across multiple systems.
  • Network Traffic Export - Exports captured network data in PCAP or JSON formats for external analysis.
  • Network Management Interfaces - Provides a web-based interface for browsing network sessions and exporting captured traffic.
  • Traffic Session Browsers - Provides a web interface to search and explore individual network sessions and packet details.
  • Client-Server Architectures - Implements a structural separation between the data-processing backend and a browser-based visualization frontend.
  • Traffic Data Export - Provides programmable interfaces to export captured network traffic and metadata for external analysis.
  • Network Forensics - Large-scale IPv4 packet capture and indexing system.
  • Hunting Tools - Large-scale packet capture and indexing system.
  • Network Analysis - Indexes and stores large-scale IPv4 traffic.
  • Network Security - Large-scale packet capture, indexing, and search system.

Star 历史

aol/moloch 的 Star 历史图表aol/moloch 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

Moloch 的开源替代方案

相似的开源项目,按与 Moloch 的功能重合度排序。
  • arkime/arkimearkime 的头像

    arkime/arkime

    7,399在 GitHub 上查看↗

    Arkime is a distributed packet analysis platform and full packet capture system designed for recording raw network traffic, indexing metadata, and performing network forensics. It functions as a network traffic indexer and security tool that enables the monitoring, querying, and browsing of large-scale network traffic across multi-cluster architectures. The platform distinguishes itself through its ability to manage distributed capture clusters from a centralized administrative dashboard. It integrates external data feeds with internal traffic logs to identify known threats and provides a pro

    C
    在 GitHub 上查看↗7,399
  • gyulyvgc/sniffnetGyulyVGC 的头像

    GyulyVGC/sniffnet

    39,325在 GitHub 上查看↗

    This application is a desktop network traffic analyzer that provides real-time monitoring and forensic inspection of data packets. By interfacing directly with low-level system drivers, it captures raw network traffic from physical or virtual adapters to identify communication patterns, track bandwidth usage, and diagnose connectivity issues. The system distinguishes itself through an immediate-mode graphical interface that rebuilds the display state every frame, ensuring high responsiveness during live data updates. It maintains performance by using asynchronous message passing to decouple t

    Rustapplicationguiiced
    在 GitHub 上查看↗39,325
  • wireshark/wiresharkwireshark 的头像

    wireshark/wireshark

    9,477在 GitHub 上查看↗

    Wireshark is a network protocol analyzer and traffic inspector used for capturing and inspecting network traffic. It functions as a packet capture tool that intercepts live data from network interfaces and a TCP/IP dissector that decodes network protocol layers to translate raw binary packets into human-readable fields. The system provides capabilities for protocol stream reconstruction, grouping related packets into cohesive conversations between endpoints. It also operates as a packet file converter, allowing for the reading, modification, and conversion of network capture files across vari

    Cpacket-capturestratosharktshark
    在 GitHub 上查看↗9,477
  • emanuele-f/pcapdroidemanuele-f 的头像

    emanuele-f/PCAPdroid

    4,133在 GitHub 上查看↗

    PCAPdroid is an Android network traffic analyzer and packet capture tool that operates without requiring root access. It functions as a VPN-based firewall and network controller, capable of recording traffic in PCAPng format and blocking connections to specific domains or malicious hosts. The project distinguishes itself through a proxy-based system for decrypting TLS traffic and routing device network traffic through SOCKS5 proxies or the Tor network. It further allows for the modification of live HTTP requests and responses via custom scripts. Its capabilities cover application connection

    Javaandroidcapture-trafficdecryption
    在 GitHub 上查看↗4,133
查看 Moloch 的所有 30 个替代方案→

常见问题解答

aol/moloch 是做什么的?

Moloch is a full packet capture system and network forensics platform designed for large scale network traffic recording and indexing. It functions as a distributed packet indexer that stores raw data in PCAP format for deep packet analysis and security investigations.

aol/moloch 的主要功能有哪些?

aol/moloch 的主要功能包括:Packet Capture Storage, Network, Network Session Indexing, Search Engine Integrations, Distributed Capture Probes, Network Traffic Analyzers, Packet Capture Engines, Packet Capture Utilities。

aol/moloch 有哪些开源替代品?

aol/moloch 的开源替代品包括: arkime/arkime — Arkime is a distributed packet analysis platform and full packet capture system designed for recording raw network… gyulyvgc/sniffnet — This application is a desktop network traffic analyzer that provides real-time monitoring and forensic inspection of… wireshark/wireshark — Wireshark is a network protocol analyzer and traffic inspector used for capturing and inspecting network traffic. It… emanuele-f/pcapdroid — PCAPdroid is an Android network traffic analyzer and packet capture tool that operates without requiring root access.… ntop/ntopng — ntopng is a web-based network traffic monitoring tool and flow data aggregator. It functions as a network security… gcla/termshark — Termshark is a terminal-based network packet analyzer and protocol flow inspector. It serves as a keyboard-driven…