arkime by arkime

Arkime (formerly Moloch) is an open source, large scale, full packet capturing, indexing, and database system.

created at July 6, 2012, 4:10 p.m.

JavaScript

365 +0

4,706 +11

877 -2

GitHub
PcapPlusPlus by seladb

PcapPlusPlus is a multiplatform C++ library for capturing, parsing and crafting of network packets. It is designed to be efficient, powerful and easy to use. It provides C++ wrappers for the most popular packet processing engines such as libpcap, WinPcap, DPDK and PF_RING.

created at Oct. 7, 2014, 9:04 p.m.

C++

82 +0

1,346 +10

366 -1

GitHub
tcpflow by simsong

TCP/IP packet demultiplexer. Download from:

created at April 1, 2012, 12:44 a.m.

C++

78 +1

1,236 +4

215 +0

GitHub
joy by cisco

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

created at Jan. 8, 2016, 8:30 p.m.

C

116 +1

1,044 +4

288 +0

GitHub
dpkt by kbandla

fast, simple packet creation / parsing, with definitions for the basic TCP/IP protocols

created at June 6, 2012, 6:39 p.m.

Python

47 +0

791 +4

219 +2

GitHub
CapTipper by omriher

Malicious HTTP traffic explorer

created at Jan. 13, 2015, 9:05 a.m.

Python

64 +0

649 +0

162 +0

GitHub
usbpcap by desowin

USB packet capture for Windows

created at Feb. 23, 2013, 10:47 p.m.

C

68 +0

538 +1

133 +0

GitHub
scalpel by sleuthkit

Scalpel is an open source data carving tool. It is not being actively maintained.

created at June 27, 2013, 4:59 p.m.

Shell

35 +0

445 +2

83 +0

GitHub
chopshop by MITRECND

Protocol Analysis/Decoder Framework

created at Sept. 18, 2012, 5:51 p.m.

Python

72 +0

444 +0

111 +0

GitHub
packet-agent by Netis

A toolset for network packet capture in Cloud/Kubernetes and Virtualized environment.

created at June 22, 2018, 10:08 a.m.

C++

26 +0

421 +1

140 +0

GitHub
PacketQ by DNS-OARC

A tool that provides a basic SQL-frontend to PCAP-files

created at Feb. 7, 2011, 3:29 p.m.

JavaScript

29 +0

367 +2

49 +1

GitHub
pcap2har by andrewf

A convertor from .pcap network capture files to HTTP Archive files.

created at July 19, 2010, 11 p.m.

Python

24 +0

204 +0

67 +0

GitHub
hadoop-pcap by RIPE-NCC

Hadoop library to read packet capture (PCAP) files

created at Oct. 2, 2011, 12:59 p.m.

Java

40 +0

195 +0

104 +0

GitHub
pcapfex by vikwin

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

created at Nov. 5, 2015, 1:47 p.m.

Python

17 +0

179 +1

39 +0

GitHub
Chaosreader by brendangregg

An any-snarf program that processes application protocols (HTTP/FTP/...) from tcpdump or snoop files and stores session and file data

created at April 10, 2014, 12:56 a.m.

Unknown languages

18 +0

178 +0

39 +0

GitHub
http-sniffer by caesar0301

A multi-threading tool to sniff TCP flow statistics and embedded HTTP headers from PCAP file. Each TCP flow carrying HTTP is exported to text file in json format.

created at Dec. 1, 2012, 9:58 a.m.

C

9 +0

159 +0

48 +0

GitHub
pkt2flow by caesar0301

A simple utility to classify packets into flows. It's so simple that only one task is aimed to finish. For Deep Packet Inspection or flow classification, it's so common to analyze the feature of one specific flow. I have make the attempt to use made-ready tools like tcpflows, tcpslice, tcpsplit, but all these tools try to either decrease the trace volume (under requirement) or resemble the packets into flow payloads (over requirement). I have not found a simple tool to classify the packets into flows without further processing. This is why this program is born.

created at Dec. 20, 2012, 1:17 p.m.

C

11 +0

114 +0

42 +0

GitHub
yaraprocessor by MITRECND

Yara is awesome, but sometimes you need to manipulate the data streams you're scanning in different ways.

created at Jan. 10, 2013, 6:49 p.m.

Python

25 +0

87 +0

11 +0

GitHub
YaraPcap by kevthehermit

Process HTTP Pcaps With YARA

created at June 29, 2013, 3:57 p.m.

Python

7 +0

78 -1

26 +0

GitHub
potiron by CIRCL

Potiron - Normalize, Index and Visualize Network Capture

created at Aug. 27, 2014, 7:46 a.m.

Python

16 +1

66 +0

20 +0

GitHub