Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Network Forensics

Tools for analyzing network traffic and communication logs to investigate security incidents.

Kitploit recommended

Top tools

10 selected
wireshark preview#1

wireshark

GitHubwireshark/wireshark
9.9k17h 12m ago
zeek preview#2

zeek

GitHubzeek/zeek
7.8k3 days ago
arkime preview#3

arkime

GitHubarkime/arkime
7.4k19h 44m ago
Malcolm preview#4

Malcolm

GitHubcisagov/malcolm
2.5k1 month ago
suricata preview#5

suricata

GitHuboisf/suricata
6.5k6 days ago
ntopng preview#7

ntopng

GitHubntop/ntopng
8.1k16h 24m ago
scapy preview#8

scapy

GitHubsecdev/scapy
12.5k1 day ago
etl2pcapng preview#10

etl2pcapng

GitHubmicrosoft/etl2pcapng
7351 year ago
netsniff-ng preview#11

netsniff-ng

GitHubnetsniff-ng/netsniff-ng
1.4k1 year ago
gopacket preview#13

gopacket

GitHubgoogle/gopacket
6.8k1 year ago
NewestRelevanceMost popularRecently updated
140 results
maltrail preview

maltrail

GitHubstamparm/maltrail

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

defensive-toolsioc-managementthreat-feeds-aggregators+11
8.6k1 day ago
zeek preview

zeek

GitHubzeek/zeek

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

defensive-toolspacket-sniffing-analysisnetwork-mapping+14
7.8k3 days ago
suricata preview

suricata

GitHuboisf/suricata

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

defensive-toolspacket-sniffing-analysisnetwork-forensics+9
6.5k6 days ago
securityonion preview

securityonion

GitHubsecurity-onion-solutions/securityonion

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

defensive-toolspacket-sniffing-analysisnetwork-forensics+9
4.9k17 days ago
Dshell preview

Dshell

GitHubusarmyresearchlab/dshell

Dshell is a network forensic analysis framework.

packet-sniffing-analysisnetwork-forensicsforensics+3
5.5k2 years ago
Incident-Response-Powershell preview

Incident-Response-Powershell

GitHubbert-janp/incident-response-powershell

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

disk-forensicsioc-managementmemory-forensics+6
8074 months ago
wireshark preview

wireshark

GitHubwireshark/wireshark

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

packet-sniffing-analysiswi-fi-auditingbluetooth-security+11
9.9k17h 12m ago
etl2pcapng preview

etl2pcapng

GitHubmicrosoft/etl2pcapng

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

packet-sniffing-analysisnetwork-forensicsforensics+2
7351 year ago
Loki preview

Loki

GitHubneo23x0/loki

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

disk-forensicsioc-managementvulnerability-scanners+11
3.8k8 months ago
velociraptor preview

velociraptor

GitHubvelocidex/velociraptor

Digging Deeper....

defensive-toolsdisk-forensicsmemory-forensics+8
4.2k12h 48m ago
grr preview

grr

GitHubgoogle/grr

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

disk-forensicsmemory-forensicsnetwork-forensics+4
5.1k3 days ago
passivedns preview

passivedns

GitHubgamelinux/passivedns

A network sniffer that logs all DNS server replies for use in a passive DNS setup

network-forensicsforensicsinformation-gathering+3
1.7k2 years ago
so-crates preview

so-crates

GitHubdougburks/so-crates

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

packet-sniffing-analysiscontainer-securityvulnerability-analysis+8
57118 hours ago
termshark preview

termshark

GitHubgcla/termshark

A terminal UI for tshark, inspired by Wireshark

packet-sniffing-analysisnetwork-forensicsnetwork-security+1
10.0k3 years ago
tcpdump preview

tcpdump

GitHubthe-tcpdump-group/tcpdump

the TCPdump network dissector

packet-sniffing-analysisnetwork-mappingvulnerability-analysis+5
3.2k7 days ago
PcapPlusPlus preview

PcapPlusPlus

GitHubseladb/pcapplusplus

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

packet-sniffing-analysisnetwork-mappingnetwork-forensics+5
3.1k2 days ago
netsniff-ng preview

netsniff-ng

GitHubnetsniff-ng/netsniff-ng

A Swiss army knife for your daily Linux network plumbing.

packet-sniffing-analysisreconnaissancenetwork-mapping+4
1.4k1 year ago
PcapViz preview

PcapViz

GitHub1ultimat3/pcapviz

Visualize network topologies and collect graph statistics based on pcap files

packet-sniffing-analysisnetwork-mappingnetwork-forensics+1
3593 years ago
Previous12…8Next