
FakeNet-NG - Next Generation Dynamic Network Analysis Tool
| ____/\ | |/ / ____| \ | | ____|__ __| | \ | |/ ____|
| |__ / \ | ' /| |__ | \| | |__ | |______| \| | | __
| __/ /\ \ | < | __| | . ` | __| | |______| . ` | | |_ |
| | / ____ \| . \| |____| |\ | |____ | | | |\ | |__| |
|_|/_/ \_\_|\_\______|_| \_|______| |_| |_| \_|\_____|
D O C U M E N T A T I O N
FakeNet-NG 3.5 is a next generation dynamic network analysis tool for malware analysts and penetration testers. It is open source and designed for the latest versions of Windows (and Linux, for certain modes of operation). FakeNet-NG is based on the excellent Fakenet tool developed by Andrew Honig and Michael Sikorski.
The tool allows you to intercept and redirect all or specific network traffic while simulating legitimate network services. Using FakeNet-NG, malware analysts can quickly identify malware's functionality and capture network signatures. Penetration testers and bug hunters will find FakeNet-NG's configurable interception engine and modular framework highly useful when testing application's specific functionality and prototyping PoCs.
You can install FakeNet-NG in a few different ways. Note that the following installation processes will retrieve third-party open-source libraries used by FakeNet-NG to your system. These libraries will be dynamically loaded at runtime, and some of these libraries may be LGPL licensed.
It is easiest to simply download the compiled version which can be obtained from the releases page:
https://github.com/mandiant/flare-fakenet-ng/releases
Execute FakeNet-NG by running 'fakenet.exe'.
This is the preferred method for using FakeNet-NG on Windows as it does not require you to install any additional modules, which is ideal for a malware analysis machine.
NOTE: FakeNet-NG may be flagged as malicious by Antivirus (AV) and Endpoint Detection and Response (EDR) solutions (e.g., Windows Defender, Chrome's Safe Browsing). This is likely due to its ability to modify network traffic and simulate network services, in addition to the use of PyInstaller to build the release executables. The official release binaries are safe, and these detections should be considered false positives. As a reminder, FakeNet-NG is designed and highly recommended for use in a controlled and isolated environment, such as a Virtual Machine (VM), where it can safely alter the system’s network settings.
Install Python 3.10.11 and latest pip for Windows/Linux OS.
On Windows, download and install Visual C++ build tools.
Installation on Linux requires the following dependencies:
Install these dependencies using the following command:
sudo apt-get install build-essential python3.10-dev libnetfilter-queue-dev
Install FakeNet-NG as a Python module using pip:
python -m pip install https://github.com/mandiant/flare-fakenet-ng/zipball/master
Or by obtaining the latest source code and installing it manually:
git clone https://github.com/mandiant/flare-fakenet-ng/
Install Python dependencies by running the following commands with admin privileges:
In Linux (tested in Ubuntu 24.04.2 LTS), run the following commands before running setup.py:
python -m pip install --upgrade setuptools
# build wheel for python 3.10
python -m pip install --force-reinstall netifaces
# Observed "ModuleNotFoundError: No module named '_cffi_backend'" error while testing
# This will get the required version of cffi packages for cryptography
python -m pip install --upgrade cryptography
If installing manually, change directory to the downloaded flare-fakenet-ng and run the following with admin privileges:
python setup.py install
In Linux, free port 53 for DNS listener:
sudo systemctl stop systemd-resolved
Execute FakeNet-NG by running 'fakenet' from any directory in a privileged shell.
Finally if you would like to avoid installing FakeNet-NG and just want to run it as-is (e.g. for development), then you would need to obtain the source code and install dependencies as follows:
Install 64-bit or 32-bit Python 3.10.11 for the 64-bit or 32-bit versions of Windows/Linux respectively.
In Windows, install Python dependencies by running the following commands with admin privileges:
python -m pip install pydivert dnslib dpkt pyopenssl pyftpdlib netifaces jinja2
NOTE: pydivert will also download and install WinDivert library and
driver in the %PYTHONHOME%\DLLs directory. FakeNet-NG bundles those
files so they are not necessary for normal use.
In Linux, install Python dependencies by running the following commands with admin privileges:
python -m pip install --upgrade setuptools
# build wheel for python 3.10
python -m pip install --force-reinstall netifaces
# Observed "ModuleNotFoundError: No module named '_cffi_backend'" error while testing
# This will get the required version of cffi packages for cryptography
python -m pip install --upgrade cryptography
python -m pip install netfilterqueue dnslib dpkt pyopenssl pyftpdlib netifaces jinja2
Optionally, you can install the following module used for testing:
python -m pip install requests
Download the FakeNet-NG source code:
git clone https://github.com/mandiant/flare-fakenet-ng
In Linux, free port 53 for DNS listener:
sudo systemctl stop systemd-resolved
Execute FakeNet-NG by running it with a Python interpreter in a privileged shell:
python -m fakenet.fakenet
The easiest way to run FakeNet-NG is to simply execute the provided
executable as an Administrator. You can provide --help command-line
parameter to get simple help:
C:\tools\fakenet-ng>fakenet.exe --help
______ _ ________ _ _ ______ _______ _ _ _____
| ____/\ | |/ / ____| \ | | ____|__ __| | \ | |/ ____|
| |__ / \ | ' /| |__ | \| | |__ | |______| \| | | __
| __/ /\ \ | < | __| | . ` | __| | |______| . ` | | |_ |
| | / ____ \| . \| |____| |\ | |____ | | | |\ | |__| |
|_|/_/ \_\_|\_\______|_| \_|______| |_| |_| \_|\_____|
Version 3.5
_____________________________________________________________
Developed by FLARE Team
Copyright (C) 2016-2026 Mandiant, Inc. All rights reserved.
_____________________________________________________________
Usage: python -m fakenet.fakenet [options]:
Options:
-h, --help show this help message and exit
-c FILE, --config-file=FILE
configuration filename
-v, --verbose print more verbose messages (default: False)
-l LOG_FILE, --log-file=LOG_FILE
-s, --log-syslog Log to syslog via /dev/log (default: False)
-f STOP_FLAG, --stop-flag=STOP_FLAG
terminate if stop flag file is created
-p, --no-pause disable pause for confirmation before closing the console
(default: pause)
-n, --no-console-output
Suppress console output (for testing on Linux)