
nfstream
NFStream: a Flexible Network Data Analysis Framework.

NFStream: a Flexible Network Data Analysis Framework.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

A wireshark plugin to instrument ETW

CLI MITM proxy that converts SOCKS4/SOCKS5 into HTTP/HTTPS/HTTP2/HTTP3 proxy with transparent TCP/UDP redirection, ARP/NDP/DNS spoofing, traffic…

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

My Aircrack-ng contribution with Thomas d'Otreppe

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Passive DNS Capture and Monitoring Toolkit

Sniffles: Packet Capture Generator for IDS and Regular Expression Evaluation

A pcap capture analysis helper

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Cross-platform network packet generator with full layer spoofing, pattern-based address randomization, and flood detection evasion for stress-testing…

A swiss-knife MCP server for analysing PCAP files

ICMP packet sniffer for capturing, analyzing, and logging Echo Request/Reply packets with filtering, SQLite storage, and PCAP export for network…

ARP spoofing, HTTP redirection, DNS spoofing and DNS forging using pcap library