Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Categories
  3. Networking
  4. PCAPTools

PCAPTools

The "Awesome PCAPTools" project is a curated collection of tools and libraries designed to facilitate the analysis of PCAP (Packet Capture) files, which are essential for network traffic analysis and cybersecurity investigations. This list encompasses a variety of resources, including packet analysis tools, visualization software, libraries for programming languages, and educational materials such as tutorials and documentation. It is beneficial for network engineers, security analysts, and researchers looking to deepen their understanding of network traffic and improve their analysis skills. Users can explore a wealth of resources to enhance their capabilities in working with PCAP files and gain insights into network behavior and security threats.

pcapnetwork-analysiscybersecuritypacket-capturenetwork-toolsdata-visualizationnetwork-security
RSSView on GitHub
3.4k stars475 forks0 contributorsUpdated
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub

Related Awesome Lists

📦
Software-Defined Networking

The "Awesome Software-Defined Networking" project is a curated resource list focused on Software-Defined Networking (SDN), an innovative approach to networking that decouples the control plane from the data plane. This list encompasses a variety of resources, including frameworks, tools, protocols, tutorials, and case studies that illustrate the implementation and benefits of SDN. It is designed for network engineers, system administrators, and researchers looking to deepen their understanding of SDN concepts and applications. By providing access to valuable insights and practical tools, this collection empowers users to explore and implement SDN solutions effectively in their environments.

1.6k
📦
Real-Time Communications

The "Awesome Real-Time Communications" project is a curated collection of resources focused on network protocols that enable near simultaneous exchange of media and data. This list encompasses various technologies such as WebRTC, SIP, and RTP, along with libraries, tools, tutorials, and community resources that facilitate real-time communication applications. Whether you're a beginner looking to understand the basics or an experienced developer seeking advanced techniques, this list provides valuable insights and tools to enhance your projects. Dive into this collection to discover how to implement effective real-time communication solutions in your applications.

471
📦
Scapy

The "Awesome Scapy" project is a curated collection of resources focused on Scapy, a powerful Python library used for interactive packet manipulation and network analysis. This list encompasses a variety of tools, libraries, tutorials, and community resources that enhance the capabilities of Scapy, including packet crafting, sniffing, and analysis. It is beneficial for network engineers, cybersecurity professionals, and developers looking to deepen their understanding of network protocols and packet manipulation. Users can explore a wealth of information and tools that will empower them to effectively utilize Scapy in their projects and research.

335
📦
SNMP

The "Awesome SNMP" project is a curated collection of resources focused on the Simple Network Management Protocol (SNMP), a standard protocol used for collecting, modifying, and organizing information about managed devices on IP networks. This list encompasses a variety of resources including libraries, tools, tutorials, and community contributions that facilitate the implementation and management of SNMP in network environments. It is beneficial for network administrators, developers, and IT professionals who seek to enhance their understanding and utilization of SNMP for effective network management. Users can explore various tools and best practices to optimize their network monitoring and management strategies.

182

Table of Contents

8 sections · 124 projects

Linux commands<a name="linuxcmds"></a>

19 projects
Screenshot

binarytides.com
Screenshot

a.fsdn.com
Screenshot

binarytides.com
Screenshot

cse.wustl.edu
Screenshot

tecmint.com
Screenshot

community.linuxmint.com
Screenshot

binarytides.com
Screenshot

wiki.ipfire.org
Jnettop

sourceforge.net
Screenshot

binarytides.com
Screenshot

binarytides.com
Screenshot

binarytides.com
Screenshot

binarytides.com
Screenshot

binarytides.com
Screenshot

binarytides.com
Screenshot

binarytides.com
Screenshot

binarytides.com
Screenshot

binarytides.com
Screenshot

howtoforge.com

Capture<a name="capture"></a>

15 projects
Libpcap/Tcpdump

tcpdump.org
Deepfence PacketStreamerDeepfence PacketStreamer

Distributed tcpdump for cloud native environments, capturing and streaming network packets from multiple hosts to a central receiver.

#suricata#pcap#observability
Stars1,928
Forks244
Last commit2 years ago
clj-net-pcapclj-net-pcap

A Clojure wrapper for jNetPcap that simplifies packet capturing and network traffic analysis.

#traffic-analysis#java-library#libpcap
Stars67
Forks32
Last commit2 years ago
jNetPcap

sourceforge.net
Arkime

arkime.com
n2disk

ntop.org
Netis Packet AgentNetis Packet Agent

A software probe for capturing and forwarding network packets in cloud, Kubernetes, and virtualized environments.

#software-probe#gre#vxlan
Stars963
Forks175
Last commit17 days ago
OpenFPCOpenFPC

A lightweight full-packet network traffic recorder and buffering tool for commodity hardware.

#traffic-analysis#traffic-recording#distributed-systems
Stars73
Forks11
Last commit7 years ago
PCAPdroidPCAPdroid

A no-root Android app for monitoring, analyzing, and blocking app network traffic with PCAP export and TLS decryption.

#traffic-analysis#open-source#tls-decryption
Stars4,262
Forks502
Last commit3 days ago
PF_RING

ntop.org
pmacctpmacct

A lightweight suite of passive network monitoring tools supporting NetFlow, sFlow, IPFIX, libpcap, and BGP telemetry.

#traffic-analysis#libpcap#ipfix
Stars1,232
Forks279
Last commit7 days ago
softflowdsoftflowd

#ipfix#netflow-exports#psamp
Stars212
Forks30
Last commit1 year ago
TTT

www2.sonycsl.co.jp
Yaf

tools.netsa.cert.org
sharppcapsharppcap

A fully managed, cross-platform .NET library for capturing network packets from live devices and files.

#sharppcap#network-programming#libpcap-wrapper
Stars1,477
Forks273
Last commit3 days ago

Analysis/Inspection<a name="analysis"></a>

65 projects
Brim

brimsecurity.com
BruteSharkBruteShark

A Network Forensic Analysis Tool (NFAT) for deep inspection of PCAP files and live traffic, extracting credentials, building network maps, and reconstructing sessions.

#cyber#network-mapping#session-reconstruction
Stars3,388
Forks357
Last commit3 years ago
AIEngine

bitbucket.org
CapAnalysis

capanalysis.net
CapTipperCapTipper

A Python tool to analyze, explore, and revive malicious HTTP traffic from PCAP files for security research.

#digital-forensics#python-tool#network-forensics
Stars724
Forks160
Last commit3 years ago
chopshopchopshop

A Python framework for creating protocol decoders and detectors to analyze APT tradecraft in network traffic.

#network-forensics#security-analysis#mitre-framework
Stars496
Forks111
Last commit3 years ago
CoralReef

caida.org
DPDK

dpdk.org
DPKTDPKT

A Python library for fast packet creation and parsing with definitions for basic TCP/IP protocols.

#packet-parsing#pcap#packet-creation
Stars1,158
Forks272
Last commit2 years ago
ECap

web.archive.org
EtherApe

etherape.sourceforge.io
EttercapEttercap

A comprehensive suite for man-in-the-middle attacks, featuring live connection sniffing, content filtering, and protocol dissection.

#traffic-analysis#passive-scanning#man-in-the-middle
Stars2,755
Forks529
Last commit1 month ago
HttpSnifferHttpSniffer

A multi-threading tool to sniff TCP flow statistics and extract HTTP headers from live traffic or PCAP files.

#network-debugging#command-line-tool#tcp-flow
Stars193
Forks50
Last commit5 months ago
IpsumdumpIpsumdump

A command-line tool for summarizing and manipulating network packet traces from libpcap or tcpdump files.

#packet-aggregation#libpcap#tcpdump
Stars40
Forks8
Last commit2 years ago
ITA

web.archive.org
JoyJoy

A libpcap-based package for extracting and analyzing network flow data in JSON format for security research and monitoring.

#network-research#libpcap#json-output
Stars1,364
Forks333
Last commit2 years ago
libcrafterlibcrafter

A high-level C++ library for crafting, decoding, and sniffing network packets with a Scapy-like interface.

#packet-parsing#traffic-analysis#packet decoder
Stars312
Forks87
Last commit4 days ago
LibnetLibnet

A portable C library for constructing and injecting network packets at IP and link layers.

#c-library#gre#tcp
Stars958
Forks261
Last commit1 year ago
Libnids

libnids.sourceforge.net
Multitail

vanheusden.com
Netsniff-ng

github.com
NetDude

netdude.sourceforge.net
Network Expect

netexpect.org
nfdumpnfdump

A suite of tools for collecting, processing, and analyzing NetFlow, IPFIX, and sFlow data from network devices.

#nfdump#traffic-analysis#pcap-parser
Stars908
Forks220
Last commit2 days ago
NFStreamNFStream

A flexible Python framework for fast network flow data analysis, offering encrypted application identification, statistical feature extraction, and extensibility via plugins.

#pcap#data-science#network-monitoring
Stars1,216
Forks144
Last commit3 days ago
Ntop

ntop.org
Ntopng

ntop.org
Ostinato

ostinato.org
packemonpackemon

A cross-platform TUI tool for generating arbitrary network packets and monitoring traffic on any interface.

#packet-analyzer#packet-generator#network
Stars305
Forks5
Last commit7 days ago
PacketQPacketQ

A command-line tool that runs SQL queries directly on PCAP files and includes a built-in web server for remote inspection.

#dns-analysis#network-troubleshooting#sql-queries
Stars396
Forks55
Last commit5 months ago
Pcap2harPcap2har

Stars243
Forks68
Last commit8 years ago
PcapPlusPlusPcapPlusPlus

A multiplatform C++ library for capturing, parsing, and crafting network packets with wrappers for libpcap, DPDK, and PF_RING.

#packet-parsing#packet-processing#libpcap
Stars3,119
Forks753
Last commit2 days ago
pcaptoparquetpcaptoparquet

A Python package for converting PCAP network capture files to Parquet, CSV, or JSON formats.

#parquet#network-traffic#pcap
Stars6
Forks1
Last commit7 months ago
pkt2flowpkt2flow

A cross-platform utility that classifies network packets into flows using the essential 4-tuple (src_ip, dst_ip, src_port, dst_port).

#deep-packet-inspection#pcap-processing#network-analysis
Stars177
Forks48
Last commit11 months ago
potironpotiron

A tool to normalize, index, enrich, and visualize network packet captures (pcap) using Redis and interactive web graphics.

#traffic-analysis#graph#pcap-parsing
Stars88
Forks17
Last commit7 years ago
pyshark

kiminewt.github.io
Sanitize

web.archive.org
Scapy

secdev.org
SiLK

tools.netsa.cert.org
Sniff

thedumbterminal.co.uk
Snort

snort.org
Socket SentrySocket Sentry

A KDE Plasma 4 widget for real-time monitoring of active network connections, showing processes, hosts, and traffic rates.

#kde-plasma#network-traffic#pcap-filters
Stars4
Forks1
Last commit7 years ago
Squey

squey.org
Suricata

suricata-ids.org
TCP-Reduce

ita.ee.lbl.gov
Tcpdpriv

ita.ee.lbl.gov
tcpflowtcpflow

A TCP/IP packet demultiplexer that captures and reconstructs TCP connections into separate files for protocol analysis and forensics.

#digital-forensics#traffic-analysis#libpcap
Stars1,773
Forks245
Last commit5 months ago
Tcplook

ita.ee.lbl.gov
tcpreplaytcpreplay

A suite of utilities for editing and replaying previously captured network traffic (pcap files) on Unix and Windows systems.

#netmap#cygwin#performance-testing
Stars1,335
Forks293
Last commit1 day ago
TcpsliceTcpslice

An advanced TCP proxy and connection splicer written in Go for high-bandwidth, high-latency connections.

#network-optimization#packaging#high-latency
Stars8
Forks4
Last commit2 years ago
TcpsplitTcpsplit

A command-line utility that splits large packet capture (pcap) files into smaller traces along TCP connection boundaries.

#network-troubleshooting#libpcap#network-forensics
Stars7
Forks2
Last commit10 years ago
Tcpstat

frenchfries.net
TcptraceTcptrace

Stars79
Forks28
Last commit9 years ago
TraceWrangler

tracewrangler.com
Tstat

tstat.tlc.polito.it
WAND

research.wand.net.nz
WinDivertWinDivert

#divert-sockets#traffic-analysis#network-programming
Stars3,222
Forks597
Last commit3 years ago
WinDump

winpcap.org
WinPcap

winpcap.org
WireEdit

wireedit.com
Wireshark suit

wiki.wireshark.org
Xplot

xplot.org
yaraPcapyaraPcap

A Python tool that extracts HTTP streams from PCAP files and scans them with YARA rules for security analysis.

#yara-scanner#forensics-tool#malware-detection
Stars108
Forks26
Last commit13 years ago
yaraprocessoryaraprocessor

Stars98
Forks11
Last commit11 years ago
Zeek

zeek.org

DNS Utilities <a name="dnstools"></a>

5 projects
dnsgram

doc.powerdns.com
dnsreplay

doc.powerdns.com
dnsscan

doc.powerdns.com
dnsscope

doc.powerdns.com
dnswasher

doc.powerdns.com

File Extraction<a name="fileextraction"></a>

11 projects
ChaosreaderChaosreader

A Perl tool that extracts and reassembles application sessions and files from network packet captures for analysis and replay.

#traffic-analysis#network-forensics#tcpdump
Stars239
Forks50
Last commit4 years ago
Dsniff

monkey.org
ForemostForemost

Stars54
Forks7
Last commit13 years ago
Justniffer

onotelli.github.io
NetworkMiner

netresec.com
pcapfexpcapfex

A Python tool that finds and extracts files from packet capture (pcap) files for forensic analysis.

#digital-forensics#plugin-system#python-2
Stars229
Forks43
Last commit6 years ago
ScalpelScalpel

Stars684
Forks111
Last commit2 years ago
Snort

snort.org
tcpick

tcpick.sourceforge.net
tcpxtract

tcpxtract.sourceforge.net
Xplico

xplico.org