Wireshark!

**The Wireshark Developers's Guide is available in several formats: ** Web pages (browseable: One huge page https://www.wireshark.org/docs/wsdg_html
or multiple pages https://www.wireshark.org/docs/wsdg_html_chunked
Web pages (ZIP file: One huge page https://www.wireshark.org/download/docs/wsdg_html.zip
or multiple pages https://www.wireshark.org/download/docs/wsdg_html_chunked.zip
PDF: US https://www.wireshark.org/download/docs/developer-guide-us.pdfor
A4 https://www.wireshark.org/download/docs/developer-guide-a4.pdf
Windows help: CHM file https://www.wireshark.org/download/docs/developer-guide.chm

Wireshark alternatives

  • tcpdump

  • tcpdump is a common packet analyzer that runs under the command line. It allows the user to intercept and display TCP/IP and other packets being transmitted or received over a network to which the computer is attached.

    tags: networking network-analyzer packet-capture sniffing packet-sniffing
  • Intercepter-NG

  • Intercepter-NG is a multifunctional network toolkit for various types of IT specialists.The main purpose is to recover *interesting* data from the network stream and perform different kinds of MiTM attacks.

    tags: Discontinued Warning Portable Jailbreak Root
  • netcat

  • Netcat is a featured networking utility which reads and writes data across network connections, using the TCP/IP protocol. It is designed to be a reliable "back-end" tool that can be used directly or easily driven by other programs and scripts. At the same time, it is a feature-rich network debugging and exploration tool, since it can create almost any kind of connection you would need and has several interesting built-in capabilities.

    tags: connect connection ipv6 network-utility networking
  • Nethogs

  • NetHogs is a small 'net top' tool. Instead of breaking the traffic down per protocol or per subnet, like most tools do, it groups bandwidth by process. NetHogs does not rely on a special kernel module to be loaded. If there's suddenly a lot of network traffic, you can fire up NetHogs and immediately see which PID is causing this. This makes it easy to indentify programs that have gone wild and are suddenly taking up your bandwidth.

    tags: traffic-monitoring network-activity network-xfce
  • Microsoft Message Analyzer

  • Message Analyzer enables you to capture, display, and analyze protocol messaging traffic; and to trace and assess system events and other messages from Windows components.

    tags: hardware-monitoring network-analyzer network-monitoring network-security packet-capture
  • SmartSniff

  • SmartSniff is a packet sniffer that capture TCP/IP packets and display them as sequence of conversations between clients and servers. You can view the TCP/IP conversations in Ascii mode (for text-based protocols, like HTTP, SMTP, POP3 and FTP) or as hex dump (for non-text base protocols, like DNS). Application can capture TCP/IP packets on your network without installing a capture driver (works only for Windows 2000/XP or greater).

    tags: Portable monitoring sniffing sockets socks
  • Microsoft Network Monitor

  • Microsoft Network Monitor is a packet analyzer. It enables capturing, viewing, and analyzing network data and deciphering network protocols. It can be used to troubleshoot network problems and applications on the network.

    tags: network-monitoring packet-capture tcp-ip
  • Ettercap

  • Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks.It supports active and passive dissection of many protocols (even ciphered ones) and includes many feature for network and host analysis.

    tags: network-analyzer arp
  • CloudShark

  • A web based platform that lets you view, analyze, and share packet capture files in a browser. Works in Safari for iPad and iPhone.

    tags: network-security network-analyzer tcp packet-capture forensics
  • Ethereal

  • Ethereal® is used by network professionals around the world for troubleshooting, analysis, software and protocol development, and education. It has all of the standard features you would expect in a protocol analyzer, and several features not seen in any other product. Its open source license allows talented experts in the networking community to add enhancements. It runs on all popular computing platforms, including Unix, Linux, and Windows.

    tags: Discontinued network-analyzer packet-capture
  • PacketSled

  • PacketSled is next generation network forensics and breach detection.

    tags: network-monitoring network-security packet-capture packet-sniffing network-security-software
  • Colasoft Capsa

  • Colasoft network packet sniffer or network analyzer software for Windows platform, sniff packets, monitor activities and analyze protocols, best tool for network monitoring and troubleshooting, Free trial available, download now.

    tags: packet-sniffing captured-packets
  • Sysdig

  • Sysdig is open source, system-level exploration: capture system state and activity from a running Linux instance, then save, filter and analyze. Think of it as strace + tcpdump + lsof + awesome sauce.With a little Lua cherry on top.

    tags: app-container-monitoring application-monitoring container-monitoring cpu-monitoring it-management
  • Scapy

  • Scapy is a powerful interactive packet manipulation program. It is able to forge or decode packets of a wide number of protocols, send them on the wire, capture them, match requests and replies, and much more. It can easily handle most classical tasks like scanning, tracerouting, probing, unit tests, attacks or network discovery (it can replace hping, 85% of nmap, arpspoof, arp-sk, arping, tcpdump, tethereal, p0f, etc.). It also performs very well at a lot of other specific tasks that most other tools can't handle, like sending invalid frames, injecting your own 802.11 frames, combining technics (VLAN hopping+ARP cache poisoning, VOIP decoding on WEP encrypted channel, ...), etc. »

    tags: packet-crafting packet-editor packet-generator packet-sniffing python
  • Debookee

  • Debookee is the simplest & most powerful network traffic analyzer for macOS.

    tags: network-analyzer network-monitoring network-scanner