Wireshark is the world's foremost network protocol analyzer, and is the de facto (and often de jure) standard across many industries and educational institutions.
(Wireshark was known as Ethereal until June 09, 2006)
Snort is a lightweight network intrusion detection system, capable of performing real-time traffic analysis and packet logging on IP networks. It can perform protocol analysis, content searching/matching and can be used to detect a variety of attacks and probes, such as buffer overflows, stealth
... [More] port scans, CGI attacks, SMB probes, OS fingerprinting attempts, and much more. Snort uses a flexible rule based language to describe traffic that it should collect or pass, and a modular detection engine. Snort has a real-time alerting capability, with alert mechanisms for syslog, a user specified file, a UNIX socket, or WinPopup messages to Windows clients using Samba's smbclient. [Less]
Ostinato is a cross-platform network packet and traffic generator and analyzer with a friendly GUI. It aims to be "Wireshark in Reverse" and thus become complementary to Wireshark.
Features custom packet crafting with any field editing support for several protocols -
L2: Ethernet, 802.3, LLC
... [More] SNAP, VLAN (with Q-in-Q)
L3: ARP, IPv4, IPv6, IP-in-IP (a.k.a IP Tunneling)
L4: TCP, UDP, ICMPv4, ICMPv6, IGMP, MLD
L5: HTTP, SIP, RTSP, NNTP etc.
Useful for both functional and performance testing.
Works on Windows, Linux, BSD and Mac OS X.
See the Homepage for a full list of features. [Less]
GroinK is an advanced sniffer that supports protocol deconding and MiTM attacks. Unlike other sniffers, Groink uses lua as scripting language that allows you to extend it easily.
This site uses cookies to give you the best possible experience.
By using the site, you consent to our use of cookies.
For more information, please see our
Privacy Policy