Loading...
Network security is the set of controls that govern how traffic moves between users, devices, workloads, and the internet, deciding what gets to talk to what and inspecting the conversation along the way. It is one of the oldest disciplines in the field and one of the most actively rebuilt, because the network keeps changing shape: the perimeter that used to sit at a data center edge now follows the user to a coffee shop, and workloads that once lived behind a firewall now spin up across multiple clouds. CISOs shop this category for two different reasons. One is to defend the network they still run, with next-gen firewalls, intrusion detection and prevention, network detection and response, DDoS mitigation, network sandboxing, and network access control. The other is to retire the castle-and-moat model entirely, with zero trust network access, microsegmentation, and the converged cloud-delivered architectures analysts file under secure access service edge and security service edge. So the first practical question is whether you are hardening the network you have or rearchitecting how access works.
We cover 561 Network Security tools, 71 free and 490 commercial.
Accuracy and depth improve over time. Last reviewed Jul 2026. Is something off? Reach out.
Romana automates cloud-native network isolation and distributed firewall policies for Kubernetes and OpenStack environments using topology-aware IPAM without overlays.
A KDE Plasma 4 widget that displays real-time traffic information for active network connections on Linux computers.
PFQ v6.2 is a functional framework for Linux optimized for efficient packet capture/transmission and in-kernel processing.
6Guard is an IPv6 attack detector sponsored by Google Summer of Code 2012 and supported by The Honeynet Project organization.
A set of Bro/Zeek scripts that detect ATT&CK-based adversarial activity and raise notices
A controller addon that provides additional security defenses for onion services ahead of official Tor-core release.
An intrusion prevention system for SSH that blocks IP addresses after a set number of consecutive failed login attempts.
A wireless network detector, sniffer, and intrusion detection system
Passive Network Audit Framework (PNAF) v0.1.2 provides passive network auditing capabilities and is now a project of COSMIC-Chapter of The Honeynet Project.
OpenSnitch is a GNU/Linux application firewall with interactive outbound connections filtering and system-wide domain blocking capabilities.
Netcap efficiently converts network packets into structured audit records for machine learning algorithms, using Protocol Buffers for encoding.
CrowdSec is a collaborative behavior detection engine that analyzes system logs to identify and block malicious activities using community-shared threat intelligence.
Accurate detection of HTTPS interception and robust TLS fingerprinting tool.
A package for capturing and analyzing network flow data and intraflow data.
Cilium is a networking, observability, and security solution with an eBPF-based dataplane.
A tool for classifying packets into flows based on 4-tuple without additional processing.
An open-source network security monitoring tool.
Apache Spot is an open source big data platform that analyzes network flows and packet data to identify security threats and provide visibility into enterprise computing environments.
Open source framework for network traffic analysis with advanced features.
Express middleware for detecting and redirecting Tor or Surface users.
An open source packet capture and forwarding tool that captures network packets on one machine and sends them to another for remote monitoring and analysis.
An open source DDoS protection system that uses distributed algorithms to defend against multi-vector attacks and scale to handle varying bandwidth requirements for network operators and service providers.
561 tools across 11 specializations · 71 free, 490 commercial
Network Detection and Response
NDR platforms for real-time network threat detection, investigation, and automated response to network-based attacks.
Next-Gen Firewalls
Next-generation firewall (NGFW) solutions with advanced threat detection, application control, and deep packet inspection.
VPN
Virtual Private Network tools for secure, encrypted connections and privacy protection.
Common questions about Network Security tools, selection guides, pricing, and comparisons.
Network security is the practice of controlling and inspecting traffic as it moves between users, devices, applications, and external networks. It covers perimeter defenses like firewalls, intrusion prevention, and DDoS mitigation, plus access-centric models like zero trust network access and microsegmentation that limit lateral movement once an attacker is inside. The goal is to enforce who and what can communicate, and to detect or block malicious activity in transit.
Network security is the broad category; SASE and SSE are specific cloud-delivered architectures within it. Secure access service edge converges networking and security functions into one cloud platform that follows the user. Security service edge is the security half of that, typically combining secure web gateway, CASB, and zero trust network access without the networking layer. Traditional network security still includes on-premises tools like next-gen firewalls and IDPS that SASE and SSE often aim to consolidate.
Decide first whether you are hardening an existing network or moving toward zero trust access. Then map your traffic: remote users, branch offices, data center, and multi-cloud workloads each pull you toward different subcategories. Weigh inspection depth against latency, how the tool handles encrypted traffic, integration with your identity provider and SIEM, and whether you want point products or a converged SASE or SSE platform. Match the architecture to where your users and workloads actually live.
In most cases yes. Zero trust network access changes how users reach applications by brokering identity-aware connections rather than granting broad network access, but it does not inspect every flow or stop volumetric attacks on its own. Firewalls, intrusion prevention, DDoS mitigation, and network detection and response still cover north-south traffic, internet-facing assets, and east-west visibility. Most organizations run both through a multi-year transition rather than ripping out perimeter controls overnight.
Intrusion detection systems alert on suspicious traffic, while intrusion prevention systems sit inline and can block it, which is why the two ship together as IDPS. Network detection and response goes further, using behavioral analytics across network telemetry to find threats that signature-based tools miss, and it adds investigation and response workflows. IDPS leans toward known-pattern enforcement; NDR leans toward anomaly detection and incident response.
Ranked by real community upvotes and saves — never for sale. Featured placement is always labeled.
Network Access Control
Network Access Control (NAC) solutions for controlling device access to networks, enforcing security policies, and managing network endpoints.