Arkime is an open-source network capture and analysis tool designed to augment existing security infrastructure. It stores and indexes network traffic in standard PCAP format, offering full network visibility to security teams. The tool is scalable, capable of handling hundreds of gigabits per second when deployed across multiple clustered systems. Arkime features a Sessions page for viewing indexed sessions, a powerful search functionality, and the ability to export results as PCAP or CSV. It includes an SPI (Session Profile Information) View for analyzing unique values of captured fields, and an SPI Graph page for temporal views of top unique field values. The Connections page provides a network graph visualization of search results. Additionally, Arkime offers a Parliament application for monitoring multiple Arkime clusters and a Cont3xt application for gathering contextual intelligence during technical investigations.
FEATURES
ALTERNATIVES
netsniff-ng is a free Linux networking toolkit with zero-copy mechanisms for network development, analysis, and auditing.
A powerful command-line packet analyzer and a portable C/C++ library for network traffic capture with comprehensive documentation.
A wrapper around jNetPcap for packet capturing with Clojure, available for Linux and Windows.
MIDAS (Mac Intrusion Detection Analysis System) - archived and no longer supported.
Chaosreader is a tool for ripping files from network sniffing dumps and replaying various protocols and file transfers.
A collection of PCAPs for ICS/SCADA utilities and protocols with the option for users to contribute.
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.