NFStream Logo

NFStream

0
Free
Visit Website

NFStream is a multiplatform Python framework providing fast, flexible, and expressive data structures designed to make working with online or offline network data easy and intuitive. It aims to be Python's fundamental high-level building block for doing practical, real-world network flow data analysis. Additionally, it has the broader goal of becoming a unifying network data analytics framework for researchers providing data reproducibility across experiments. - Live Notebook - Project Website - Discussion Channel - Latest Release - Supported Versions - Project License - Continuous Integration - Code Quality - Table of Contents - Main Features - How to get it? - How to use it? - Encrypted application identification and metadata extraction - System visibility - Post-mortem statistical flow features extraction - Early statistical flow features extraction - Pandas export interface - CSV export interface - Extending NFStream - Machine Learning models training and deployment - Training the model - ML powered streamer on live traffic - Building from sources - Contributing - Ethics - Credits - Citation - Authors - Supporting organizations - Publications that use NFStream - License Main Features: - Performance: NFStream is designed to be fast: AF_PACKET

FEATURES

ALTERNATIVES

JARM is a TLS server fingerprinting tool used for identifying server configurations and malicious infrastructure.

A tool for creating custom policies for IEE policies

High-performance remote packet capture and collection tool used for forensic analysis in cloud workloads.

A honeytoken-based tripwire for Microsoft's Active Directory to detect privilege escalation attempts

netsniff-ng is a free Linux networking toolkit with zero-copy mechanisms for network development, analysis, and auditing.

Snort is an open source intrusion prevention system that uses rules to detect and prevent malicious network activity.

SSHGuard protects hosts from brute-force attacks by monitoring system logs, detecting attacks, and blocking attackers using a firewall.

A utility to generate malicious network traffic for security evaluation.