PCAPdroid is a privacy-friendly open source app that allows you to track, analyze, and block connections made by other apps on your device. It enables you to export a PCAP dump of the traffic, inspect HTTP, decrypt TLS traffic, and more. Features include logging and examining connections made by user and system apps, extracting SNI, DNS query, HTTP URL, and remote IP address, inspecting HTTP requests and replies, decrypting HTTPS/TLS traffic, exporting SSLKEYLOGFILE, dumping traffic to a PCAP file, creating rules to filter traffic, identifying country and ASN of remote servers, and on rooted devices, capturing traffic while other VPN apps are running. Paid features include firewall creation and malware detection.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A honeytoken-based tripwire for Microsoft's Active Directory to detect privilege escalation attempts
A complete suite of tools for assessing WiFi network security with capabilities for monitoring, attacking, testing, and cracking.
Ensnare is a gem plugin for Ruby on Rails that enables quick deployment of a malicious behavior detection and response scheme using Honey Traps and Trap Responses.
Open source DDoS protection system with centralized policy for network operators.
Zeek Remote desktop fingerprinting script for fingerprinting Remote Desktop clients.
Fail2ban is a daemon that automatically bans IP addresses showing malicious behavior by monitoring log files and updating firewall rules to prevent brute-force attacks.
A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.