The open-source network traffic analyzer. Deep packet inspection, anomaly detection, IP timeline replay and geographic analysis for PCAP & PCAPNG captures.
Parses TCP, UDP, ICMP, DNS, HTTP, TLS, ARP, VLAN and more. Extracts domains, URIs, SNIs, user agents and certificates.
Detects port scans, brute force, C2 beaconing, DNS tunneling, ARP spoofing, data exfiltration and suspicious ports.
Maps every public IP to country, city, ASN and organization. Visualizes connections on an interactive world map.
Watch every connection as animated comets across the map. Filter time windows with the draggable range scrubber.
Protocol distribution, port usage, DNS query types, HTTP status codes and per-IP traffic breakdowns with Chart.js.
Written in C with libpcap for maximum speed. Processes multi-GB captures. Ethernet, Linux SLL/SLL2, Raw IP and VLAN.
Drag and drop or click to upload .pcap, .pcapng or .cap files of any size.
The C engine parses packets, extracts protocols, resolves GeoIP and runs 40+ anomaly checks.
Navigate dashboards, maps, timelines and anomaly reports. Click any event for forensic details.