tcpdump Alternatives for Linux

There are many alternatives to tcpdump for Linux if you are looking for a replacement. The best Linux alternative is Wireshark, which is both free and Open Source. If that doesn't suit you, our users have ranked more than 25 alternatives to tcpdump and 13 are available for Linux so hopefully you can find a suitable replacement. Other interesting Linux alternatives to tcpdump are NetworkMiner, Sysdig, Termshark and Justniffer.

Copy a direct link to this comment to your clipboard
tcpdump alternatives page was last updated

Alternatives list

  1. Wireshark icon
     956 likes

    Wireshark is a premier network protocol analyzer used globally in industries and education, offering multi-platform support, deep protocol inspection, powerful display filters, and VoIP analysis. It allows both live capture and offline analysis, supporting various networks and protocols.

    57 Wireshark alternatives

    Cost / License

    • Free
    • Open Source

    Platforms

    • Mac
    • Windows
    • Linux
    • BSD
    • Snapcraft
    • Flathub
    • Homebrew
    • Chocolatey
     
  2. NetworkMiner icon
     19 likes

    NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can extract transmitted files and certificates from PCAP files containing HTTP, FTP, SMB, SMB2, TFTP and several other protocols.

    38 NetworkMiner alternatives

    Cost / License

    Platforms

    • Windows
    • Linux
     
  3. Sysdig icon
     12 likes

    Sysdig is open source, system-level exploration: capture system state and activity from a running Linux instance, then save, filter and analyze. Think of it as strace + tcpdump + lsof + awesome sauce.

    Cost / License

    • Free
    • Open Source

    Platforms

    • Mac
    • Windows
    • Linux
     
  4. Termshark icon
     Like

    If you're debugging on a remote machine with a large pcap and no desire to scp it back to your desktop, termshark can help!

    Cost / License

    • Free
    • Open Source (MIT)

    Platforms

    • Mac
    • Windows
    • Linux
    • BSD
     
    |
    1
    Termshark vs tcpdump Comments
    Guest
    Positive
    0

    good for tracing on remote machine

    Review by a new / low-activity user.
    • Termshark is Free and Open Sourcetcpdump is also Free and Open Source
  5. justniffer is a TCP sniffer. It reassembles and reorders packets and displays the tcp flow in a customizable way. It can log network traffic in web server log format. It can also log network services performances and extract http content.

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Linux
     
    |
    1
    Justniffer vs tcpdump Comments
    Guest
    Positive
    0

    correctly extract the tcp content

    Review by a new / low-activity user.
    • Justniffer is Free and Open Sourcetcpdump is also Free and Open Source
  6.  3 likes

    tcpflow, a TCP Flow Recorder, is a program that captures data transmitted as part of TCP connections (flows), and stores the data in a way that is convenient for protocol analysis or debugging. A program like 'tcpdump' shows a summary of packets seen on the wire, but...

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
     
  7. G-Earth icon
     2 likes

    Cross-platform Habbo packet manipulator.

    Cost / License

    • Free
    • Open Source (MIT)

    Platforms

    • Windows
    • Mac
    • Linux
     
  8.  Like

    httpry is a tool designed for displaying and logging HTTP traffic. It is not intended to perform analysis itself, but instead to capture, parse and/or log the traffic for later analysis. It can be run in real-time displaying the live traffic on the wire, or as a daemon process...

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Linux
     
  9.  1 like

    PlayCap plays back captures made from Wireshark, tcpdump, WinDump, or any libpcap-based application. PlayCap was originally (and still is) a part of IG Scanner by Signal 11 Software, but was spun off as a separate app and released as Open Source software.

    Cost / License

    • Free
    • Open Source

    Alerts

    • Discontinued

    Platforms

    • Windows
    • Linux
    • tcpdump
    • Wireshark
     
  10. Edgeshark icon
     1 like

    Discover and capture container network traffic from your comfy desktop Wireshark, using a containerized service and a Wireshark plugin.

    Cost / License

    • Free
    • Open Source (MIT)

    Application type

    Platforms

    • Self-Hosted
    • Docker
    • Windows
    • Linux
    • Mac
     
  11.  2 likes

    Driftnet is a program which listens to network traffic and picks out images from TCP streams it observes.

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Linux
     
12 of 13 tcpdump alternatives