tcpdump is a common packet analyzer that runs under the command line. It allows the user to intercept and display TCP/IP and other packets being transmitted or received over a network to which the computer is attached.



There are many alternatives to Wireshark for Linux if you are looking for a replacement. The best open source Linux alternative is tcpdump. If that doesn't suit you, our users have ranked more than 50 alternatives to Wireshark and 19 are open source and available for Linux so hopefully you can find a suitable replacement. Other interesting open source Linux alternatives to Wireshark are NetworkMiner, Ettercap, Termshark and Scapy.
tcpdump is a common packet analyzer that runs under the command line. It allows the user to intercept and display TCP/IP and other packets being transmitted or received over a network to which the computer is attached.



NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can extract transmitted files and certificates from PCAP files containing HTTP, FTP, SMB, SMB2, TFTP and several other protocols.




Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks.

Sysdig is open source, system-level exploration: capture system state and activity from a running Linux instance, then save, filter and analyze. Think of it as strace + tcpdump + lsof + awesome sauce.
NetHogs is a small 'net top' tool. Instead of breaking the traffic down per protocol or per subnet, like most tools do, it groups bandwidth by process.






Discover and capture container network traffic from your comfy desktop Wireshark, using a containerized service and a Wireshark plugin.


It's open source and use CLI