Open Source Wireshark Alternatives for Linux

There are many alternatives to Wireshark for Linux if you are looking for a replacement. The best open source Linux alternative is tcpdump. If that doesn't suit you, our users have ranked more than 50 alternatives to Wireshark and many of them are open source and available for Linux so hopefully you can find a suitable replacement. Other interesting open source Linux alternatives to Wireshark are NetworkMiner, Ettercap, Termshark and Scapy.

filter to find the best alternatives

Most Wireshark alternatives are Network Monitors, but you can also narrow the list to Network Analyzers. Other popular filters are iPhone, Android, Mac, Linux and Open Source. You can also filter for EU-based alternatives if you prefer software from the European Union.
Copy a direct link to this comment to your clipboard
Alternatives
Wireshark alternatives page was last updated

Alternatives list

  1. tcpdump icon
     60 likes

    Command-line packet analyzer for monitoring, capturing, and filtering network traffic in real time. Supports TCP/IP protocols, pcap file export, BPF syntax, timestamped outputs, and works on UNIX-like systems with both wired and wireless interfaces.

    32 tcpdump alternatives

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
    • BSD
    Good alternative?
     
    |
    1
  2. NetworkMiner icon
     19 likes

    NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can extract transmitted files and certificates from PCAP files containing HTTP, FTP, SMB, SMB2, TFTP and several other protocols.

    43 NetworkMiner alternatives

    Cost / License

    Application type

    Platforms

    • Windows
    • Linux
    Good alternative?
     
  3. Ettercap icon
     18 likes

    Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks.

    Cost / License

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
    Good alternative?
     
  4. Termshark icon
     Like

    If you're debugging on a remote machine with a large pcap and no desire to scp it back to your desktop, termshark can help!

    54 Termshark alternatives

    Cost / License

    • Free
    • Open Source (MIT)

    Platforms

    • Mac
    • Windows
    • Linux
    • BSD
    Good alternative?
     
  5.  6 likes

    Scapy is a powerful interactive packet manipulation program. It is able to forge or decode packets of a wide number of protocols, send them on the wire, capture them, match requests and replies, and much more.

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
    Good alternative?
     
  6. Sysdig icon
     12 likes

    Sysdig is open source, system-level exploration: capture system state and activity from a running Linux instance, then save, filter and analyze. Think of it as strace + tcpdump + lsof + awesome sauce.

    25 Sysdig alternatives

    Cost / License

    • Free
    • Open Source

    Platforms

    • Mac
    • Windows
    • Linux
    Good alternative?
     
  7.  21 likes

    NetHogs is a small 'net top' tool. Instead of breaking the traffic down per protocol or per subnet, like most tools do, it groups bandwidth by process.

    26 Nethogs alternatives

    Cost / License

    • Free
    • Open Source

    Platforms

    • Linux
    • Xfce
    Good alternative?
     
  8.  3 likes

    tcpflow, a TCP Flow Recorder, is a program that captures data transmitted as part of TCP connections (flows), and stores the data in a way that is convenient for protocol analysis or debugging. A program like 'tcpdump' shows a summary of packets seen on the wire, but...

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
    Good alternative?
     
  9.  Like

    httpry is a tool designed for displaying and logging HTTP traffic. It is not intended to perform analysis itself, but instead to capture, parse and/or log the traffic for later analysis. It can be run in real-time displaying the live traffic on the wire, or as a daemon process...

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Linux
    Good alternative?
     
  10. Impacket icon
     1 like

    Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself.

    Cost / License

    • Free
    • Open Source

    Platforms

    • Python
    • Docker
    • Mac
    • Linux
    • Windows
    • BSD
    Good alternative?
     
  11.  1 like

    PlayCap plays back captures made from Wireshark, tcpdump, WinDump, or any libpcap-based application. PlayCap was originally (and still is) a part of IG Scanner by Signal 11 Software, but was spun off as a separate app and released as Open Source software.

    Cost / License

    • Free
    • Open Source

    Alerts

    • Discontinued

    Platforms

    • Windows
    • Linux
    • tcpdump
    • Wireshark
    Good alternative?
     
  12.  1 like

    Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

    Cost / License

    • Free
    • Open Source (MIT)

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
    • Rust
    Good alternative?
     
12 of 23 Wireshark alternatives