Command-line packet analyzer for monitoring, capturing, and filtering network traffic in real time. Supports TCP/IP protocols, pcap file export, BPF syntax, timestamped outputs, and works on UNIX-like systems with both wired and wireless interfaces.



There are many alternatives to Wireshark for Linux if you are looking for a replacement. The best Linux alternative is tcpdump, which is both free and Open Source. If that doesn't suit you, our users have ranked more than 50 alternatives to Wireshark and 14 are available for Linux so hopefully you can find a suitable replacement. Other interesting Linux alternatives to Wireshark are NetworkMiner, Mojo Packets, Scapy and tcpflow.
Command-line packet analyzer for monitoring, capturing, and filtering network traffic in real time. Supports TCP/IP protocols, pcap file export, BPF syntax, timestamped outputs, and works on UNIX-like systems with both wired and wireless interfaces.



NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can extract transmitted files and certificates from PCAP files containing HTTP, FTP, SMB, SMB2, TFTP and several other protocols.




Mojo Packets™ is web based tool that simplifies trace based analysis and troubleshooting of connectivity/performance issues observed in Wi-Fi (IEEE 802.11) environments.




Scapy is a powerful interactive packet manipulation program. It is able to forge or decode packets of a wide number of protocols, send them on the wire, capture them, match requests and replies, and much more.



tcpflow, a TCP Flow Recorder, is a program that captures data transmitted as part of TCP connections (flows), and stores the data in a way that is convenient for protocol analysis or debugging. A program like 'tcpdump' shows a summary of packets seen on the wire, but...

Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself.
Discover and capture container network traffic from your comfy desktop Wireshark, using a containerized service and a Wireshark plugin.




justniffer is a TCP sniffer. It reassembles and reorders packets and displays the tcp flow in a customizable way. It can log network traffic in web server log format. It can also log network services performances and extract http content.
VisualEther turns Wireshark packet captures into readable sequence diagrams — and lets an AI agent reason about them. Built on tshark, it reconstructs multi-layer protocol conversations (5G NR/core, LTE, IMS/VoLTE, SIP/RTP, BGP, OSPF, DNS, HTTP/2 & HTTP/3, TLS, Kerberos...




It's open source and use CLI