Wireshark Alternatives for LinuxFiltered by 'Packet Sniffer'

There are many alternatives to Wireshark for Linux if you are looking for a replacement. The best Linux alternative is tcpdump, which is both free and Open Source. If that doesn't suit you, our users have ranked more than 50 alternatives to Wireshark and 14 are available for Linux so hopefully you can find a suitable replacement. Other interesting Linux alternatives to Wireshark are NetworkMiner, Mojo Packets, Scapy and tcpflow.

filter to find the best alternatives

Wireshark alternatives are mainly Network Monitors, but if you're looking for Network Analyzers you can filter on that. Other popular filters include Android, iPhone, Mac, Linux, Open Source, iPhone + Network Monitoring and iPhone + Network Analyzer. You can also filter by region, for example EU-based alternatives if you prefer software developed in the European Union. These are just examples - use the filter bar below to find more specific alternatives to Wireshark.
Copy a direct link to this comment to your clipboard
Wireshark alternatives page was last updated

Alternatives list

  1. tcpdump icon
     60 likes

    Command-line packet analyzer for monitoring, capturing, and filtering network traffic in real time. Supports TCP/IP protocols, pcap file export, BPF syntax, timestamped outputs, and works on UNIX-like systems with both wired and wireless interfaces.

    32 tcpdump alternatives

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
    • BSD
     
    |
    1
  2. NetworkMiner icon
     19 likes

    NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can extract transmitted files and certificates from PCAP files containing HTTP, FTP, SMB, SMB2, TFTP and several other protocols.

    42 NetworkMiner alternatives

    Cost / License

    Platforms

    • Windows
    • Linux
     
  3. Mojo Packets icon
     2 likes

    Mojo Packets™ is web based tool that simplifies trace based analysis and troubleshooting of connectivity/performance issues observed in Wi-Fi (IEEE 802.11) environments.

    Cost / License

    • Free
    • Proprietary

    Platforms

    • Mac
    • Windows
    • Linux
    • Online
    • Wireshark
     
    |
    1
  4.  6 likes

    Scapy is a powerful interactive packet manipulation program. It is able to forge or decode packets of a wide number of protocols, send them on the wire, capture them, match requests and replies, and much more.

    23 Scapy alternatives

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
     
  5.  3 likes

    tcpflow, a TCP Flow Recorder, is a program that captures data transmitted as part of TCP connections (flows), and stores the data in a way that is convenient for protocol analysis or debugging. A program like 'tcpdump' shows a summary of packets seen on the wire, but...

    22 tcpflow alternatives

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
     
  6.  Like

    httpry is a tool designed for displaying and logging HTTP traffic. It is not intended to perform analysis itself, but instead to capture, parse and/or log the traffic for later analysis. It can be run in real-time displaying the live traffic on the wire, or as a daemon process...

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Linux
     
  7. Impacket icon
     1 like

    Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself.

    Cost / License

    Platforms

    • Python
    • Docker
    • Mac
    • Linux
    • Windows
    • BSD
     
  8. Edgeshark icon
     1 like

    Discover and capture container network traffic from your comfy desktop Wireshark, using a containerized service and a Wireshark plugin.

    Cost / License

    • Free
    • Open Source (MIT)

    Application type

    Platforms

    • Self-Hosted
    • Docker
    • Windows
    • Linux
    • Mac
     
  9.  1 like

    PlayCap plays back captures made from Wireshark, tcpdump, WinDump, or any libpcap-based application. PlayCap was originally (and still is) a part of IG Scanner by Signal 11 Software, but was spun off as a separate app and released as Open Source software.

    Cost / License

    • Free
    • Open Source

    Alerts

    • Discontinued

    Platforms

    • Windows
    • Linux
    • tcpdump
    • Wireshark
     
  10.  Like

    packeth is GUI and CLI packet generator tool for ethernet. Primary it is developed and maintained for Linux, but some ports for Windows and MAC have also be done. It allows you to create and send any possible packet or sequence of packets on the ethernet link.

    Cost / License

    • Free
    • Open Source

    Platforms

    • Mac
    • Windows
    • Linux
     
  11. justniffer is a TCP sniffer. It reassembles and reorders packets and displays the tcp flow in a customizable way. It can log network traffic in web server log format. It can also log network services performances and extract http content.

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Linux
     
  12. VisualEther turns Wireshark packet captures into readable sequence diagrams — and lets an AI agent reason about them. Built on tshark, it reconstructs multi-layer protocol conversations (5G NR/core, LTE, IMS/VoLTE, SIP/RTP, BGP, OSPF, DNS, HTTP/2 & HTTP/3, TLS, Kerberos...

    Cost / License

    • Freemium
    • Proprietary

    Application type

    Platforms

    • Windows
    • Mac
    • Linux
     
12 of 14 Wireshark alternatives