Network Forensics

Compare 28 network forensics tools to find the right one for your needs

πŸ”§ Tools

Compare and find the best network forensics for your needs

Volatility Framework

An advanced memory forensics framework.

An open-source framework for incident response and malware analysis that allows for the extraction of digital artifacts from volatile memory (RAM) samples.

View tool details β†’

NetworkMiner

The Network Forensic Analysis Tool (NFAT).

An open-source tool for network forensics and traffic analysis that can extract files, emails, and other artifacts from PCAP files or live traffic.

View tool details β†’

Nmap

The Network Mapper - Free Security Scanner

A free and open-source utility for network discovery and security auditing.

View tool details β†’

Security Onion

A free and open platform for threat hunting, enterprise security monitoring, and log management.

A Linux distribution for intrusion detection, network security monitoring, and log management.

View tool details β†’

Wireshark

The world’s foremost and widely-used network protocol analyzer.

A free and open-source packet analyzer used for network troubleshooting, analysis, and software and communications protocol development.

View tool details β†’

tcpdump

A powerful command-line packet analyzer.

A free and open-source command-line utility for capturing and analyzing network traffic.

View tool details β†’

Suricata

A free and open source, mature, fast and robust network threat detection engine.

An open-source network intrusion detection system (IDS), intrusion prevention system (IPS), and network security monitoring (NSM) engine.

View tool details β†’

Paessler PRTG Network Monitor

The all-in-one network monitoring solution.

A comprehensive network monitoring tool that monitors all the systems, devices, traffic, and applications in your IT infrastructure.

View tool details β†’

Mandiant Security Validation

Continuously measure, manage, and improve cyber security effectiveness.

A security validation platform that allows you to continuously measure, manage, and improve your cyber security effectiveness.

View tool details β†’

Autopsy

The premier end-to-end open source digital forensics platform.

A free and open-source digital forensics platform that provides a graphical interface to The Sleuth Kit and other forensic tools.

View tool details β†’

Zeek

An Open Source Network Security Monitoring Tool.

A powerful and flexible open-source network analysis framework that provides detailed logs of network activity.

View tool details β†’

Snort

The foremost Open Source Intrusion Prevention System (IPS) in the world.

An open-source network intrusion prevention system (NIPS) and network intrusion detection system (NIDS) capable of real-time traffic analysis and packet logging.

View tool details β†’

LiveAction LiveWire

Packet-Level Network Forensics and Analysis.

A solution for capturing and analyzing network packets to troubleshoot network and application performance issues and conduct security forensics.

View tool details β†’

Cisco Secure Network Analytics (Stealthwatch)

Get visibility and security analytics across your network.

A network detection and response (NDR) solution that uses enterprise-wide network visibility and security analytics to detect and respond to threats in real time.

View tool details β†’

SolarWinds NetFlow Traffic Analyzer

Network traffic analysis and bandwidth monitoring.

A network traffic analysis tool that provides a comprehensive view of network traffic, allowing you to identify who and what is consuming your bandwidth.

View tool details β†’

ManageEngine NetFlow Analyzer

Real-time bandwidth monitoring and network traffic analysis.

A web-based network traffic analysis tool that collects, analyzes, and reports on what your network bandwidth is being used for and by whom.

View tool details β†’

Splunk

The Key to Enterprise Resilience.

A data platform that provides security information and event management (SIEM), observability, and IT solutions.

View tool details β†’

NetWitness NDR

Unparalleled visibility to spot threats fast.

A network detection and response (NDR) solution that provides real-time visibility into network traffic to detect and respond to threats.

View tool details β†’

Nagios Network Analyzer

In-depth network traffic analysis and bandwidth utilization.

A network traffic analysis tool that provides a detailed look at your network traffic and bandwidth utilization.

View tool details β†’

OSForensics

Digital investigation for a new era.

A digital forensics and e-discovery tool that allows you to extract and analyze digital evidence from computers, mobile devices, and other sources.

View tool details β†’

OpenText EnCase Forensic

The global standard in digital investigation technology.

A court-proven solution for digital forensics that enables examiners to acquire data from a wide variety of devices and conduct in-depth investigations.

View tool details β†’

Exterro FTK

The industry’s leading digital investigation solution.

A comprehensive digital forensics platform that provides processing and indexing of data upfront, so you can start your investigation sooner.

View tool details β†’

Xplico

Open Source Network Forensic Analysis Tool (NFAT).

An open-source network forensic analysis tool that reconstructs the contents of acquisitions performed with a packet sniffer.

View tool details β†’

CAINE

Computer Aided INvestigative Environment

A Linux live distribution created as a digital forensics project, offering a complete forensic environment.

View tool details β†’

SANS SIFT Workstation

A premier open-source incident response and digital forensics toolkit.

A collection of free and open-source incident response and forensic tools designed to perform detailed digital forensic examinations.

View tool details β†’

Bulk Extractor

A high-performance digital forensic exploitation tool.

An open-source tool that scans a disk image, a file, or a directory of files and extracts useful information without parsing the file system or file system structures.

View tool details β†’

The Sleuth Kit

Open source digital forensics tools.

A collection of command-line tools and a C library that allows you to analyze disk images and recover files from them.

View tool details β†’

Plaso

Super timeline all the things.

A command-line tool to extract timestamps from various files found on a typical computer system and aggregate them.

View tool details β†’