Every IT professional, from companies big or small, knows the value of data.
Troubleshooting is always an act that is half instinct and half data – and Packet Sniffing is where the data comes in.
A Packet Sniffer is the tool that helps you figure out if packets are being sent, received, and arriving safely on your network, but they can also do so much more!
Here is our list of the best packet sniffers and network analyzers:
- SolarWinds Bandwidth Analyzer Pack – EDITOR'S CHOICE A bundle of two network monitoring tools that watch device health and analyze traffic flows. The package includes real-time displays of packet information, which is derived from NetFlow data extractors, and also statistical functions that capture packets, analyze the header contents, and produces aggregated traffic characteristics. Installs on Windows Server. Start a 30-day free trial.
- ManageEngine NetFlow Analyzer – FREE TRIAL A traffic flow analyzer that can help implement traffic shaping measures as well. Runs on Windows Server and Linux. Start a 30-day free trial.
- Wireshark A free packet capture and analysis tool that has a great graphical front-end for viewing traffic statistics. Available for Windows, Linux, Unix, and macOS.
- tcpdump A command-line no fills packet capture utility. Available for Linux, macOS, Unix, and Android.
- Kismet A free packet sniffer for wireless networks. Available for Linux, macOS, and Unix.
- EtherApe A free packet capture tool. Runs on Linux, macOS, and Unix.
- Cain and Abel Known as a hacker tool, this system includes a wireless packet sniffer. Runs on windows.
- Network Miner Available in free and paid versions, this tool captures packets and displays them live on screen. Runs on Windows, macOS, Linux, and Unix.
- KisMAC Now revived as KisMAC 2, this free wireless packet sniffer can show live wireless signal heat maps. Runs on macOS.
Ultimately packet sniffing is the go to tool when you've got a network issue that you can't quite isolate to a single machine or protocol and it's time to start digging deep.
There's almost too many choices in this category of software.
Some of them are a bit ‘old-school'; they're grounded in terminal font and command-prompt interfaces and aren't that user friendly at first glance.
Others are flashy much more geared towards a visual audience with easy installation, or portable executables, and plenty of graphs and tables.
They also range from free to quite expensive for corporate licensing!
Here's the Best Free Packet Sniffers and Network Analyzers for Traffic and Data Analysis:
What should you look for in free network analyzers for traffic management?
We reviewed the market for free packet sniffers and analyzed the options based on the following criteria:
- The ability to communicate with switches and routers using NetFlow, sFlow, J-Flow, and Netstream
- Suitability for multi-vendor environments
- An alerting system to warn of potential bottlenecks
- Traffic shaping measures, such as queuing methodologies
- The option to analyze network packets by sorting, filtering, grouping, and searching
- A way to try paid network analyzers for free
- Tools that work and are not a waste of time installing
With these selection criteria in mind, we have identified some excellent traffic analyzers that have good reputations. We have selected systems that will install on Windows, Linux, macOS, Unix, and Android. Some of the options are paid tools but they offer long free trial periods.
Below is a list of some of the Best Packet Analyzers and Sniffers and some of the features that they have built in for you to extract network information and data. They all tend to have the same sort of functionality – you can view packets being sent and received on some level or another, but many of the tools have certain nuances that allow them to shine in certain situations or network environments; the trick is knowing which one!
SolarWinds Bandwidth Analyzer Pack consists is a two-piece deal with similar, but distinct, functionality that goes hand in hand.
The Network Performance Monitor, as the name implies, monitors network performance and is going to be one of the Best Network Data Sniffers on the market if you want an overall view of what's going on in your network.
What this means, more plainly, is it pays mind to more of the pure motility of the network.
Transmission speeds and rates, packet transmission reliability, and even comes pre-configured with a wide variety of visual aids and sharp looking charts to make irregularities easier to spot.
Its counterpart, the Network Analyzer, again with a self-explanatory name, is more focused on the traffic itself.
While the Performance Monitor is focused more on the overall view of the network's performance, the Network Analyzer is paying a lot more attention to the network on a more granular level.
- Great interface that balances visualizations and key insights well
- Highly customizable reports, dashboards, and monitoring tools
- Uses simple QoS rules for quick traffic shaping
- Built with large networks in mind, can scale to 50,000 flows
- Available for both Linux and Windows
- Is a highly specialized suite of tools designed for network professionals, not designed for non-technical users
In particular this part of the program ferrets out the bandwidth hogs and anomalies, sorted by merit of users, protocols, or applications. Available for Windows environments only. You can start of with a 30-day free trial.
The SolarWinds Bandwidth Analyzer Pack is our top pick for a packet sniffer and network analyzer for traffic and data analysis because it presents all of the monitoring tools that you need for a network. This package incorporates a packet sniffer that is able to read the headers of packets to get detailed traffic information. It is also able to use the NetFlow protocol to gather network utilization information. Tools in the package enable you to implement traffic shaping measures to gain extra value from your network infrastructure.
Official Site: solarwinds.com/server-application-monitor/registration
OS: Windows Server
WireShark is relatively new tool in the broad scheme of network diagnostics, and it does a great job finding a middle ground between raw data and visual representations of that data.
It's simple, it's compatible, it's portable. It does what needs doing and it does it succinctly.
It's got a clean UI, plenty of options for filtering and sorting, and, best of all for some of the multi-platform folks, it jives happily on any of the big three in terms of OS.
Add to that the fact that it's open-source and a Free Sniffer and you've got a compelling tool to reach for when you need some quick diagnostics. Available for *NIX, Windows, and OSX environments.
- One of the most popular packet analyzer tools, with a massive community behind it
- Open-source project that adds new features and plugins
- Supports packet collection and analysis in the same program
- Completely free
- Has a steep learning curve, designed for network professionals
- Filtering can take time to learn, collects everything by default which can be overwhelming on large networks
Download & More Information: https://www.wireshark.org/
Tcpdump is something of an older tool and, to be frank, it looks like it. But there's a certain power in tools that are so cut and dry – it does what it needs to do, does it with as little a footprint as possible, and does it cleanly.
It may be harder for some professionals to weed through the stark tables of data, but in some environments, or on a machine barely running, minimal is best.
It's native and has its origins in the *NIX environment, but there are several Windows ports that do the job well.
It has all the functionality you'd want and need from a sniffer – capturing, recording, etc. – but it does lack a lot of the fancier capabilities of more robust software.
Tcpdump is often called for due to its sheer reliability and simplicity. Available for *NIX and Windows environments.
- Open-source tool backed by a large and dedicated community
- Simple syntax is easy to learn, especially for users who are comfortable with CLI tools
- Lightweight application, utilizes CLI for most commands
- Completely free
- Isn’t as user friendly as other options
- Uses a complicated query language for filtering
- Packet capture can only be read by applications that can read pcap files, not saved in plain text files
Download & More Information: http://www.tcpdump.org/
Kismet is more than just a packet sniffer and, in fact, delves into wide range of functionality.
Kismet even has the ability to sniff and analyze traffic of hidden networks or un-broadcasted SSIDs!
Tools like this can be strangely invaluable in the right circumstances when there's something unknown causing troubles and you can't just find it – Kismet can sniff it out, if it happens to be a rogue network or AP acting up nobody mentioned they setup not quite right.
As one can imagine by the nature of wireless networking it's a little more complex when it comes to sniffing, which is why a specialized tool like Kismet not only exists but is looked to frequently.
Kismet is an excellent go to if you've got a lot of wireless traffic and wireless devices and need a tool that's better suited to handling a wireless-heavy network. Available for *NIX, Windows Under Cygwin, and OSX environments.
- Available for Linux, Mac, and OpenBSD
- Can scan for Bluetooth signals along with other wireless protocols outside of Wifi
- Allows for real-time packet capture that can be forwarded to multiple team members
- Uses plugins for additional features keeps the base installation lightweight
- Free to use
- Designed for smaller networks
- Lacks enterprise-level reporting capabilities
- Reliant upon the open-source community for support and updates
Download & More Information: https://www.kismetwireless.net
EtherApe has a lot of the same sort of functionality that WireShark does and, to boot, it also boasts being both Open-Source and free of any cost!
What makes it different, though, is that it's far more graphically driven.
Whereas WireShark has you peering at lists of numbers and comparing network throughput in a more numerical sense, EtherApe takes the focus more to the visual and graphical realm.
Some people just plain prefer the visual approach, and EtherApe tends to take precedence over WireShark for those folks. Available for *NIX and OSX environments.
- Complete free
- Continuously updated
- Leverages simple but powerful data visualization to display information natively
- An open-source project
- Only available for Linux, Unix, and MacOS
Download & More Information: http://etherape.sourceforge.net/
7. Cain and Abel
This particular software has a bit of a curious name, and it belies the remarkable breadth of tasks the program can perform.
If your needs extend well beyond simple sniffing, then this may be the tool for you.
It can even perform limited password recovery, do dictionary attacks to retrieve lost credentials, peruse VOIP data on the network, analyze routing, and so much more.
This is a powerful tool that can really shine in those rare instances when you need to do a little search and recovery on a network.
Available for Windows environments only.
- A very popular cybersecurity tool with lots of documentation
- Can capture wireless traffic for analysis or packet injection
- Supports password cracking via brute force, hash calculation, and rainbow tables
- Can be used in legacy systems (Windows 9x)
- Is fairly dated, is better suited for password cracking than for packet sniffing
Download & More Information: http://www.oxid.it/cain.html
Network miner is another tool that does more than sniff and, arguably, would be better suited to ferreting out problematic users or systems on a network than overall diagnosis or monitoring as a whole.
Whereas other sniffers focus on the packets being sent back and forth, NetworkMiner is paying more mind to the ones doing the sending and receiving.
An excellent tool for finding problem machines or users.
Available for Windows environments only.
- Acts as a forensic tool as well as packet sniffer
- Can reconstruct files and packets over TCP streams
- Does not introduce any noise to the network while in use, good for avoiding cross-contamination
- Free to use, includes a paid version for more advanced features
- Offers a GUI rather than only CLI
- The interface is antiquated, and can be difficult to navigate at times
Download & More Information: http://www.netresec.com/?page=NetworkMiner
This software's name says it all – it's a lot like Kismet, but for the Mac environment. KisMAC! Simple as that.
These days Kismet has a Mac environment port, so it may seem redundant, but it's worth emphasizing that KisMAC actually has its own codebase and was not directly derivative from Kismet's.
Of particular note is that it offers several mapping and de-auth features on Mac that Kismet itself doesn't provide, and due to its unique codebase you may find it does the job better than Kismet itself at times. Available for OSX environments only.
- Designed to run natively on MacOS – great tool for a Windows alternative
- Designed to capture and replay wireless packets – great for wireless security
- Displays data within the program through heatmapping, which is also useful for identifying rogue APs
- Would like to see more supported hardware chipsets
Download & More Information: http://www.igrsoft.com/en/kismac2
Using Network Analyzers and Packet Sniffers will become a necessary tool when you have network issues of almost any kind – whether it's performance, dropped connections, or issues with network-based backups.
Just about anything that involves transmitting or receiving data on the network can often be fixed using some clues from the above software.
Packet sniffing is invaluable when you've got to really dig down beyond the top layer of a problem to get a better picture of what's happening, or what isn't happening and should be!