Every IT professional, from companies big or small, knows the value of data. Troubleshooting is always an act that is half instinct and half data – and Packet Sniffing is where the data comes in. A Packet Sniffer is the tool that helps you figure out if packets are being sent, received, and arriving safely on your network, but they can also do so much more!
Below is a list of some of the Best Network Analyzers and Sniffers and some of the features that they have built in for you to extract network information and data. They all tend to have the same sort of functionality – you can view packets being sent and received on some level or another, but many of the tools have certain nuances that allow them to shine in certain situations or network environments; the trick is knowing which one! Ultimately packet sniffing is the go to tool when you've got a network issue that you can't quite isolate to a single machine or protocol and it's time to start digging deep.
There's almost too many choices in this category of software. Some of them are a bit ‘old-school'; they're grounded in terminal font and command-prompt interfaces and aren't that user friendly at first glance. Others are flashy much more geared towards a visual audience with easy installation, or portable executables, and plenty of graphs and tables. They also range from free to quite expensive for corporate licensing!
To help make sense of the choices, here's a list of the Top 8 Free Sniffers, along with a few highlights of each:
Solarwinds Bandwidth Analyzer 2-Pack – Free Download
This particular software is a two-piece deal with similar, but distinct, functionality that goes hand in hand.
The Network Performance Monitor, as the name implies, monitors network performance and is going to be one of the Best Network Data Sniffers on the market if you want an overall view of what's going on in your network. What this means, more plainly, is it pays mind to more of the pure motility of the network. Transmission speeds and rates, packet transmission reliability, and even comes pre-configured with a wide variety of visual aids and sharp looking charts to make irregularities easier to spot.
Its counterpart, the Network Analyzer, again with a self-explanatory name, is more focused on the traffic itself. While the Performance Monitor is focused more on the overall view of the network's performance, the Network Analyzer is paying a lot more attention to the network on a more granular level.
In particular this part of the program ferrets out the bandwidth hogs and anomalies, sorted by merit of users, protocols, or applications. Available for Windows environments only.
WireShark is relatively new tool in the broad scheme of network diagnostics, and it does a great job finding a middle ground between raw data and visual representations of that data. It's simple, it's compatible, it's portable. It does what needs doing and it does it succinctly.
It's got a clean UI, plenty of options for filtering and sorting, and, best of all for some of the multi-platform folks, it jives happily on any of the big three in terms of OS. Add to that the fact that it's open-source and a Free Sniffer and you've got a compelling tool to reach for when you need some quick diagnostics. Available for *NIX, Windows, and OSX environments.
Tcpdump is something of an older tool and, to be frank, it looks like it. But there's a certain power in tools that are so cut and dry – it does what it needs to do, does it with as little a footprint as possible, and does it cleanly. It may be harder for some professionals to weed through the stark tables of data, but in some environments, or on a machine barely running, minimal is best.
It's native and has its origins in the *NIX environment, but there are several Windows ports that do the job well. It has all the functionality you'd want and need from a sniffer – capturing, recording, etc. – but it does lack a lot of the fancier capabilities of more robust software. Tcpdump is often called for due to its sheer reliability and simplicity. Available for *NIX and Windows environments.
Kismet is more than just a packet sniffer and, in fact, delves into wide range of functionality. Kismet even has the ability to sniff and analyze traffic of hidden networks or un-broadcasted SSIDs! Tools like this can be strangely invaluable in the right circumstances when there's something unknown causing troubles and you can't just find it – Kismet can sniff it out, if it happens to be a rogue network or AP acting up nobody mentioned they setup not quite right.
As one can imagine by the nature of wireless networking it's a little more complex when it comes to sniffing, which is why a specialized tool like Kismet not only exists but is looked to frequently. Kismet is an excellent go to if you've got a lot of wireless traffic and wireless devices and need a tool that's better suited to handling a wireless-heavy network. Available for *NIX, Windows Under Cygwin, and OSX environments.
EtherApe has a lot of the same sort of functionality that WireShark does and, to boot, it also boasts being both Open-Source and free of any cost! What makes it different, though, is that it's far more graphically driven. Whereas WireShark has you peering at lists of numbers and comparing throughput in a more numerical sense, EtherApe takes the focus more to the visual and graphical realm. Some people just plain prefer the visual approach, and EtherApe tends to take precedence over WireShark for those folks. Available for *NIX and OSX environments.
Cain and Abel
This particular software has a bit of a curious name, and it belies the remarkable breadth of tasks the program can perform. If your needs extend well beyond simple sniffing, then this may be the tool for you. It can even perform limited password recovery, do dictionary attacks to retrieve lost credentials, peruse VOIP data on the network, analyze routing, and so much more. This is a powerful tool that can really shine in those rare instances when you need to do a little search and recovery on a network. Available for Windows environments only.
Network miner is another tool that does more than sniff and, arguably, would be better suited to ferreting out problematic users or systems on a network than overall diagnosis or monitoring as a whole. Whereas other sniffers focus on the packets being sent back and forth, NetworkMiner is paying more mind to the ones doing the sending and receiving. An excellent tool for finding problem machines or users. Available for Windows environments only.
This software's name says it all – it's a lot like Kismet, but for the Mac environment. KisMAC! Simple as that. These days Kismet has a Mac environment port, so it may seem redundant, but it's worth emphasizing that KisMAC actually has its own codebase and was not directly derivative from Kismet's. Of particular note is that it offers several mapping and de-auth features on Mac that Kismet itself doesn't provide, and due to its unique codebase you may find it does the job better than Kismet itself at times. Available for OSX environments only.
Using Network Analyzers and Packet Sniffers will become a necessary tool when you have network issues of almost any kind – whether it's performance, dropped connections, or issues with network-based backups. Just about anything that involves transmitting or receiving data on the network can often be fixed using some clues from the above software.
Packet sniffing is invaluable when you've got to really dig down beyond the top layer of a problem to get a better picture of what's happening, or what isn't happening and should be!