netsniff-ng is a free, open-source Linux network analyzer and toolkit for network development, debugging, analysis, auditing, and reconnaissance. It captures, analyzes, replays, and redirects network traffic using zero-copy packet mechanisms. Users can capture traffic live from the command line, apply packet filters, and analyze saved traces offline. It captures and reads pcap files, including tcpdump-capable formats with nanosecond resolution, Alexey Kuznetzov's pcap, and netsniff-ng pcap. Its dissector covers protocols and link types such as Ethernet, WLAN, ARP, VLAN, IPv4, IPv6, TCP, and UDP. The toolkit also includes trafgen, mausezahn, ifpps, curvetun, astraceroute, flowtop, and bpfc. It is licensed under GNU GPL version 2.0. The project marks mausezahn and curvetun experimental and advises against production use; it also makes no guarantee that the tools are free of bugs. Release verification instructions use Git tags and GPG signatures, and the project points users to a mailing list and online FAQ.
Who it is for
netsniff-ng suits Linux users who need command-line capture, packet filtering, or offline trace analysis. Its toolkit also covers network development, debugging, auditing, and reconnaissance.
What is good
- Free and open source under GNU GPL 2.0.
- Supports live capture and offline trace analysis.
- Reads several pcap formats.
- Includes low- and high-level packet filters.
What to know first
- Available for Linux only.
- Mausezahn and curvetun are experimental.
- The project gives no bug-free guarantee.
Verdict
netsniff-ng brings capture, filtering, protocol analysis, and trace replay into a Linux toolkit. Note that two utilities are marked experimental and the project does not guarantee bug-free tools.
netsniff-ng plans and pricing
All plansCompared on network packet analyzer software
- Free plan
- Yes
- Live capture
- Yes
- Capture file formats
- tcpdump-capable pcap; tcpdump-capable pcap with nanosecond resolution; Alexey Kuznetzov's pcap; netsniff-ng pcap



