{"repo":"NotYuSheng/TracePcap","free":true,"listed":false,"github":"https://github.com/NotYuSheng/TracePcap","clone":"git clone https://github.com/NotYuSheng/TracePcap.git","description":"Self-hosted PCAP analysis platform with LLM-powered incident triage, signature-based threat detection, and AI-generated incident narratives. Features network change monitoring across captures, deep packet inspection via nDPI, and automated Wireshark filter generation. Runs fully offline with local LLMs (Ollama, LM Studio).","language":"Java","stars":37,"topics":["cybersecurity","llm","network-forensics","network-monitoring","packet-analysis","pcap","pcap-analyzer","protocol-analysis","wireshark","blue-team"],"license":"MIT","category":"security-tools","readme_excerpt":"TracePcap Black-box network analysis from PCAP captures — no prior knowledge of the network required Features • Quick Start • Usage • Documentation --- TracePcap is a self-hosted PCAP analysis workbench designed for situations where you work from the traffic itself — with no prior knowledge of the network. Upload one or more PCAP captures and the tool characterises devices, maps topology, reconstructs sessions, tracks changes over time, and generates AI-powered narratives — all derived purely from observed traffic. This makes it well-suited for: - Network audits and third-party assessments — handed a PCAP with no documentation; build the picture from scratch - Incident response — incomplete network records; reconstruct what happened from packet evidence - Penetration test reconnaissance — map an unknown or scarcely-documented network from captured traffic - Research and education — explore any capture without needing context about the environment Features Feature Description --------- ------------- PCAP Upload & Management Upload and manage PCAP/PCAPNG/CAP files (upload limit derived from APP MEMORY MB , 512MB by default) with MinIO object storage; duplicate detection and configurable upload limits Network Visualization Interactive network topology using Sigma.js (WebGL) + graphology with ForceAtlas2 / ELK layouts, a rich filter panel (IP, port, device type, protocol, risk), fullscreen toggle, layout controls, and clickable node detail panels nDPI Security Detection Deep pack","default_branch":null,"files":null,"tree":[],"storefront":"/r/NotYuSheng","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/NotYuSheng/TracePcap/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}