{"repo":"dreadl0ck/netcap","free":true,"listed":false,"github":"https://github.com/dreadl0ck/netcap","clone":"git clone https://github.com/dreadl0ck/netcap.git","description":"A framework for secure and scalable network traffic analysis - https://netcap.io","language":"Go","stars":1803,"topics":["network","security","monitoring","detection","analysis"],"license":"GPL-3.0","category":"analytics","readme_excerpt":"Netcap (NETwork CAPture) converts network packets into structured, type-safe Protocol Buffer audit records — designed for security monitoring, forensic analysis, and machine learning. A single Go binary with 83 packet decoders, 40+ stream decoders, and 141+ audit record types, backed by a concurrent architecture and a built-in web UI. Protocol hierarchy visualization in the Netcap web UI — more screenshots Features Protocol Analysis - 83 packet-layer decoders — Ethernet, IPv4/6, TCP, UDP, DNS, DHCP, ARP, TLS ClientHello/ServerHello, ICMP, NTP, SIP, OSPF, BGP, MPLS, GRE, VXLAN, 802.11, and many more - 40+ stream decoders — TLS, SSH, HTTP/2, QUIC, SMB, FTP, SMTP, POP3, IMAP, IRC, Kerberos, DCERPC, and more - Industrial protocols — Modbus, S7Comm, DNP3, OPC-UA, PROFINET, BACnet, CIP, IEC 62351 - Full TCP/UDP stream reassembly with configurable limits Web UI Built-in React (Vite + TypeScript) dashboard in service mode with interactive visualizations: - Sankey diagrams, treemaps, 3D scatter plots, geo maps, host communication graphs - Record browsing with JSON/UI views and field-level filtering - Protocol statistics, connection analysis, host profiling, alert management See the Gallery for screenshots. Security Analysis - JA4 fingerprinting — JA4, JA4S, JA4H, JA4SSH, JA4X for TLS, HTTP, SSH, and X.509 classification - YARA rules — file scanning with compiled yara-x rules for malware detection - Magika AI — Google's AI-based file type classification on extracted files - Credential ","default_branch":null,"files":null,"tree":[],"storefront":"/r/dreadl0ck","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dreadl0ck/netcap/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}