Comparison of packet analyzers

The following tables compare general and technical information for several packet analyzer software utilities. Please see the individual products' articles for further information.

General information

Basic general information about the software—creator/company, license/price, etc.

Creator User interface Software license
Cain and Abel Massimiliano Montoro GUI Freeware
Capsa Free Edition Colasoft GUI Proprietary
Carnivore Federal Bureau of Investigation ? N/A
Clarified Analyzer Clarified Networks GUI Proprietary
Clusterpoint Network Traffic Surveillance System Clusterpoint web GUI Proprietary
CommView TamoSoft GUI Proprietary
dSniff Dug Song CLI BSD License
EtherApe Juan Toledo GUI GNU General Public License
Ettercap ALoR and NaGA Both GNU General Public License
justniffer The Justniffer team CLI GNU General Public License
Kismet Mike Kershaw (dragorn) CLI GNU General Public License
LANMeter Fluke Corporation handheld? ?
netsniff-ng Daniel Borkmann CLI GNU General Public License
ngrep Jordan Ritter CLI BSD-style
Microsoft Network Monitor Microsoft GUI Proprietary
Observer Network Instruments GUI Proprietary
OmniPeek (formerly AiroPeek, EtherPeek) WildPackets GUI Proprietary
SteelCentral Transaction Analyzer OPNET Technologies/Riverbed Technology GUI Proprietary
snoop Sun Microsystems CLI CDDL
tcpdump The Tcpdump team CLI BSD License
Wireshark (formerly Ethereal) The Wireshark team Both GNU General Public License
Xplico The Xplico team Both GNU General Public License

Operating system support

The utilities can run on these operating systems.

Client Microsoft Windows OS X Linux BSDs Solaris Other
Cain and Abel Yes No No No No No
Capsa Free Edition Yes No No No No No
Carnivore Yes No No No No No
Clarified Analyzer Yes Yes Yes No No ?
Clusterpoint Network Traffic
Surveillance System
Yes Yes Yes Yes No Any virtual-machine compatible OS
CommView Yes No No No No No
dSniff ? Yes Yes Yes Yes ?
EtherApe No Yes Yes Yes Yes ?
Ettercap Yes Yes Yes Yes Yes ?
justniffer No Yes Yes Yes Yes ?
Kismet Yes Yes Yes Yes ? ?
LANMeter No No No No No Fluke proprietary hardware
netsniff-ng No No Yes No No No
ngrep Yes Yes Yes Yes Yes AIX, BeOS, HP-UX, IRIX, Tru64 UNIX
Microsoft Network Monitor Yes No No No No No
Observer Yes No No No No No
OmniPeek (formerly AiroPeek, EtherPeek) Yes No No No No No
SteelCentral Transaction Analyzer Yes Version 3.5 capture agents on PowerPC only GUI, plus version 3.5 capture agents No Version 3.5 capture agents on SPARC only Version 3.5 capture agents on AIX and PA-RISC HP-UX only
snoop No No No No Yes No
tcpdump Yes (WinDump) Yes Yes Yes Yes AIX, HP-UX, IRIX, Tru64 UNIX
Wireshark (formerly Ethereal) Yes Yes Yes Yes Yes AIX, HP-UX, IRIX, Tru64 UNIX
Xplico No No Yes No No No