network
Network Monitor and Application Firewall for macOS.
The Little Snitch Network Monitor shows you where your Mac connects to on the Internet. You decide what you want to allow or deny.
This tool automates Cisco Catalyst SD-WAN lab deployment inside Cisco Modeling Labs (CML).
Command-line utility for limiting an adapter's bandwidth.
Wonder Shaper is a script that allows the user to limit the bandwidth of one or more network adapters. It does so by using iproute's tc command, but greatly simplifies its operation.
Netronome is a modern network speed testing and monitoring tool built with Go and React.
A complete network performance monitoring solution with distributed agents, real-time metrics, and beautiful visualizations.
Related contents:
open source boot firmware. iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features
See and Manage Open Ports on Mac.
When you're working on multiple projects at the same time, it's easy to lose track of what's running. A database here, a dev server there, an API you forgot was still open... before long, your ports become a mess.
Portero gives you a clear view of everything running on your machine, so you always know what's using each port, can stop what you don't need, and get back to building instead of debugging port conflicts.
Visual Homelab Mapper & Monitor.
Self-hosted visual canvas for your network. Drag, document and watch every device live — now native in Home Assistant.
A lightweight, browser-based tool for mapping Ethernet connections. Create switches, patch panels, wall ports, routers, etc. Assign ports, connect them, and visualise how your network is wired.
TraceWrangler is a network capture file toolkit running on Windows (or on Linux, using WINE) that supports PCAP as well as the new PCAPng file format, which is now the standard file format used by Wireshark. The most prominent use case for TraceWrangler is the easy sanitization and anonymization of PCAP and PCAPng files (sometimes called "trace files", "capture files" or "packet captures"), removing or replacing sensitive data while being easy to use.
Automatically discover and visually document network topology.
NetVisor scans your network, identifies hosts and services, and generates an interactive visualization showing how everything connects, letting you easily create and maintain network documentation.
Related contents:
Any File. Any Device. Cross-platform Network File Transfer Application. A cross-platform network file transfer application designed to make transferring any file to any device as painless as possible.
Thread is a low-power and low-latency wireless mesh networking protocol built using open and proven standards. Thread solves the complexities of the IoT, addressing challenges such as interoperability, range, security, energy, and reliability. Thread networks have no single point of failure and include the ability to self-heal.
vTunnel is a tool that proxies IP traffic between guest and host networks by using the VSOCK protocol.
This project provides the ability to tunnel IP traffic through the hypervisor so that connections can be proxied into or out of virtual machines.
Related contents:
Bash script to automate setup of Linux router useful for IoT device traffic analysis and SSL mitm
The ZMap Project is a collection of open source measurement tools for performing large-scale studies of the hosts and services that compose the public Internet.
ZMap is a fast single packet network scanner designed for Internet-wide network surveys.
Related contents:
Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, and case management. It also includes other tools such as Playbook, osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
SmokePing is a deluxe latency measurement tool. It can measure, store and display latency, latency distribution and packet loss. SmokePing uses RRDtool to maintain a longterm data-store and to draw pretty graphs, giving up to the minute information on the state of each network connection.
WIFI / LAN intruder detector. Check the devices connected and alert you with unknown devices. It also warns of the disconnection of "always connected" devices
View the HTTP and HTTPS requests made by any linux program by running httptap -- <command>.
Lightweight network IP scanner. Can be used to notify about new hosts and monitor host online/offline history
The Swiss Army knife for 802.11, BLE, IPv4 and IPv6 networks reconnaissance and MITM attacks. bettercap is a powerful, easily extensible and portable framework written in Go which aims to offer to security researchers, red teamers and reverse engineers an easy to use, all-in-one solution with all the features they might possibly need for performing reconnaissance and attacking WiFi networks, Bluetooth Low Energy devices, wireless HID devices and Ethernet networks.
Open Network Linux (ONL) is an open-source, foundational platform software layer for next-generation, modular NOS architecture on open networking hardware.
Open RAN is intelligent Radio Access Network(RAN) integrated with general purpose platforms with open interface between software definced funtions. Open RAN ecosystem enables enormous flexibility and interoperability with a complete openess to multi-vendor deployments. Open RAN architecture is designed for building virtualized RAN with AI powered control, which is the key to tame the 5G/6G complexity.
A Dumb WhoIs.
A simple web application for looking up WHOIS, IP, and ASN information using free APIs. The application automatically detects the type of query and provides formatted results with a clean, modern UI that supports both light and dark modes.
Accelerating your DevOps with pyATS & Genie.
pyATS is an end-to-end DevOps automation ecosystem. Agnostic by design, pyATS enable network engineers to automate their day-to-day DevOps activities, perform stateful validation of their device operational status, build a safety-net of scalable, data-driven and reusable tests around their network, and visualize everything in a modern, easy to use dashboard.
Real Intelligence Threat Analytics (R-I-T-A) is an open-source framework for detecting command and control communication through network traffic analysis. The RITA framework ingests Zeek logs or PCAPs converted to Zeek logs for analysis.
A lightweight mac status bar development port monitor.
A lightweight cross-platform status bar app that monitors and manages development processes running on configurable ports. The app provides real-time process detection and allows you to kill individual processes or all processes at once.
Related contents:
Terminal bandwidth utilization tool.
This is a CLI utility for displaying current network utilization by process, connection and remote IP/hostname
eBPF implementation that runs on top of Windows.
eBPF is a well-known technology for providing programmability and agility, especially for extending an OS kernel, for use cases such as DoS protection and observability. This project is a work-in-progress that allows existing eBPF toolchains and APIs familiar in the Linux ecosystem to be used on top of Windows. That is, this project takes existing eBPF projects as submodules and adds the layer in between to make them run on top of Windows.
WiFiman is here to save your network from sluggish surfing, endless buffering, and congested data channels.
- Detect available WiFi networks and Bluetooth LE devices instantly.
- Scan network subnets for additional details on detected devices, such as Bonjour, SNMP, NetBIOS, and Ubiquiti discovery protocols.
- Connect to your UniFi network remotely via Teleport - a free, zero-configuration VPN.
Like nmap for mapping wifi networks you're not connected to. Maps and tracks wifi networks and devices through raw 802.11 monitoring.
Mesh network sidecars for NixOS Services.
meshSidecar provides a flexible way to integrate mesh networking capabilities with NixOS services. It allows services to participate in mesh networks without requiring direct modification of the service itself.
Related contents:
Making the Network Visible.
sFlow® is an industry standard technology for monitoring high speed switched networks. It gives complete visibility into the use of networks enabling performance optimization, accounting/billing for usage, and defense against security threats.
flannel is a network fabric for containers, designed for Kubernetes. Flannel is a simple and easy way to configure a layer 3 network fabric designed for Kubernetes.
Flannel is responsible for providing a layer 3 IPv4 network between multiple nodes in a cluster. Flannel does not control how containers are networked to the host, only how the traffic is transported between hosts. However, flannel does provide a CNI plugin for Kubernetes and a guidance on integrating with Docker.
Related contents:
NetBox - The Premier Network Source of Truth.
NetBox is the source of truth for everything on your network, from physical components like power systems and cabling to virtual assets like IP addresses and VLANs. Network automation and observability tools depend on NetBox’s authoritative data to roll out configurations, monitor changes, and accelerate operations across the enterprise.
Network & IT Training Courses Network Walks offers a wide range of IT & Network Training Courses spanning from Cisco CCNA, CCNP, CCIE till Huawei HCNA, HCNP...
Programming Protocol-independent Packet Processors (P4) is a domain-specific language for network devices, specifying how data plane devices (switches, NICs, routers, filters, etc.) process packets.
An open-source router that you can manage from a browser, a terminal CLI, or directly from your AI agents (Claude Desktop, OpenCode, Cline, GitHub Copilot). Born as a router-on-a-stick for the Le Potato (or any ARM SBC running Armbian/Ubuntu), it also installs and runs on x86 — mini-PCs, thin clients, and VMs — where it adapts the network topology to however many NICs the box actually has. Manages 802.1Q VLANs, DHCP, DNS, firewall rules, static routes, and VPN (Tailscale, WireGuard, Nebula) — all from a browser, over SSH, or through a standard MCP server. Still a potato at heart either way.
Related contents:
Artica V4 is an appliance based on Debian 10 Operating system. Your can install it on the Hardware or Virtual Machine of your choice and get a Web Gateway appliance within minutes.
VyOS is a fully open-source, enterprise-grade router platform. Being open-source and community-driven is not a liability for us, not an early stage gimmick we want to shed—it’s our distinctive advantage. VyOS started as a community fork of a discontinued Vyatta Core project in 2013, with a promise to live up to free and open-source software values. We kept the promise and turned VyOS into a successful, self-funded project.
OpenZiti is a free and open source project focused on bringing zero trust networking principles directly into any application. The project provides all the pieces required to implement a zero trust overlay network and provides all the tools necessary to integrate zero trust into your existing solutions. The OpenZiti project believes the principles of zero trust shouldn't stop at your network, those ideas belong in your application.
Lightweight Network Scanner.
LAN Orangutan is a lightweight network scanner with persistent device labeling, multi-network support, and Tailscale integration. Built by 291 Group.
A modern load testing framework.
An open source load testing tool. Define user behaviour with Python code, and swarm your system with millions of simultaneous users.
Related contents:
PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a captive-portal for registration and remediation, centralized wired and wireless management, powerful BYOD management options, 802.1X support, layer-2 isolation of problematic devices; PacketFence can be used to effectively secure networks small to very large heterogeneous networks.
A self-hosted, real-time port monitoring and discovery tool.
By auto-discovering services on your systems, portracker provides a live, accurate map of your network. It helps eliminate manual tracking in spreadsheets and prevents deployment failures caused by port conflicts.
Related contents:
Web Dashboard and Reporting. A Web Dashbord for Nmap XML Report.
RDAP command line client. OpenRDAP is a command line client for the Registration Data Access Protocol, written in Go.
RDAP is a replacement for WHOIS, which provides domain name & IP address registration information in JSON format over HTTP.
I2P is an anonymous network, exposing a simple layer that applications can use to anonymously and securely send messages to each other. The network itself is strictly message based (a la IP), but there is a library available to allow reliable streaming communication on top of it (a la TCP). All communication is end to end encrypted (in total there are four layers of encryption used when sending a message), and even the end points ("destinations") are cryptographic identifiers (essentially a pair of public keys).
WoLi WebGUI is an extremely lightweight (under 8MB) container image for sending WoL Magic Packets easily to a public WoL proxy of your choice.
RouterOS is the operating system of RouterBOARD
It can also be installed on a PC and will turn it into a router with all the necessary features - routing, firewall, bandwidth management, wireless access point, backhaul link, hotspot gateway, VPN server and more.
Cloud native networking and network security.
Calico is a single platform for networking, network security, and observability for any Kubernetes distribution in the cloud, on-premises, or at the edge. Whether you're just starting with Kubernetes or operating at scale, Calico's open source, enterprise, and cloud editions provide the networking, security, and observability you need.
Related contents:
- Kubernetes Is Powerful, But Not Secure (at least not by default) @ Tigera.
- What’s New in Calico v3.31: eBPF, NFTables, and More @ Tigera.
- An In-Depth Look at Istio Ambient Mode with Calico @ Tigera.
- Save the Address, Save the Cloud: A Hands-on KubeVirt Live Migration Workshop @ Tigera.
- Mon homelab, ou comment j'essaie de rester dans la game @ Cyril Beaufrere's LinkedIn :fr:.
The above text dump is a traceroute. This particular one depicts your journey — or at least your packets’ journey — traversing the networks of the Internet to reach the server hosting this website. The preceeding traceroute and all future green-glowing text was generated on the fly, specially for you, during the loading of this website.
Another Looking-glass Server.
NetMirror is a modern, feature-rich looking-glass server with a beautiful web interface for network diagnostics and performance testing.
Easy, direct connections that punch through NATs & stay connected as network conditions change.
Dumb pipes are Iroh Connections. The dumbpipe tool is a 200-line wrapper around the iroh rust crate. You can use the iroh Endpoint to create a connection to use as a dumb pipe in your own app.
Optimized Node Monitoring for Network Analysis.
SONAR is designed to simplify network configuration audits in critical environments. With a clean interface and a robust architecture, it enables any personnel — even non-technical — to understand and document network flows independently.
Network recon framework.
IVRE is an open-source framework for network recon. It relies on open-source well-known tools (Nmap, Masscan, ZGrab2, ZDNS and Zeek (Bro)) to gather data (network intelligence), stores it in a database (MongoDB is the recommended backend), and provides tools to analyze it.
Networking component for interconnecting Pods and Services across Kubernetes clusters.
Submariner enables direct networking between Pods and Services in different Kubernetes clusters, either on-premises or in the cloud.
Lighthouse provides DNS discovery to Kubernetes clusters connected by Submariner in multi-cluster environments.
Open Source NAC.
PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a captive-portal for registration and remediation, centralized wired, wireless and VPN management, industry-leading BYOD capabilities, 802.1X and RBAC support, integrated network anomaly detection with layer-2 isolation of problematic devices; PacketFence can be used to effectively secure small to very large heterogeneous networks.
Quickly and easily design network layouts. Split and join subnets, add notes and color, then collaborate with others by sharing a custom link to your design.
Enter the network you wish to subnet and use the Split/Join buttons on the right to start designing!
Real-time router/firewall traffic visualizer TUI for Linux (interfaces, conntrack, firewall drops).
Where a host monitor shows your machine's own traffic, fwtop is built for the box that sits between networks — an edge router or firewall. It reads kernel state directly (near-zero overhead, no packet capture) to show per-interface throughput (split into WAN/LAN zones), the live connection-tracking table (including NAT), and firewall rule counters with a smoke→fire drops heatmap that surfaces spikes at a glance.
Related contents: