// the find
dreadl0ck/netcap
A framework for secure and scalable network traffic analysis - https://netcap.io
Netcap converts live interface traffic or PCAP files into typed Protocol Buffer audit records, one structured record per protocol event, so analysis runs over data instead of re-parsing captures. It is aimed at security engineers, forensic analysts, and anyone building ML features from network traffic. It ships as a single Go binary with an optional web UI and a YAML detection rule engine.
The Protobuf records are typed per protocol, so downstream code gets a schema instead of a CSV it has to re-parse. That design choice is what makes the rest of the project usable for anything beyond eyeballing output. The nodpi build tag and the opt-in Hyperscan path are real build-time knobs: you can drop the nDPI C dependencies or add Vectorscan without changing the default build. The detection engine has concrete primitives, including source-to-distinct-destination fan-out counting and time-of-day helpers, and the S7comm hunt is mapped to a named CISA advisory, which you can check against the advisory. Distributed capture is split into an agent and a collector with encrypted transport, which is the part most single-host tools skip.
Breadth is the main risk. The README claims 83 packet decoders, 40+ stream decoders, 141 record types, and industrial protocols, but it gives no accuracy or coverage numbers, and the only performance figures are self-reported Hyperscan multipliers. Before you depend on any decoder, test it against your own traffic. The license is GPLv3, so you cannot ship it inside a closed-source product. JA4+ support is available only in opt-in source builds under the FoxIO license, which is easy to miss if you package binaries. Building needs libpcap, CGO for the DPI and Hyperscan paths, and Go 1.25. The committed frontend/dist directory contains only a placeholder file, so a plain go build probably gives you a binary without the web UI until you run the frontend build script. That UI is a large React and ECharts codebase bolted onto a capture tool, which adds a second project's worth of maintenance.