Skip to content
OpenCatalogcurated by FLOSSK
Security & Privacy

Arkime

Large-scale full packet capture, indexing, and search (SPIE) with a web UI—successor to the Moloch lineage for NSM teams.

Why it is included

Widely deployed open stack for retaining and hunting PCAP without proprietary NDR appliances.

Best for

SOCs needing session reconstruction, PCAP export, and analyst search at ISP/enterprise volume.

Strengths

  • PCAP lifecycle
  • Scalable capture
  • Strong community

Limitations

  • Storage and ES ops are the main cost; privacy/legal retention policies required

Good alternatives

Zeek logs only · Commercial NDR · Stenographer

Related tools