{"adoption": {"forks": 168, "observed_at": "2026-08-28T04:05:39.004411+00:00", "stars": 1805}, "canonical_url": "https://ross.abutalabs.com/products/netcap", "card": {"archived": false, "artifact_type": "framework", "description": "A framework for secure and scalable network traffic analysis - https://netcap.io", "domain": ["security", "networking", "monitoring", "analytics", "machine-learning"], "enriched": true, "function": ["networking", "security", "monitoring", "analytics", "machine-learning", "data-science"], "health_score": 98, "homepage": null, "language": "Go", "license": "GPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["dreadl0ck/netcap"], "name": "dreadl0ck/netcap", "platform": ["windows", "cross-platform", "cli", "go"], "pushed_at": "2026-08-26T13:59:17+00:00", "repo": "dreadl0ck/netcap", "stars": 1805, "tags": ["network-traffic-analysis", "packet-capture", "audit-records", "protocol-buffers", "pcap", "forensics", "intrusion-detection", "ja4-fingerprinting", "yara", "stream-reassembly", "linux", "macos"], "topics": ["network", "security", "monitoring", "detection", "analysis"], "urls": [], "use_cases": ["analyze pcap files and extract structured audit records", "monitor network traffic for security threats", "fingerprint TLS, HTTP, and SSH clients with JA4", "detect malware in transferred files with YARA rules", "reconstruct TCP and UDP streams from captures", "feed network features into machine learning models", "inspect industrial control system protocols like Modbus and S7Comm", "visualize protocol hierarchy and host communication"], "what_it_is": "Netcap is a Go framework that converts network packets into structured, type-safe Protocol Buffer audit records for security monitoring, forensics, and machine learning. It ships as a single binary with 83 packet decoders, 40+ stream decoders, 141+ audit record types, and a built-in web UI for visualization and analysis.", "when_to_avoid": ["you only need simple packet capture without structured analysis", "you require a lightweight passive sniffer with minimal resource usage", "you need a GUI-first tool rather than a CLI/service framework", "your license requirements are incompatible with GPL-3.0"], "when_to_choose": ["you need scalable, concurrent full-packet analysis on Linux, macOS, or Windows", "you want structured, machine-readable output instead of ad-hoc pcap parsing", "you need broad protocol coverage including industrial protocols", "you are building security monitoring, forensics, or ML pipelines on network data"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/netcap", "repo": "dreadl0ck/netcap", "role": "main", "score": 92}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.004411+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:21:33.475421+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1d2f4d883a7a58486a875dd603076c3a1d310a3fc1de20e756c29e9a0ea9bb26", "fetched_at": "2026-08-28T04:05:39.004411+00:00", "kind": "readme", "missing": false, "url": "https://github.com/dreadl0ck/netcap"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.004411+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:21:33.475421+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1d2f4d883a7a58486a875dd603076c3a1d310a3fc1de20e756c29e9a0ea9bb26", "fetched_at": "2026-08-28T04:05:39.004411+00:00", "kind": "readme", "missing": false, "url": "https://github.com/dreadl0ck/netcap"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:21:33.475421+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1d2f4d883a7a58486a875dd603076c3a1d310a3fc1de20e756c29e9a0ea9bb26", "fetched_at": "2026-08-28T04:05:39.004411+00:00", "kind": "readme", "missing": false, "url": "https://github.com/dreadl0ck/netcap"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.004411+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.004411+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.004411+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:21:33.475421+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1d2f4d883a7a58486a875dd603076c3a1d310a3fc1de20e756c29e9a0ea9bb26", "fetched_at": "2026-08-28T04:05:39.004411+00:00", "kind": "readme", "missing": false, "url": "https://github.com/dreadl0ck/netcap"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.004411+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.004411+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:21:33.475421+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1d2f4d883a7a58486a875dd603076c3a1d310a3fc1de20e756c29e9a0ea9bb26", "fetched_at": "2026-08-28T04:05:39.004411+00:00", "kind": "readme", "missing": false, "url": "https://github.com/dreadl0ck/netcap"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.004411+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.004411+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.004411+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:21:33.475421+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1d2f4d883a7a58486a875dd603076c3a1d310a3fc1de20e756c29e9a0ea9bb26", "fetched_at": "2026-08-28T04:05:39.004411+00:00", "kind": "readme", "missing": false, "url": "https://github.com/dreadl0ck/netcap"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.004411+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:39.004411+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:21:33.475421+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1d2f4d883a7a58486a875dd603076c3a1d310a3fc1de20e756c29e9a0ea9bb26", "fetched_at": "2026-08-28T04:05:39.004411+00:00", "kind": "readme", "missing": false, "url": "https://github.com/dreadl0ck/netcap"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:21:33.475421+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1d2f4d883a7a58486a875dd603076c3a1d310a3fc1de20e756c29e9a0ea9bb26", "fetched_at": "2026-08-28T04:05:39.004411+00:00", "kind": "readme", "missing": false, "url": "https://github.com/dreadl0ck/netcap"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:21:33.475421+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1d2f4d883a7a58486a875dd603076c3a1d310a3fc1de20e756c29e9a0ea9bb26", "fetched_at": "2026-08-28T04:05:39.004411+00:00", "kind": "readme", "missing": false, "url": "https://github.com/dreadl0ck/netcap"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:21:33.475421+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "1d2f4d883a7a58486a875dd603076c3a1d310a3fc1de20e756c29e9a0ea9bb26", "fetched_at": "2026-08-28T04:05:39.004411+00:00", "kind": "readme", "missing": false, "url": "https://github.com/dreadl0ck/netcap"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 99, "longevity": 100, "rhythm": 78}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2835, "days_push": 7, "days_rel": 146, "gap_med": 0, "n_releases_24m": 8}, "score": 92, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}