Ross ROSS = Recommend OSS · open-source software intelligence for agents

deepfence/PacketStreamer

:star: :star: Distributed tcpdump for cloud native environments :star: :star: observed · 2026-08-28

github.com/deepfence/PacketStreamer · Go · Apache-2.0 (permissive) · archived observed · 2026-08-28

Health v2 · maintenance only

10/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: archived

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1622
  • days_rel: n/a
  • days_push: 793
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1929 stars · 244 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

PacketStreamer is a distributed, high-performance remote packet capture tool that runs lightweight sensors on target hosts to stream filtered network traffic to a central receiver. The receiver aggregates streams from multiple sensors into pcap files that can be fed to tools like Zeek, Wireshark, or Suricata for analysis.

Use cases

  • capture packets from multiple remote servers into a central pcap file
  • collect network traffic from Kubernetes nodes for forensic analysis
  • stream live network traffic to Zeek, Suricata, or Wireshark
  • run lightweight tcpdump-like capture across cloud workloads
  • gather raw packets on demand from VMs and AWS Fargate tasks
  • apply BPF filters and stream filtered traffic with TLS encryption
  • centralize packet capture for security monitoring and incident response

When to choose

  • you need distributed packet capture across many hosts with a central collection point
  • you want minimal performance overhead on the machines being monitored
  • you need to feed raw traffic into existing analysis tools like Zeek or Suricata
  • you are running cloud native workloads on Kubernetes, Docker, or Fargate
  • you need encrypted or compressed traffic streams from remote sensors

When to avoid

  • you only need packet capture on a single local machine
  • you want built-in protocol analysis or alerting rather than raw capture
  • you need deep packet inspection or IDS functionality out of the box
  • your environment is not Linux or Windows based

Facets

cli-tool · maturity active

networking monitoring security tracing analytics security networking cloud-computing self-hosted developer-tools windows cloud self-hosted go cli packet-capture tcpdump pcap distributed-tracing network-forensics traffic-streaming bpf-filters tls-encryption suricata zeek wireshark snort sensor-receiver-architecture kubernetes aws-fargate forensics soc observability packet-sniffer remote-capture devops containers linux docker

1 source

Member repositories

RepositoryRoleHealth v2
deepfence/PacketStreamermain10

For agents

markdown · JSON · MCP: product_card(name="deepfence/PacketStreamer")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem