FlowCarp
FlowCarp identifies protocols in network traffic based on behaviour rather than port numbers.
It reads PCAP files and detects the actual application-layer protocols in use, exposing services running on non-standard ports.

More from NETRESEC
NetworkMiner
Network forensic analysis tool that parses PCAP files and reconstructs hosts, files, sessions, and credentials.
PolarProxy
Transparent TLS-decrypting proxy that intercepts encrypted malware traffic and saves it as decrypted PCAP.
CapLoader
Handle large PCAP datasets fast — view traffic as TCP/UDP flows, filter, and export to other tools.
PacketCache
Free Windows service that continuously buffers captured packets in memory for retrospective analysis.
RawCap
Tiny command-line sniffer for Windows that needs no drivers and can capture localhost traffic.
TrimPCAP
Open-source tool that shrinks PCAP files by over 90% to enable longer traffic retention.
findject
Open-source script that detects injected TCP packets and Man-on-the-Side attacks in HTTP sessions.
SplitCap
Command-line tool that splits large PCAP files by IP, session, or host for faster filtering.