traffic66
NetFlow / sFlow / IPFIXWindows · Linux · macOS

Flow analytics in a single program

traffic66 collects flow exports from switches, routers and firewalls, and shows who uses the bandwidth, where the traffic goes, and whether the numbers match the devices' own interface counters. One executable, no database to install, works offline.

Overview: open findings, bandwidth by application compared with the same time yesterday, top clients and services

What it does

Collect

sFlow v5, NetFlow v5 and v9, IPFIX on any UDP port, or local capture from a network card or mirror port.

Check the numbers

Flow estimates next to the interface counters (sFlow or SNMP), with the likely cause when they differ.

See who and where

Top 66 conversations, ring charts of clients and servers, flow paths, countries and networks on a world map.

Find attacks

Scans, password guessing, lateral movement, unusual uploads, floods and threat lists, also through sampling.

Analyse captures

traffic66 capture.pcap opens a packet capture with the same pages, kept apart from the live data.

Read it your way

Web UI and terminal UI in 13 languages, five colour themes, links that open exactly the same view.

Interface check: the flow estimate of each interface next to the device counter
Interface check: flows against the device counters, worst first.
Findings: every step of an attack, found through 1:4096 sFlow sampling
Findings: an attack found step by step through 1:4096 sFlow sampling.

Latest from the blog

Licence

Source available under the PolyForm Noncommercial License 1.0.0 with the Traffic66 Additional Use Grant: free for evaluation and for organizations under 100 people; larger organizations register after 30 days of production use. Nothing is ever switched off. Read the terms.