Skip to content

Ettercap

Comprehensive suite for man-in-the-middle attacks, network sniffing and traffic interception.

Self-hostedNot yet verified
Report issue
MIT★ 3000Source project only — not browser-runnable

External Tool

This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.

Browse security tools →

What's next with Ettercap?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Ettercap?

Ettercap is an open-source network analysis tool designed for performing man-in-the-middle (MITM) attacks. It enables users to intercept, analyze, and manipulate live network traffic between two or more devices. The tool is primarily used by cybersecurity professionals, penetration testers, and network administrators to assess vulnerabilities in network communications. Ettercap addresses the challenge of monitoring and analyzing real-time data transfers, offering features like packet sniffing, content filtering, and protocol analysis. Its ability to dissect and modify traffic makes it valuable for both ethical hacking exercises and network troubleshooting. The tool's GPL-2.0 license allows widespread use and modification, contributing to its popularity among security researchers. By providing a comprehensive suite for MITM operations, Ettercap helps users understand and mitigate risks associated with insecure network environments.

How it works

Ettercap is a suite of tools for conducting MITM attacks, enabling the interception and analysis of live network traffic. It supports both active and passive sniffing, allowing users to monitor data transfers without altering the communication flow. The primary purpose of Ettercap is to analyze network protocols, filter content in real-time, and identify vulnerabilities in communication channels. It is widely used in penetration testing to simulate attacks and assess the security of networked systems. Ettercap can dissect and manipulate over 30 protocols, including HTTP, FTP, SMTP, and DNS. It supports active attacks like ARP spoofing to redirect traffic through the attacker's system and passive monitoring for stealthy data capture. The tool also includes features for content filtering, such as modifying packets or injecting malicious payloads.

How to use it

  1. 1Launch Ettercap in a terminal and select the network interface using 'ettercap -i <interface>'. 2. Use 'ettercap -T' to enter the text-based interface, then scan the network with 'scan <target IP>'. 3. Initiate a MITM attack by targeting two devices with 'attack <source> <target>'. 4. Monitor intercepted traffic in real-time using the 'Sniff' menu or analyze logs via 'etterlog'. Practical tips include using Wireshark for deeper packet analysis, verifying SSL/TLS connections with 'sslstrip' to bypass encryption, and ensuring the target network is isolated to prevent detection.

What it can do

  • man-in-the-middle suite

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/Ettercap/ettercap
  • license: GPL-2.0 — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Offensive tool — authorized penetration testing and lab use only; unauthorized use is illegal.
  • Requires physical access to the target network or compromised devices
  • Limited effectiveness against encrypted traffic without SSL stripping
  • Depends on ARP spoofing, which may be detected by network defenses
  • Struggles with high-traffic environments due to performance constraints

Understanding the result

Comprehensive suite for man-in-the-middle attacks, network sniffing and traffic interception.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(Ettercap/ettercap)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with Ettercap/ettercap. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is Ettercap used for?

Ettercap is used for conducting man-in-the-middle attacks, intercepting live network traffic, and analyzing protocol interactions. It helps security professionals assess vulnerabilities in network communications, such as weak encryption or data leakage, by capturing and modifying packets in real-time.

How does Ettercap perform MITM attacks?

Ettercap uses ARP spoofing to trick devices into routing traffic through its system. It identifies target devices on the network, then redirects their communication by altering ARP tables. This allows the tool to intercept data between two devices while maintaining the illusion of normal network behavior.

How do I capture HTTP traffic with Ettercap?

Launch Ettercap with 'ettercap -i <interface>', scan the network, and target two devices. Use the 'Sniff' menu to enable 'HTTP' filtering. Captured traffic will be displayed in plain text, allowing you to inspect headers, request URLs, and payload data without decrypting SSL/TLS connections.

How does Ettercap compare to Wireshark?

Ettercap is focused on MITM operations and real-time traffic manipulation, while Wireshark is a passive packet analyzer. Ettercap integrates sniffing and attack capabilities into a single tool, whereas Wireshark requires separate tools for network interception and modification. Ettercap is better suited for penetration testing, while Wireshark excels in forensic analysis.

What should I do if Ettercap fails to detect a target?

Ensure the target devices are on the same subnet and the network interface is correctly configured. Check for firewall rules blocking ARP requests or traffic interception. Use 'ettercap -T' to verify interface compatibility, and try disabling IPv6 if conflicts arise. If SSL/TLS is in use, combine Ettercap with 'sslstrip' to decrypt HTTPS traffic.

Spotted something wrong with Ettercap, or want to maintain it? See how to help.