BotHunter is a passive network monitoring tool designed to recognize the communication patterns of malware-infected computers within your network perimeter. Using an advanced infection-dialog-based event correlation engine (patent pending), BotHunter represents the most in-depth network-based malware infection diagnosis system available today.
  • Linux - tested on Fedora, Red Hat Enterprise Linux, Debian, and SuSE distributions
  • FreeBSD - tested on Product Release 7.0
  • Mac OS X - tested on Tiger and Leopard, Mac OS 10.4 and 10.5
  • Windows XP - a self-installing Win32 executable is available and will install all necessary supporting packages
  • Live-CD - a self-booting ISO image of BotHunter operating on Ubuntu Linux


BotHunter® is available free for both experimental operational use and to help stimulate research in understanding the life cycle of malware infections.

http://www.bothunter.net/