Andreas Bogk and Hannes Mehnert created alternative to Wireshark. The tool is written in the Dylan programming language, which is new to me. The authors have written a paper (.pdf) that describes the project in detail. It’s the software equivalent of my “defensible network architecture” idea, which describes how to build an enterprise with the best chance possible of resisting intrusions. When I teach network forensics I describe the importance of being aware of handling malicious traffic that might seek to compromise analysis tools.”]
Source: https://taosecurity.blogspot.com/2006/12/wireshark-substitute-encourages.html