Wireshark (formerly Ethereal) is an advanced network protocol analyzer for Linux and the de facto standard across many industries and educational institutions.
chkrootkit is a Linux hacking tool to locally check for signs of a rootkit. It contains a chkrootkit: shell script that checks system binaries for rootkit modification.
Nmap ("Network Mapper") is a free and open source software utility for network exploration or security auditing. It is available for Linux and Windows.
p0f is a versatile passive OS fingerprinting and masquerade detection tool for Linux, to be used for evidence or information gathering on servers, firewalls,etc.