P0f is a tool that utilizes an array of sophisticated, purely passive traffic fingerprinting mechanisms to identify the players behind any incidental TCP/IP communications (often as little as a single normal SYN) without interfering in any way. Version 3 is a complete rewrite of the original codebase, incorporating a significant number of improvements to network-level fingerprinting, and introducing the ability to reason about application-level payloads (e.g., HTTP).
You can download it from the following link: https://packetstormsecurity.com/files/download/109101/p0f-3.03b-win.zip
Source: https://packetstormsecurity.com/files/109101/p0f-3.03b-Windows-Port.html