Did everyone forget about wireshark, which can totally be ran as non-root?
https://blog.wireshark.org/2010/02/running-wireshark-as-you/
https://blog.wireshark.org/2010/02/running-wireshark-as-you/
Also, can Wireshark/libpcap decrypt SSL/TLS traffic this easily?