#1Tools for analyzing network traffic and communication logs to investigate security incidents.
Kitploit recommended

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Dshell is a network forensic analysis framework.

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…


Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

A terminal UI for tshark, inspired by Wireshark

the TCPdump network dissector

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

A Swiss army knife for your daily Linux network plumbing.

Visualize network topologies and collect graph statistics based on pcap files