#1Tools for analyzing network traffic and communication logs to investigate security incidents.
Kitploit recommended

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

A list of cyber-chef recipes and curated links

You didn't think I'd go and leave the blue team out, right?

Wireshark RDP resources

Decrypts Covenant C2 communications by extracting RSA private keys from minidumps, recovering AES session keys, and converting network captures to…

Malware samples, analysis exercises and other interesting resources.

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic…

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…


Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…


Selective protocol extractor from PCAPs or interfaces

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

Pcap importer for Burp

A pcap capture analysis helper

A flow-based network monitor with Deep Packet Inspection