#1Tools for analyzing network traffic and communication logs to investigate security incidents.
Kitploit recommended

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Zeek support for Community ID flow hashing.

A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

Bro analyzer that detects Google's QUIC protocol

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek OSPF packet analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.

A Zeek Wireguard protocol analyzer based on Spicy.

AIEngine is a next generation interactive/programmable Python/Ruby/Java/Lua and Go NIDS (Network intrusion detection system).

Shell Companies Inside Apple's Privacy Relay

Decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, can also remove IEEE 802.1Q (virtual lan) header. Works with pcap…

This is the development tree. Production downloads are at:

Forensic Scanner

Decodes PlugX traffic and encrypted/compressed artifacts

Parsing Ramnit's traffic

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…