#1Tools for analyzing network traffic and communication logs to investigate security incidents.
Kitploit recommended

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors
FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

create cypher create statements for neo4j out of netstat files from multiple machines

A tool for processing a lot of pcaps using tshark

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

A tool to assist with network-based hunting for GRU's Drovorub malware c2


❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

A network packet forensics tool for SSH

A tool to analyze the network flow during attack/defence Capture the Flag competitions

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Lua plugin to extract data from Wireshark and convert it into MISP format

All-in-One malware analysis tool.

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.