#1Tools for analyzing network traffic and communication logs to investigate security incidents.
Kitploit recommended

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

DFIR forensics companion server + capture extension

Free hands-on digital forensics labs for students and faculty

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Zero-dependency, sub-second Windows live digital forensics & incident response (DFIR) triage engine for USB responders.

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…