#1Tools for analyzing network traffic and communication logs to investigate security incidents.
Kitploit recommended

TCP/IP packet demultiplexer. Download from:

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

A Swiss army knife for your daily Linux network plumbing.

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Malicious HTTP traffic explorer

Malcom - Malware Communications Analyzer

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Collection of forensic tools

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…