#1Tools for analyzing network traffic and communication logs to investigate security incidents.
Kitploit recommended

A tool to analyze the network flow during attack/defence Capture the Flag competitions
The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Visualize network topologies and collect graph statistics based on pcap files

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

A curated collection of DFIR skills and workflows for InfoSec practitioners.

The Multiplatform Linux Sandbox

A network packet forensics tool for SSH

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

Wireshark RDP resources

Pcap (capture file) Analysis Toolkit(v.1)

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Powershell module for VMWare vSphere forensics

A tool for processing a lot of pcaps using tshark

Pcap importer for Burp