#1Tools for analyzing network traffic and communication logs to investigate security incidents.
Kitploit recommended

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Standalone Windows VM malware sandbox running capemon, with GUI triage viewer, YARA signatures, IOC extraction, network analysis, and…

OpenFPC, Open Source Full Packet Capture

NetworkAssessment: Network Compromise Assessment Tool

Offline AI Security Assistant for Air-Gapped Pentesting

create cypher create statements for neo4j out of netstat files from multiple machines

A swiss-knife MCP server for analysing PCAP files

It was developed to speed up the processes of SOC Analysts during analysis

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Decodes PlugX traffic and encrypted/compressed artifacts

Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

Writeup for the DEF CON 30 badge challenge

Lua plugin to extract data from Wireshark and convert it into MISP format

Zeek support for Community ID flow hashing.

Forensic Scanner

Decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, can also remove IEEE 802.1Q (virtual lan) header. Works with pcap…

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

Decrypts Covenant C2 communications by extracting RSA private keys from minidumps, recovering AES session keys, and converting network captures to…