#1Tools for analyzing network traffic and communication logs to investigate security incidents.
Kitploit recommended


A tool to assist with network-based hunting for GRU's Drovorub malware c2

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

A flow-based network monitor with Deep Packet Inspection

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

A pcap capture analysis helper

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek Wireguard protocol analyzer based on Spicy.

Bro analyzer that detects Google's QUIC protocol

A Zeek OSPF packet analyzer based on Spicy.

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

A Zeek STUN protocol analyzer based on Spicy.

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…