
wireshark
Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

A lightweight eBPF program to monitor file creation and modification events on Linux. This tool leverages eBPF (Extended Berkeley Packet Filter) to…

Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Dshell is a network forensic analysis framework.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

TCP/IP packet demultiplexer. Download from:

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…