
TCPViewer
The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors

TCP/IP packet demultiplexer. Download from:

A lightweight eBPF program to monitor file creation and modification events on Linux. This tool leverages eBPF (Extended Berkeley Packet Filter) to…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

Dshell is a network forensic analysis framework.

Lua plugin to extract data from Wireshark and convert it into MISP format

Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files