
tcpflow
TCP/IP packet demultiplexer. Download from:

TCP/IP packet demultiplexer. Download from:

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Lua plugin to extract data from Wireshark and convert it into MISP format

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)