
pcapfex
'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Lua plugin to extract data from Wireshark and convert it into MISP format

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

TCP/IP packet demultiplexer. Download from:

Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)

Full-node Bitcoin client that validates transactions and blocks on the peer-to-peer network, with integrated wallet, cryptographic security, and…

Add POST body excerpt to Bro's HTTP log

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…

A repository of sysmon configuration modules


🐍 High-performance, multi-threaded YARA & IOC scanner

Collection of private Yara rules.