
etl2pcapng
Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…