

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.



Multi-source subdomain enumeration tool with 50+ collection modules, DNS brute-force, passive DNS analysis, certificate transparency, search engine…

Scripts and utilities to help your hacking needs

ngrep is like GNU grep applied to the network layer. It's a PCAP-based tool that allows you to specify an extended regular or hexadecimal expression…

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

A curated collection of tools, techniques, frameworks, and learning resources focused on Attack Surface Management (ASM).

Passive-recursive DNS daemon that logs all DNS queries and responses, enabling network visibility, EDR/IR log enrichment, and passive DNS data…

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Dshell is a network forensic analysis framework.

Automates OSINT data collection and analysis for threat intelligence, attack surface mapping, and reconnaissance. Integrates 200+ modules for DNS,…

A portable OSINT Swiss Army Knife for DFIR/OSINT professionals 🕵️ 🕵️ 🕵️


LLMNR/NBNS/mDNS Spoofing Detection Toolkit