
DCSYNCMonitor
Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.

Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.

Conveigh is a Windows PowerShell LLMNR/NBNS spoofer detection tool

Security Tool to detect arp poisoning attacks

NetworkAssessment: Network Compromise Assessment Tool

A simple tool to detect NBT-NS and LLMNR spoofing (and messing with them a bit)

A tool to assist with network-based hunting for GRU's Drovorub malware c2

A real-time traffic monitoring tool that detects and displays network traffic volume per IP address to identify potential DDoS attacks.

Corelight@Home script

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…

Digital forensics and incident response tool using YARA rules to scan Citrix NetScaler core dumps, disk images, and live hosts for signs of…

Windows Analysis and Research Toolkit

Deep Learning models for network traffic classification

JA4+ is a suite of network fingerprinting standards