


Sniffles: Packet Capture Generator for IDS and Regular Expression Evaluation

Zeek package that uses OpenSSL to detect CVE-2020-0601 exploit attempts

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

An event-driven network monitoring platform that performs live packet capture (Npcap), low-latency traffic analytics, and unsupervised threat…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

A network packet forensics tool for SSH

DNXFIREWALL® and DAD'S NEXT-GEN FIREWALL™, a C/CPython hybrid next generation firewall built on top of Linux and bound to kernel/ netfilter hooks for…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

NetworkAssessment: Network Compromise Assessment Tool

PCAPs and Suricata signatures for detecting OpenSSL CVE-2022-3602 exploitation attempts, including malicious client/server traffic and legitimate…

With Wireshark or TCPdump, you can determine whether there is harmful activity on your network traffic that you have recorded on the network you…

Security Tool to detect arp poisoning attacks

A network detection package for CVE-2020-16898 (Windows TCP/IP Remote Code Execution Vulnerability)

Zeek package to detect CVE-2022-21907 HTTP exploit attempts by analyzing packet captures for malformed requests and triggering alerts.

Lightweight network intrusion detection engine capturing live traffic with libpcap. Detects SYN/ICMP floods, port scans, and signature-based web…

Repo containing lua scripts and PCAP to find CVE-2020-0601 exploit attempts via network traffic