
libpcap
System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

System-independent library for user-level packet capture and filtering. Provides a portable framework for low-level network monitoring, security…

Network traffic sensor

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

Spip network sensor written in Go

Integrates your Modern Honeypot Network Server and Wordpress Blog via MHN's REST API and WP's shortcodes

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

LLMNR/NBNS/mDNS Spoofing Detection Toolkit


Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

SQL powered operating system instrumentation, monitoring, and analytics.

Github mirror of official Kismet repository

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.


Automated threat intelligence aggregation tool that extracts and normalizes indicators from multiple sources (OSINT feeds, malware reports) into a…

A Wordpress Honeypot

Honeynet Project generic authenticated datafeed protocol