
etl2pcapng
Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

A network packet forensics tool for SSH

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Lua plugin to extract data from Wireshark and convert it into MISP format

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…