
Baskerville
Selective protocol extractor from PCAPs or interfaces

Selective protocol extractor from PCAPs or interfaces

Dshell is a network forensic analysis framework.

Collection of forensic tools

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

A tool to assist with network-based hunting for GRU's Drovorub malware c2

A network sniffer that logs all DNS server replies for use in a passive DNS setup

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…


Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

A network packet forensics tool for SSH

Pcap (capture file) Analysis Toolkit(v.1)

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

It was developed to speed up the processes of SOC Analysts during analysis

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Incident response walkthrough analyzing CVE-2023-46604 exploitation of Apache ActiveMQ via OpenWire, including PCAP analysis, IOC identification, and…