
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Analyzes pcapng packet captures and generates HTML reports for network traffic review, protocol inspection, and incident response investigations.

Selective protocol extractor from PCAPs or interfaces

Malware Configuration And Payload Extraction

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

Dshell is a network forensic analysis framework.

Distributed & real time digital forensics at the speed of the cloud

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

Provides packet processing capabilities for Go

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Free hands-on digital forensics labs for students and faculty

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Malcom - Malware Communications Analyzer