
Dshell
Dshell is a network forensic analysis framework.

Dshell is a network forensic analysis framework.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Visualize network topologies and collect graph statistics based on pcap files

A Swiss army knife for your daily Linux network plumbing.

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

create cypher create statements for neo4j out of netstat files from multiple machines

A pcap capture analysis helper

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Selective protocol extractor from PCAPs or interfaces

Malware Configuration And Payload Extraction

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Distributed & real time digital forensics at the speed of the cloud

A Zeek STUN protocol analyzer based on Spicy.

Provides packet processing capabilities for Go

JA4+ is a suite of network fingerprinting standards

Collection of forensic tools