
Skadi
Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

Visualize network topologies and collect graph statistics based on pcap files

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek OSPF packet analyzer based on Spicy.

A Zeek Wireguard protocol analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.

Selective protocol extractor from PCAPs or interfaces

A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

CVE-2017-0199 XLS --> HTA --> VBS --> STEGANOGRAPHY --> DBATLOADER/GULOADER STYLE MALWARE