
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Dshell is a network forensic analysis framework.

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…


Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

A terminal UI for tshark, inspired by Wireshark

Visualize network topologies and collect graph statistics based on pcap files

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

A Swiss army knife for your daily Linux network plumbing.

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…