


IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

JA4+ is a suite of network fingerprinting standards

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

A network sniffer that logs all DNS server replies for use in a passive DNS setup

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

A network packet forensics tool for SSH

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

A swiss-knife MCP server for analysing PCAP files