
Skadi
Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Free hands-on digital forensics labs for students and faculty

Malcom - Malware Communications Analyzer

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

AIEngine is a next generation interactive/programmable Python/Ruby/Java/Lua and Go NIDS (Network intrusion detection system).

A terminal UI for tshark, inspired by Wireshark

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

Dshell is a network forensic analysis framework.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Malware Configuration And Payload Extraction



Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors