
passivedns
A network sniffer that logs all DNS server replies for use in a passive DNS setup

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Visualize network topologies and collect graph statistics based on pcap files

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

create cypher create statements for neo4j out of netstat files from multiple machines

Malware Configuration And Payload Extraction

It was developed to speed up the processes of SOC Analysts during analysis

Standalone Windows VM malware sandbox running capemon, with GUI triage viewer, YARA signatures, IOC extraction, network analysis, and…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Selective protocol extractor from PCAPs or interfaces

All-in-One malware analysis tool.

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

Forensic triage of DNS cache poisoning in legacy hardware. Includes PCAP analysis of 839-byte unsolicited record injections, CVE-2025-40778 mapping,…

The Multiplatform Linux Sandbox

A network packet forensics tool for SSH

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…