
Loki
IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Visualize network topologies and collect graph statistics based on pcap files

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Selective protocol extractor from PCAPs or interfaces

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

A Zeek STUN protocol analyzer based on Spicy.

All-in-One malware analysis tool.

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

A Zeek OSPF packet analyzer based on Spicy.

A Zeek IPSec protocol analyzer based on Spicy.

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)

Powershell module for VMWare vSphere forensics

Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)

OpenFPC, Open Source Full Packet Capture