
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

A Zeek STUN protocol analyzer based on Spicy.

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

JA4+ is a suite of network fingerprinting standards

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…


eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…