
Skadi
Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Malcom - Malware Communications Analyzer

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

A terminal UI for tshark, inspired by Wireshark

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

Dshell is a network forensic analysis framework.

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…


Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

JA4+ is a suite of network fingerprinting standards

All-in-One malware analysis tool.

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

TCP/IP packet demultiplexer. Download from:

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Malware samples, analysis exercises and other interesting resources.