
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…


A network sniffer that logs all DNS server replies for use in a passive DNS setup


A Swiss army knife for your daily Linux network plumbing.

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Visualize network topologies and collect graph statistics based on pcap files

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Zero-dependency, sub-second Windows live digital forensics & incident response (DFIR) triage engine for USB responders.

This is the development tree. Production downloads are at:


JA4+ is a suite of network fingerprinting standards

It was developed to speed up the processes of SOC Analysts during analysis

create cypher create statements for neo4j out of netstat files from multiple machines

A pcap capture analysis helper

PowerShell script that monitors Windows DNS traffic via pktmon to detect poisoning, spoofing, rogue resolver responses, and gateway MAC changes,…