
arkime
Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Dshell is a network forensic analysis framework.


Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Collection of forensic tools

A tool to analyze the network flow during attack/defence Capture the Flag competitions

A curated collection of DFIR skills and workflows for InfoSec practitioners.

A network packet forensics tool for SSH

Wireshark RDP resources

A tool for processing a lot of pcaps using tshark

Pcap (capture file) Analysis Toolkit(v.1)

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Offline AI Security Assistant for Air-Gapped Pentesting