
BruteShark
Network forensic analysis tool for deep PCAP inspection, extracting passwords, authentication hashes, and network maps. Supports live capture,…

Network forensic analysis tool for deep PCAP inspection, extracting passwords, authentication hashes, and network maps. Supports live capture,…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

A tool to analyze the network flow during attack/defence Capture the Flag competitions

Analyzes SSH packet captures using machine learning to predict reverse tunnels, keystrokes, data exfiltration, and authentication methods for…

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

A tool for processing a lot of pcaps using tshark

Analyzes pcap files to detect DNS tunneling, SSH tunneling, TCP hijacking, and various network attacks (SYN flood, Slowloris, SMB) with…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

It was developed to speed up the processes of SOC Analysts during analysis

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files