
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

Dshell is a network forensic analysis framework.

PowerShell script that monitors Windows DNS traffic via pktmon to detect poisoning, spoofing, rogue resolver responses, and gateway MAC changes,…

JA4+ is a suite of network fingerprinting standards

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

A network sniffer that logs all DNS server replies for use in a passive DNS setup


A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Visualize network topologies and collect graph statistics based on pcap files

create cypher create statements for neo4j out of netstat files from multiple machines


It was developed to speed up the processes of SOC Analysts during analysis

A pcap capture analysis helper

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.