
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…


PowerShell script that monitors Windows DNS traffic via pktmon to detect poisoning, spoofing, rogue resolver responses, and gateway MAC changes,…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

A Swiss army knife for your daily Linux network plumbing.


JA4+ is a suite of network fingerprinting standards

This is the development tree. Production downloads are at:

create cypher create statements for neo4j out of netstat files from multiple machines

It was developed to speed up the processes of SOC Analysts during analysis

Standalone Windows VM malware sandbox running capemon, with GUI triage viewer, YARA signatures, IOC extraction, network analysis, and…

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

A tool for processing a lot of pcaps using tshark