
Dshell
Dshell is a network forensic analysis framework.

Dshell is a network forensic analysis framework.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…


Visualize network topologies and collect graph statistics based on pcap files

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A Swiss army knife for your daily Linux network plumbing.

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

It was developed to speed up the processes of SOC Analysts during analysis

This is the development tree. Production downloads are at:

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact


🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

Free hands-on digital forensics labs for students and faculty

Distributed & real time digital forensics at the speed of the cloud

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark