
zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

Dshell is a network forensic analysis framework.


Visualize network topologies and collect graph statistics based on pcap files

A Swiss army knife for your daily Linux network plumbing.

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

It was developed to speed up the processes of SOC Analysts during analysis

This is the development tree. Production downloads are at:

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

Distributed & real time digital forensics at the speed of the cloud

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Free hands-on digital forensics labs for students and faculty

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.