
Dshell
Dshell is a network forensic analysis framework.

Dshell is a network forensic analysis framework.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…


A Swiss army knife for your daily Linux network plumbing.

Visualize network topologies and collect graph statistics based on pcap files

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

This is the development tree. Production downloads are at:

It was developed to speed up the processes of SOC Analysts during analysis

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

Distributed & real time digital forensics at the speed of the cloud

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

Free hands-on digital forensics labs for students and faculty

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.