
arkime
Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.


Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

A list of cyber-chef recipes and curated links

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

TCP/IP packet demultiplexer. Download from:

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Malicious HTTP traffic explorer

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

A tool to analyze the network flow during attack/defence Capture the Flag competitions

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

Visualize network topologies and collect graph statistics based on pcap files

The Multiplatform Linux Sandbox

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles