
Skadi
Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

A terminal UI for tshark, inspired by Wireshark

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…


IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…


Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

JA4+ is a suite of network fingerprinting standards

All-in-One malware analysis tool.

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Collection of forensic tools

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic