
timesketch
Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

This is the development tree. Production downloads are at:

Malicious HTTP traffic explorer

Malcom - Malware Communications Analyzer

A network sniffer that logs all DNS server replies for use in a passive DNS setup

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

JA4+ is a suite of network fingerprinting standards

A tool for processing a lot of pcaps using tshark

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

A tool to assist with network-based hunting for GRU's Drovorub malware c2


❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

A network packet forensics tool for SSH

A tool to analyze the network flow during attack/defence Capture the Flag competitions

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

All-in-One malware analysis tool.

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.