
QCSuper
QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Selective protocol extractor from PCAPs or interfaces

A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek OSPF packet analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.

A Zeek Wireguard protocol analyzer based on Spicy.

CVE-2017-0199 XLS --> HTA --> VBS --> STEGANOGRAPHY --> DBATLOADER/GULOADER STYLE MALWARE

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Visualize network topologies and collect graph statistics based on pcap files

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files