

Bro analyzer that detects Google's QUIC protocol

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.


eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…


PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A swiss-knife MCP server for analysing PCAP files

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files