
timesketch
Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, can also remove IEEE 802.1Q (virtual lan) header. Works with pcap…

This is the development tree. Production downloads are at:

Decodes PlugX traffic and encrypted/compressed artifacts


Malicious HTTP traffic explorer

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

Malcom - Malware Communications Analyzer

A network sniffer that logs all DNS server replies for use in a passive DNS setup

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

JA4+ is a suite of network fingerprinting standards

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors

A tool for processing a lot of pcaps using tshark

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

A tool to assist with network-based hunting for GRU's Drovorub malware c2
