
windows-malware-behavioral-analysis
Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.


Malware samples, analysis exercises and other interesting resources.


Android Connections Forensics

Selective protocol extractor from PCAPs or interfaces

Pcap importer for Burp

A flow-based network monitor with Deep Packet Inspection


Zeek support for Community ID flow hashing.

Bro analyzer that detects Google's QUIC protocol

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek OSPF packet analyzer based on Spicy.

A Zeek Wireguard protocol analyzer based on Spicy.

This is the development tree. Production downloads are at:
