
NetScope
Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Wireshark RDP resources

Selective protocol extractor from PCAPs or interfaces

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

A Zeek STUN protocol analyzer based on Spicy.

A curated collection of DFIR skills and workflows for InfoSec practitioners.


Offline AI Security Assistant for Air-Gapped Pentesting

Pcap (capture file) Analysis Toolkit(v.1)

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Dshell is a network forensic analysis framework.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

A network sniffer that logs all DNS server replies for use in a passive DNS setup

OpenFPC, Open Source Full Packet Capture

A tool for processing a lot of pcaps using tshark