
CAPEsolo
Standalone Windows VM malware sandbox running capemon, with GUI triage viewer, YARA signatures, IOC extraction, network analysis, and…

Standalone Windows VM malware sandbox running capemon, with GUI triage viewer, YARA signatures, IOC extraction, network analysis, and…

Provides packet processing capabilities for Go

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

Wireshark RDP resources

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

Selective protocol extractor from PCAPs or interfaces

A pcap capture analysis helper

A flow-based network monitor with Deep Packet Inspection

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Zeek support for Community ID flow hashing.

A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

Bro analyzer that detects Google's QUIC protocol

A Zeek IPSec protocol analyzer based on Spicy.