
timesketch
Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

JA4+ is a suite of network fingerprinting standards


All-in-One malware analysis tool.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

It was developed to speed up the processes of SOC Analysts during analysis

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

NetworkAssessment: Network Compromise Assessment Tool

A network sniffer that logs all DNS server replies for use in a passive DNS setup

A tool to analyze the network flow during attack/defence Capture the Flag competitions


PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

A network packet forensics tool for SSH

Malcom - Malware Communications Analyzer