
ja4
JA4+ is a suite of network fingerprinting standards

JA4+ is a suite of network fingerprinting standards

All-in-One malware analysis tool.

This is the development tree. Production downloads are at:

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…


Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

It was developed to speed up the processes of SOC Analysts during analysis

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

NetworkAssessment: Network Compromise Assessment Tool

A network sniffer that logs all DNS server replies for use in a passive DNS setup

A tool for processing a lot of pcaps using tshark

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

A tool to analyze the network flow during attack/defence Capture the Flag competitions