
ja4
JA4+ is a suite of network fingerprinting standards

JA4+ is a suite of network fingerprinting standards

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…


PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

A swiss-knife MCP server for analysing PCAP files

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.


A Zeek IPSec protocol analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

A network sniffer that logs all DNS server replies for use in a passive DNS setup


A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…