
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Free hands-on digital forensics labs for students and faculty

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

All-in-One malware analysis tool.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!



DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

Analyzes pcapng packet captures and generates HTML reports for network traffic review, protocol inspection, and incident response investigations.