
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

JA4+ is a suite of network fingerprinting standards

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

A swiss-knife MCP server for analysing PCAP files

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

A network sniffer that logs all DNS server replies for use in a passive DNS setup