
scapy
Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Web-based Traffic and Cybersecurity Network Traffic Monitoring

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

JA4+ is a suite of network fingerprinting standards

Malware Configuration And Payload Extraction

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.


Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…


Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

All-in-One malware analysis tool.