
ntopng
Web-based Traffic and Cybersecurity Network Traffic Monitoring

Web-based Traffic and Cybersecurity Network Traffic Monitoring


Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…


This is the development tree. Production downloads are at:

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

Collection of forensic tools

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Forensic triage of DNS cache poisoning in legacy hardware. Includes PCAP analysis of 839-byte unsolicited record injections, CVE-2025-40778 mapping,…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Dshell is a network forensic analysis framework.