
forensictools
Collection of forensic tools

Collection of forensic tools

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Offline AI Security Assistant for Air-Gapped Pentesting

It was developed to speed up the processes of SOC Analysts during analysis

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

A Zeek STUN protocol analyzer based on Spicy.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Wireshark RDP resources

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Dshell is a network forensic analysis framework.

A tool for processing a lot of pcaps using tshark


A tool to analyze the network flow during attack/defence Capture the Flag competitions

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…