
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Web-based Traffic and Cybersecurity Network Traffic Monitoring


Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek OSPF packet analyzer based on Spicy.

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

NetworkAssessment: Network Compromise Assessment Tool

AIEngine is a next generation interactive/programmable Python/Ruby/Java/Lua and Go NIDS (Network intrusion detection system).