
arkime
Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.


Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

JA4+ is a suite of network fingerprinting standards

DFIR forensics companion server + capture extension

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

LetsDefend SOC lab investigating CVE-2024-49138 exploitation and related malicious activity.