
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

JA4+ is a suite of network fingerprinting standards

Web-based Traffic and Cybersecurity Network Traffic Monitoring

All-in-One malware analysis tool.

Free hands-on digital forensics labs for students and faculty

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

This is the development tree. Production downloads are at:

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…


Malware Configuration And Payload Extraction

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

You didn't think I'd go and leave the blue team out, right?

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…