
Wireshark
Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

You didn't think I'd go and leave the blue team out, right?

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…

Web-based Traffic and Cybersecurity Network Traffic Monitoring

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark


Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

JA4+ is a suite of network fingerprinting standards

Malware Configuration And Payload Extraction

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

All-in-One malware analysis tool.

Free hands-on digital forensics labs for students and faculty

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

This is the development tree. Production downloads are at: