
Wireshark
Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…


Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

A Zeek Wireguard protocol analyzer based on Spicy.

TCP/IP packet demultiplexer. Download from:

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek OSPF packet analyzer based on Spicy.

A Swiss army knife for your daily Linux network plumbing.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Provides packet processing capabilities for Go

Powershell module for VMWare vSphere forensics

NetworkAssessment: Network Compromise Assessment Tool

A network sniffer that logs all DNS server replies for use in a passive DNS setup