
packetStrider
A network packet forensics tool for SSH

A network packet forensics tool for SSH

A swiss-knife MCP server for analysing PCAP files

Zeek support for Community ID flow hashing.

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

⭐ ⭐ Distributed tcpdump for cloud native environments ⭐ ⭐


Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

It was developed to speed up the processes of SOC Analysts during analysis

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

A flow-based network monitor with Deep Packet Inspection

A Zeek Wireguard protocol analyzer based on Spicy.

Bro analyzer that detects Google's QUIC protocol

A Zeek OSPF packet analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.