
zeek-quic
Bro analyzer that detects Google's QUIC protocol

Bro analyzer that detects Google's QUIC protocol

Selective protocol extractor from PCAPs or interfaces

A terminal UI for tshark, inspired by Wireshark

TCP/IP packet demultiplexer. Download from:

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek Wireguard protocol analyzer based on Spicy.

A Zeek OSPF packet analyzer based on Spicy.


Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

A network packet forensics tool for SSH

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

AIEngine is a next generation interactive/programmable Python/Ruby/Java/Lua and Go NIDS (Network intrusion detection system).

A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense.

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…