
ir-rescue
A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

A tool to analyze the network flow during attack/defence Capture the Flag competitions

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Lua plugin to extract data from Wireshark and convert it into MISP format

A tool to assist with network-based hunting for GRU's Drovorub malware c2

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

A network sniffer that logs all DNS server replies for use in a passive DNS setup

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Malicious HTTP traffic explorer

Malcom - Malware Communications Analyzer