
pcapfex
'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Pcap importer for Burp

OpenFPC, Open Source Full Packet Capture

NetworkAssessment: Network Compromise Assessment Tool

Lua plugin to extract data from Wireshark and convert it into MISP format

Zeek support for Community ID flow hashing.

A tool to assist with network-based hunting for GRU's Drovorub malware c2

A flow-based network monitor with Deep Packet Inspection

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek Wireguard protocol analyzer based on Spicy.

Bro analyzer that detects Google's QUIC protocol

A Zeek OSPF packet analyzer based on Spicy.

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Selective protocol extractor from PCAPs or interfaces

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…