
security checks
linux security checks

linux security checks
PowerShell script that monitors Windows DNS traffic via pktmon to detect poisoning, spoofing, rogue resolver responses, and gateway MAC changes,…

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.


Dshell is a network forensic analysis framework.

JA4+ is a suite of network fingerprinting standards


eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Standalone Windows VM malware sandbox running capemon, with GUI triage viewer, YARA signatures, IOC extraction, network analysis, and…

OpenFPC, Open Source Full Packet Capture

NetworkAssessment: Network Compromise Assessment Tool

Decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, can also remove IEEE 802.1Q (virtual lan) header. Works with pcap…

A pcap capture analysis helper

A Zeek IPSec protocol analyzer based on Spicy.

Selective protocol extractor from PCAPs or interfaces