
linux-root-kit
End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

Free hands-on digital forensics labs for students and faculty

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

A swiss-knife MCP server for analysing PCAP files

Writeup for the DEF CON 30 badge challenge

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Visualize network topologies and collect graph statistics based on pcap files

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

It was developed to speed up the processes of SOC Analysts during analysis

Collection of forensic tools

Malware samples, analysis exercises and other interesting resources.

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.