
babyshark
Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

A tool for processing a lot of pcaps using tshark

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

create cypher create statements for neo4j out of netstat files from multiple machines

Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

Android Connections Forensics



Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

A terminal UI for tshark, inspired by Wireshark

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

This is the development tree. Production downloads are at:

TCP/IP packet demultiplexer. Download from:

Collection of forensic tools

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…