
etl2pcapng
Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

A network packet forensics tool for SSH

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

A tool for processing a lot of pcaps using tshark

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

NetworkAssessment: Network Compromise Assessment Tool

Offline AI Security Assistant for Air-Gapped Pentesting

create cypher create statements for neo4j out of netstat files from multiple machines

Android Connections Forensics


Selective protocol extractor from PCAPs or interfaces

CVE-2017-0199 XLS --> HTA --> VBS --> STEGANOGRAPHY --> DBATLOADER/GULOADER STYLE MALWARE


Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

A terminal UI for tshark, inspired by Wireshark