
babyshark
Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

A list of cyber-chef recipes and curated links

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

Lua plugin to extract data from Wireshark and convert it into MISP format

Controlled reproduction of CVE-2017-0144 (EternalBlue) in an isolated AWS EC2 lab — exploit analysis, Wireshark traffic capture, and MITRE ATT&CK…

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

Forensic triage of DNS cache poisoning in legacy hardware. Includes PCAP analysis of 839-byte unsolicited record injections, CVE-2025-40778 mapping,…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Visualize network topologies and collect graph statistics based on pcap files

A swiss-knife MCP server for analysing PCAP files

Writeup for the DEF CON 30 badge challenge

Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic…

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.