
keepass-exfil-forensics
Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

⭐ ⭐ Distributed tcpdump for cloud native environments ⭐ ⭐

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.


Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

It was developed to speed up the processes of SOC Analysts during analysis

A flow-based network monitor with Deep Packet Inspection

A Zeek Wireguard protocol analyzer based on Spicy.

Bro analyzer that detects Google's QUIC protocol

A Zeek OSPF packet analyzer based on Spicy.

Automated cross-platform sandbox that detonates suspicious files in isolated VMs/emulators, captures network and memory artifacts, and creates LLM…