


IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

Dshell is a network forensic analysis framework.

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark


Parsing Ramnit's traffic

This is the development tree. Production downloads are at:

Wireshark RDP resources