
joy
A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

Lua plugin to extract data from Wireshark and convert it into MISP format

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Decodes PlugX traffic and encrypted/compressed artifacts

Decrypts Covenant C2 communications by extracting RSA private keys from minidumps, recovering AES session keys, and converting network captures to…

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…