
bulk_extractor
This is the development tree. Production downloads are at:

This is the development tree. Production downloads are at:

TCP/IP packet demultiplexer. Download from:

Collection of forensic tools

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

Pcap importer for Burp

OpenFPC, Open Source Full Packet Capture

Zeek support for Community ID flow hashing.


A flow-based network monitor with Deep Packet Inspection

Bro analyzer that detects Google's QUIC protocol

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek Wireguard protocol analyzer based on Spicy.

A Zeek OSPF packet analyzer based on Spicy.



Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)
