
zeek-spicy-stun
A Zeek STUN protocol analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.

linux security checks

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

Distributed & real time digital forensics at the speed of the cloud

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.


Dshell is a network forensic analysis framework.

You didn't think I'd go and leave the blue team out, right?

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

JA4+ is a suite of network fingerprinting standards

This is the development tree. Production downloads are at:

A list of cyber-chef recipes and curated links


TCP/IP packet demultiplexer. Download from:

Malicious HTTP traffic explorer