
babyshark
Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Wireshark RDP resources

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Powershell module for VMWare vSphere forensics

Pcap importer for Burp

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Standalone Windows VM malware sandbox running capemon, with GUI triage viewer, YARA signatures, IOC extraction, network analysis, and…

OpenFPC, Open Source Full Packet Capture

Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

Writeup for the DEF CON 30 badge challenge

Lua plugin to extract data from Wireshark and convert it into MISP format

Zeek support for Community ID flow hashing.

A flow-based network monitor with Deep Packet Inspection

A pcap capture analysis helper

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek Wireguard protocol analyzer based on Spicy.