
zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

JA4+ is a suite of network fingerprinting standards

A network sniffer that logs all DNS server replies for use in a passive DNS setup

A Swiss army knife for your daily Linux network plumbing.

Malicious HTTP traffic explorer

Malcom - Malware Communications Analyzer

The Multiplatform Linux Sandbox

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Powershell module for VMWare vSphere forensics

Pcap importer for Burp

OpenFPC, Open Source Full Packet Capture

It was developed to speed up the processes of SOC Analysts during analysis

Decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, can also remove IEEE 802.1Q (virtual lan) header. Works with pcap…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis