
zeek-quic
Bro analyzer that detects Google's QUIC protocol

Bro analyzer that detects Google's QUIC protocol

Selective protocol extractor from PCAPs or interfaces

Parsing Ramnit's traffic

DFIR investigation + 7 Suricata rules on a simulated NexaCorp intrusion (vsftpd 2.3.4 CVE-2011-2523 + MITRE Caldera C2). 4-day solo engagement…

Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)

linux security checks

create cypher create statements for neo4j out of netstat files from multiple machines



All-in-One malware analysis tool.

A terminal UI for tshark, inspired by Wireshark

Provides packet processing capabilities for Go

Dshell is a network forensic analysis framework.

This is the development tree. Production downloads are at:

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors

TCP/IP packet demultiplexer. Download from:

Collection of forensic tools