
pcapan
A pcap capture analysis helper

A pcap capture analysis helper

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Bro analyzer that detects Google's QUIC protocol

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek Wireguard protocol analyzer based on Spicy.

A Zeek OSPF packet analyzer based on Spicy.

DFIR investigation + 7 Suricata rules on a simulated NexaCorp intrusion (vsftpd 2.3.4 CVE-2011-2523 + MITRE Caldera C2). 4-day solo engagement…

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

Selective protocol extractor from PCAPs or interfaces

A Zeek STUN protocol analyzer based on Spicy.

Shell Companies Inside Apple's Privacy Relay

Parsing Ramnit's traffic

Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)


A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

Forensic triage of DNS cache poisoning in legacy hardware. Includes PCAP analysis of 839-byte unsolicited record injections, CVE-2025-40778 mapping,…