
Android-Projector-C2-Malware
Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, can also remove IEEE 802.1Q (virtual lan) header. Works with pcap…

DFIR forensics companion server + capture extension

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

Bro analyzer that detects Google's QUIC protocol

Selective protocol extractor from PCAPs or interfaces

Parsing Ramnit's traffic

DFIR investigation + 7 Suricata rules on a simulated NexaCorp intrusion (vsftpd 2.3.4 CVE-2011-2523 + MITRE Caldera C2). 4-day solo engagement…

Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)

create cypher create statements for neo4j out of netstat files from multiple machines



All-in-One malware analysis tool.

A terminal UI for tshark, inspired by Wireshark

Provides packet processing capabilities for Go

Dshell is a network forensic analysis framework.