
ptcpdump
eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Visualize network topologies and collect graph statistics based on pcap files

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Wireshark RDP resources

Powershell module for VMWare vSphere forensics

A swiss-knife MCP server for analysing PCAP files

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Decodes PlugX traffic and encrypted/compressed artifacts

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

Writeup for the DEF CON 30 badge challenge

Decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, can also remove IEEE 802.1Q (virtual lan) header. Works with pcap…

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

DFIR investigation + 7 Suricata rules on a simulated NexaCorp intrusion (vsftpd 2.3.4 CVE-2011-2523 + MITRE Caldera C2). 4-day solo engagement…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

A Zeek STUN protocol analyzer based on Spicy.