
plugxdecoder
Decodes PlugX traffic and encrypted/compressed artifacts

Decodes PlugX traffic and encrypted/compressed artifacts

Lua plugin to extract data from Wireshark and convert it into MISP format


Decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, can also remove IEEE 802.1Q (virtual lan) header. Works with pcap…

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

Decrypts Covenant C2 communications by extracting RSA private keys from minidumps, recovering AES session keys, and converting network captures to…

Android Connections Forensics

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

A pcap capture analysis helper

A Zeek IPSec protocol analyzer based on Spicy.

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Selective protocol extractor from PCAPs or interfaces

Shell Companies Inside Apple's Privacy Relay

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

Parsing Ramnit's traffic