
CapTipper
Malicious HTTP traffic explorer

Malicious HTTP traffic explorer

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

All-in-One malware analysis tool.

A network packet forensics tool for SSH

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

It was developed to speed up the processes of SOC Analysts during analysis

Decodes PlugX traffic and encrypted/compressed artifacts

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…


QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

A tool to analyze the network flow during attack/defence Capture the Flag competitions