
ja4
JA4+ is a suite of network fingerprinting standards

JA4+ is a suite of network fingerprinting standards

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Selective protocol extractor from PCAPs or interfaces

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Incident response walkthrough analyzing CVE-2023-46604 exploitation of Apache ActiveMQ via OpenWire, including PCAP analysis, IOC identification, and…