
Bryobio
It was developed to speed up the processes of SOC Analysts during analysis

It was developed to speed up the processes of SOC Analysts during analysis

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.


IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

A tool to analyze the network flow during attack/defence Capture the Flag competitions

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

NetworkAssessment: Network Compromise Assessment Tool

A tool to assist with network-based hunting for GRU's Drovorub malware c2

This is the development tree. Production downloads are at:

Malcom - Malware Communications Analyzer

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…


Python wrapper for tshark, allowing python packet parsing using wireshark dissectors

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Malicious HTTP traffic explorer

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…