
forensictools
Collection of forensic tools

Collection of forensic tools

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Dshell is a network forensic analysis framework.


Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Wireshark RDP resources

A tool for processing a lot of pcaps using tshark

It was developed to speed up the processes of SOC Analysts during analysis

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Incident response walkthrough analyzing CVE-2023-46604 exploitation of Apache ActiveMQ via OpenWire, including PCAP analysis, IOC identification, and…

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

A tool to analyze the network flow during attack/defence Capture the Flag competitions

A network packet forensics tool for SSH

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…