
Baskerville
Selective protocol extractor from PCAPs or interfaces

Selective protocol extractor from PCAPs or interfaces

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

Visualize network topologies and collect graph statistics based on pcap files

A Zeek Wireguard protocol analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.

Incident response walkthrough analyzing CVE-2023-46604 exploitation of Apache ActiveMQ via OpenWire, including PCAP analysis, IOC identification, and…

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

A network sniffer that logs all DNS server replies for use in a passive DNS setup