
linux-root-kit
End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

It was developed to speed up the processes of SOC Analysts during analysis

Malware Configuration And Payload Extraction

Dshell is a network forensic analysis framework.

Malware samples, analysis exercises and other interesting resources.

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

Visualize network topologies and collect graph statistics based on pcap files

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

A network packet forensics tool for SSH

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

A tool to assist with network-based hunting for GRU's Drovorub malware c2