
fatt
FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

A Zeek Wireguard protocol analyzer based on Spicy.

A Zeek OSPF packet analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Visualize network topologies and collect graph statistics based on pcap files

Selective protocol extractor from PCAPs or interfaces

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

CVE-2017-0199 XLS --> HTA --> VBS --> STEGANOGRAPHY --> DBATLOADER/GULOADER STYLE MALWARE