
securityonion
Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

A terminal UI for tshark, inspired by Wireshark

Provides packet processing capabilities for Go

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

A Swiss army knife for your daily Linux network plumbing.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic