
IPED
IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

Bro analyzer that detects Google's QUIC protocol

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

JA4+ is a suite of network fingerprinting standards


RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.