
NetScope
Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

A terminal UI for tshark, inspired by Wireshark

A network packet forensics tool for SSH

AIEngine is a next generation interactive/programmable Python/Ruby/Java/Lua and Go NIDS (Network intrusion detection system).

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Lua plugin to extract data from Wireshark and convert it into MISP format

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

⭐ ⭐ Distributed tcpdump for cloud native environments ⭐ ⭐