
zeek-spicy-stun
A Zeek STUN protocol analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.

A Zeek IPSec protocol analyzer based on Spicy.

A network packet forensics tool for SSH

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Bro analyzer that detects Google's QUIC protocol

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

A swiss-knife MCP server for analysing PCAP files

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…