
wireshark-rdp
Wireshark RDP resources

Wireshark RDP resources

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files


PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Selective protocol extractor from PCAPs or interfaces

create cypher create statements for neo4j out of netstat files from multiple machines

Malware samples, analysis exercises and other interesting resources.

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

A swiss-knife MCP server for analysing PCAP files

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

Visualize network topologies and collect graph statistics based on pcap files

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files