
forensictools
Collection of forensic tools

Collection of forensic tools

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Selective protocol extractor from PCAPs or interfaces

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

A tool for processing a lot of pcaps using tshark

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

It was developed to speed up the processes of SOC Analysts during analysis

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…