
Mortimer
A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

Collection of forensic tools

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Wireshark RDP resources

A tool for processing a lot of pcaps using tshark

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

It was developed to speed up the processes of SOC Analysts during analysis

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Dshell is a network forensic analysis framework.


A tool to analyze the network flow during attack/defence Capture the Flag competitions

A network packet forensics tool for SSH

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

A tool to assist with network-based hunting for GRU's Drovorub malware c2