
drovorub-hunt
A tool to assist with network-based hunting for GRU's Drovorub malware c2

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Network forensic analysis tool for deep PCAP inspection, extracting passwords, authentication hashes, and network maps. Supports live capture,…

A tool to analyze the network flow during attack/defence Capture the Flag competitions

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

A tool for processing a lot of pcaps using tshark

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Analyzes SSH packet captures using machine learning to predict reverse tunnels, keystrokes, data exfiltration, and authentication methods for…

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Analyzes pcap files to detect DNS tunneling, SSH tunneling, TCP hijacking, and various network attacks (SYN flood, Slowloris, SMB) with…

It was developed to speed up the processes of SOC Analysts during analysis