
maltrail
Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

Pcap (capture file) Analysis Toolkit(v.1)

It was developed to speed up the processes of SOC Analysts during analysis

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

A pcap capture analysis helper

Arkime is an open source, large scale, full packet capturing, indexing, and database system.


JA4+ is a suite of network fingerprinting standards

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

This is the development tree. Production downloads are at:

A Swiss army knife for your daily Linux network plumbing.

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Visualize network topologies and collect graph statistics based on pcap files

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

A tool for processing a lot of pcaps using tshark

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.