
Baskerville
Selective protocol extractor from PCAPs or interfaces

Selective protocol extractor from PCAPs or interfaces

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.

A swiss-knife MCP server for analysing PCAP files

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

create cypher create statements for neo4j out of netstat files from multiple machines

Distributed & real time digital forensics at the speed of the cloud

A tool for processing a lot of pcaps using tshark

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

Offline AI Security Assistant for Air-Gapped Pentesting

It was developed to speed up the processes of SOC Analysts during analysis

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

A Zeek STUN protocol analyzer based on Spicy.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Visualize network topologies and collect graph statistics based on pcap files