
packetStrider
A network packet forensics tool for SSH

A network packet forensics tool for SSH


Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

NetworkAssessment: Network Compromise Assessment Tool

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

A Zeek based NetSupport detector. NetSupport is often abused by attackers in malware.

AIEngine is a next generation interactive/programmable Python/Ruby/Java/Lua and Go NIDS (Network intrusion detection system).

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.