


A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

TCP/IP packet demultiplexer. Download from:

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

create cypher create statements for neo4j out of netstat files from multiple machines

Lua plugin to extract data from Wireshark and convert it into MISP format

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

Selective protocol extractor from PCAPs or interfaces

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

All-in-One malware analysis tool.