
pyshark
Python wrapper for tshark, allowing python packet parsing using wireshark dissectors
digital-forensicsencryption-decryption-toolsforensics+5
2.5k

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

JA4+ is a suite of network fingerprinting standards

Decodes PlugX traffic and encrypted/compressed artifacts

Decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, can also remove IEEE 802.1Q (virtual lan) header. Works with pcap…

Decrypts Covenant C2 communications by extracting RSA private keys from minidumps, recovering AES session keys, and converting network captures to…