
drovorub-hunt
A tool to assist with network-based hunting for GRU's Drovorub malware c2

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

A network sniffer that logs all DNS server replies for use in a passive DNS setup

All-in-One malware analysis tool.

A network packet forensics tool for SSH

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

A tool for processing a lot of pcaps using tshark

It was developed to speed up the processes of SOC Analysts during analysis

A tool to analyze the network flow during attack/defence Capture the Flag competitions

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…


Malicious HTTP traffic explorer

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Malcom - Malware Communications Analyzer

NetworkAssessment: Network Compromise Assessment Tool

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files