
arkime
Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

JA4+ is a suite of network fingerprinting standards

This is the development tree. Production downloads are at:

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

Visualize network topologies and collect graph statistics based on pcap files

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

A tool for processing a lot of pcaps using tshark

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

Pcap (capture file) Analysis Toolkit(v.1)

Offline AI Security Assistant for Air-Gapped Pentesting

A swiss-knife MCP server for analysing PCAP files

It was developed to speed up the processes of SOC Analysts during analysis

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

create cypher create statements for neo4j out of netstat files from multiple machines

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally